Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
179 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.38% | — | Wpchill Strong TestimonialsAI | 25/2/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Strong Testimonials: from n/a through <= 3.2.3. | |
| Aplazada | Media (6.4) | 0.27% | — | Schiller ELI 380AISchiller ELI 280AISchiller Bur280AISchiller Mlbur 280AI+5 | 7/2/2025 | 17/6/2026 | A use of hard-coded password vulnerability may allow authentication abuse.This issue affects ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior; ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph: Versions 2.3.1 and prior; ELI 250c/BUR 250c Resting Electrocardiograph: Versions 2.1.2 and prior; ELI 150c/BUR… | |
| Aplazada | Media (6.1) | 0.18% | — | Paulswarthout Child-themes-helperAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in paulswarthout Child Themes Helper child-themes-helper allows Path Traversal.This issue affects Child Themes Helper: from n/a through <= 2.2.7. | |
| Aplazada | Alta (7.6) | 0.58% | — | Wpchill Rsvp AND Event ManagementAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill RSVP and Event Management rsvp allows SQL Injection.This issue affects RSVP and Event Management: from n/a through <= 2.7.14. | |
| Aplazada | Media (5.3) | 0.36% | — | Wpchill Htaccess File EditorAI | 15/1/2025 | 17/6/2026 | Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Htaccess File Editor: from n/a through <= 1.0.19. | |
| Aplazada | Baja (1.9) | 0.97% | 💥 Exploit | SickchillAI | 8/1/2025 | 17/6/2026 | SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, an authenticated attacker may use this to redirect the user to arbitrary destinations, leading to open redirect. Commit… | |
| Analizada | Alta (8.8) | 0.86% | — | Wpchill Modula Image Gallery | 8/1/2025 | 17/6/2026 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 2.11.10. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on… | |
| Aplazada | Media (5.3) | 0.34% | — | Wpchill Rsvp AND Event ManagementAI | 7/1/2025 | 17/6/2026 | The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX functions like bulk_delete_attendees() and bulk_delete_questions() in all versions up to, and including, 2.7.13. This makes it possible for unauthenticated attackers to delete… | |
| Analizada | Alta (7.5) | 0.40% | — | Wpchill Passster | 7/1/2025 | 17/6/2026 | The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted… | |
| Aplazada | Media (5.3) | 0.35% | — | Wpchill Kali FormsAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Kali Forms kali-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kali Forms: from n/a through <= 2.3.27. | |
| Aplazada | Media (6.5) | 0.46% | — | Wpchill Kali FormsAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Kali Forms kali-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kali Forms: from n/a through <= 2.3.28. | |
| Aplazada | Alta (8.1) | 2.4% | 💥 Exploit | Mainwp ChildAI | 13/12/2024 | 17/6/2026 | The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable to privilege escalation due to a missing authorization checks on the register_site function in all versions up to, and including, 5.2 when a site is left in an unconfigured state. This makes it… | |
| Aplazada | Media (4.3) | 0.35% | — | Orbisius Child Theme CreatorAI | 12/12/2024 | 17/6/2026 | The Child Theme Creator by Orbisius plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cloud_delete() and cloud_update() functions in all versions up to, and including, 1.5.5. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Media (5.3) | 0.38% | — | Wpchill Simple RestrictAI | 10/12/2024 | 17/6/2026 | The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.7 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as… | |
| Aplazada | Media (6.5) | 0.33% | — | Strailejoey Achilles-shortcodesAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in strailejoey AchillesTheme-shortcodes achilles-shortcodes allows DOM-Based XSS.This issue affects AchillesTheme-shortcodes: from n/a through <= 0.1. | |
| Modificada | Alta (8.8) | 0.37% | — | Wpchill Htaccess File Editor | 1/11/2024 | 17/6/2026 | Incorrect Authorization vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Htaccess File Editor: from n/a through <= 1.0.18. | |
| Modificada | Alta (8.8) | 0.40% | — | Wpchill Strong Testimonials | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testimonials: from n/a through <= 3.1.16. | |
| Analizada | Alta (7.5) | 0.47% | — | Wpchill Download Monitor | 16/10/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for… | |
| Analizada | Media (4.3) | 0.37% | — | Wpchill Download Monitor | 26/9/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable shop… | |
| Analizada | Media (6.5) | 0.23% | — | Freakingwildchild Visual Sound | 17/9/2024 | 17/6/2026 | The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Media (6.5) | 0.25% | — | Freakingwildchild Visual Sound | 12/9/2024 | 17/6/2026 | The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Media (6.1) | 0.31% | — | Orbisius Child Theme Creator | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Svetoslav Marinov (Slavi) Child Theme Creator allows Reflected XSS.This issue affects Child Theme Creator: from n/a through 1.5.4. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpchill FilrAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Filr filr-protection.This issue affects Filr: from n/a through <= 1.2.4. | |
| Analizada | Alta (8.8) | 0.31% | — | Mainwp Child | 8/8/2024 | 17/6/2026 | The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrary options that can… | |
| Modificada | Media (5.3) | 0.37% | — | Wpchill Optimize Images ALT Text (alt Tag) & Names FOR SEO Using AI | 24/7/2024 | 17/6/2026 | The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.1.1. This is due the plugin utilizing cocur and not preventing direct access to the generate-default.php file. This makes it possible for unauthenticated… |