Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.30% | — | Massimo.serpilli Incredible-font-awesomeAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in massimo.serpilli Incredible Font Awesome incredible-font-awesome allows Stored XSS.This issue affects Incredible Font Awesome: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.28% | — | Alexander Weleczka Fontawesome.io ShortcodesAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexander Weleczka FontAwesome.io ShortCodes allows Stored XSS.This issue affects FontAwesome.io ShortCodes: from n/a through 1.0. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Themesawesome SakolawpAI | 7/1/2025 | 17/6/2026 | The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly limiting what roles a user can register as. This makes it possible for unauthenticated attackers to register as an… | |
| Analizada | Media (4.9) | 0.99% | — | Awesomemotive Easy Digital Downloads | 21/12/2024 | 17/6/2026 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.2 via the file download functionality. This makes it possible for authenticated attackers, with Administrator-level access and above, to read… | |
| Analizada | Baja (3.7) | 0.36% | — | Awesomemotive Easy Digital Downloads | 17/12/2024 | 17/6/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ensure the requesting user is the intended recipient of the purchase receipt. This makes it possible… | |
| Aplazada | Media (6.5) | 0.60% | — | Awesomesupport Awesome SupportAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.3.1. | |
| Modificada | Crítica (9.8) | 0.64% | — | Awesomemotive Easy Digital Downloads | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi Easy Digital Downloads easy-digital-downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through <= 3.1.5. | |
| Aplazada | Media (6.4) | 0.38% | — | Perfect Font Awesome IntegrationAI | 12/12/2024 | 17/6/2026 | The Perfect Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pfai' shortcode in all versions up to, and including, 2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Media (6.5) | 0.55% | — | Getawesomesupport Awesome Support | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.7. | |
| Modificada | Media (5.4) | 0.48% | — | Getawesomesupport Awesome Support | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.10. | |
| Modificada | Media (5.4) | 0.48% | — | Getawesomesupport Awesome Support | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.4. | |
| Aplazada | Media (5.3) | 0.44% | — | Awesometogi Product Category TreeAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in AWESOME TOGI Product Category Tree allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Category Tree: from n/a through 2.5. | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpfactory Awesome ShortcodesAI | 6/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Awesome Shortcodes awesome-shortcodes allows Reflected XSS.This issue affects Awesome Shortcodes: from n/a through <= 1.7.2. | |
| Aplazada | Alta (7.1) | 0.35% | — | Wpoets Awesome StudioAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpoets Awesome Studio awesome-studio allows Reflected XSS.This issue affects Awesome Studio: from n/a through <= 2.4.4. | |
| Aplazada | Media (6.5) | 0.38% | — | Shingo Awesome Fitness TestimonialsAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shingo Awesome Fitness Testimonials awesome-fitness-testimonials allows Stored XSS.This issue affects Awesome Fitness Testimonials: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.37% | — | Surbma Font AwesomeAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Surbma Surbma | Font Awesome surbma-font-awesome allows DOM-Based XSS.This issue affects Surbma | Font Awesome: from n/a through <= 3.0. | |
| Aplazada | Alta (7.1) | 0.20% | — | Sanjeev Mohindra Awesome Shortcodes FOR GenesisAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sanjeev Mohindra Awesome Shortcodes For Genesis awesome-shortcodes-for-genesis allows Stored XSS.This issue affects Awesome Shortcodes For Genesis: from n/a through 1.1.8. | |
| Aplazada | Media (6.5) | 0.29% | — | Abdullah Nahian Awesome Progress BARAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abdullah Nahian Awesome Progress Bar awesome-progess-bar allows DOM-Based XSS.This issue affects Awesome Progress Bar: from n/a through <= 1.0.13. | |
| Aplazada | Media (6.5) | 0.25% | — | MD Shiddikur Rahman Awesome Tool TIPAI | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md. Shiddikur Rahman Awesome Tool Tip awesome-tool-tip allows DOM-Based XSS.This issue affects Awesome Tool Tip: from n/a through <= 1.0. | |
| Aplazada | Crítica (9) | 0.68% | — | Decidim AwesomeAIPapertrailAI | 12/11/2024 | 17/6/2026 | An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands. | |
| Aplazada | Media (6.5) | 0.23% | — | Rupok AwesomepressAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rupok AwesomePress awesomepress allows Stored XSS.This issue affects AwesomePress: from n/a through <= 1.0. | |
| Analizada | Alta (8.8) | 0.49% | — | Awesomemotive Easy Digital Downloads | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.2.12. | |
| Aplazada | Media (5.4) | 0.39% | — | Theme4press Demo AwesomeAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Theme4Press Demo Awesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Awesome: from n/a through 1.0.2. | |
| Aplazada | Media (6.4) | 0.33% | — | WP Awesome LoginAI | 26/10/2024 | 17/6/2026 | The WP Awesome Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary… | |
| Analizada | Media (5.4) | 0.26% | — | Sohelwpexpert Awesome Buttons | 25/10/2024 | 17/6/2026 | The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… |