Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

299 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.3)0.15%—Plechevandrey Wp-recallAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in tggfref WP-Recall allows Privilege Escalation. This issue affects WP-Recall: from n/a through 16.26.14.
AplazadaAlta (7.5)0.62%—Plechevandrey Wp-recallAI7/5/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in tggfref WP-Recall allows PHP Local File Inclusion. This issue affects WP-Recall: from n/a through 16.26.14.
AnalizadaBaja (3.5)0.27%—Plechevandrey Wp-recall28/4/202517/6/2026
The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaAlta (7.1)0.15%—Pham Thanh Call NOW PHT BlogAI24/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Pham Thanh Call Now PHT Blog call-now-coccoc-pht-blog allows Stored XSS.This issue affects Call Now PHT Blog: from n/a through <= 2.4.1.
AplazadaAlta (7.1)0.19%—Nimbata Call TrackingAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in nimbata Nimbata Call Tracking nimbata-call-tracking allows Stored XSS.This issue affects Nimbata Call Tracking: from n/a through <= 1.7.4.
AplazadaMedia (5.9)0.40%—Scott Salisbury Request Call BackAI9/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Salisbury Request Call Back request-call-back allows Stored XSS.This issue affects Request Call Back: from n/a through <= 1.4.1.
AplazadaBaja (3.8)0.16%—Element WEBAIElement CallAIMatrix React SDKAI8/4/202517/6/2026
Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to version 1.11.96, can be configured to load Element Call from an external URL. Under certain conditions, the external page is able to get access to the media encryption keys used for an Element Call…
AplazadaAlta (7.3)0.50%—SO Called AIR QuotesAI29/3/202517/6/2026
The So-Called Air Quotes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated…
AplazadaMedia (5.3)1.5%—Aishida Call Center SystemAI28/3/202517/6/2026
A vulnerability, which was classified as critical, has been found in Aishida Call Center System up to 20250314. This issue affects some unknown processing of the file /doscall/weixin/open/amr2mp3. The manipulation of the argument File leads to command injection. The attack may be initiated remotely. The exploit has…
AnalizadaMedia (4.7)0.32%—Plechevandrey Wp-recall25/3/202517/6/2026
The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
AplazadaAlta (7.1)0.19%—Wpshop CallphonerAI24/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPShop.ru CallPhone'r callphoner allows Stored XSS.This issue affects CallPhone'r: from n/a through <= 1.1.1.
AnalizadaMedia (6.3)0.34%—Plechevandrey Wp-recall8/3/202517/6/2026
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execution due to a missing capability check on the 'rcl_preview_post' AJAX endpoint in all versions up to, and including, 16.26.10. This makes it possible for authenticated attackers, with Subscriber-level…
AnalizadaMedia (5.4)0.25%—Plechevandrey Wp-recall8/3/202517/6/2026
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'public-form' shortcode in all versions up to, and including, 16.26.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
AnalizadaCrítica (9.8)2.9%💥 ExploitPlechevandrey Wp-recall8/3/202517/6/2026
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AnalizadaMedia (4.3)0.46%—Plechevandrey Wp-recall8/3/202517/6/2026
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 16.26.10 via the 'feed' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to view data…
AplazadaAlta (7.1)0.30%—Callback RequestAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Callback Request allows Reflected XSS. This issue affects Callback Request: from n/a through 1.4.
AnalizadaAlta (7.8)0.28%—Trendmicro Housecall FOR Home Networks22/2/202517/6/2026
Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.
AplazadaAlta (7.1)0.31%—Podamibe Nepal Podamibe Twilio Private CallAI14/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podamibe Nepal Podamibe Twilio Private Call podamibe-twilio-private-call allows Reflected XSS.This issue affects Podamibe Twilio Private Call: from n/a through <= 1.0.1.
AplazadaAlta (7.1)0.13%—Callmeforsox Post ThumbsAI13/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Callmeforsox Post Thumbs allows Stored XSS. This issue affects Post Thumbs: from n/a through 1.5.
AplazadaAlta (7.5)0.15%—Forever Kidswatch Call ME Kw-50AI6/2/202517/6/2026
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to lack of encryption in device-server communication.
AplazadaMedia (6.6)0.20%—Forever Kidswatch Call ME Kw50AIForever Kidswatch Call ME 2 Kw60AI6/2/202517/6/2026
The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it is possible to…
AplazadaCrítica (9.1)0.35%—Forever Kidswatch Call ME Kw50AIForever Kidswatch Call ME 2 Kw60AI6/2/202517/6/2026
Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b have a Hardcoded password vulnerability.
AplazadaCrítica (9.8)0.41%—Forever Kidswatch Call ME Kw50AIForever Kidswatch Call ME 2 Kw60AI6/2/202517/6/2026
Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allows malicious users to change the device IMEI-number which allows for forging the identity of the device.
AplazadaCrítica (9.8)0.44%—Forever Kidswatch Call ME Kw-50AIForever Kidswatch Call ME Kw-60AI6/2/202517/6/2026
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allow a malicious user to gain information about the device by sending an SMS to the device which returns sensitive information.
AnalizadaMedia (5.4)0.69%💥 ExploitApidaze Widget4call1/2/202517/6/2026
The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Orbitaley — Vulnerabilidades