Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.30% | — | Companion PortfolioAI | 14/12/2024 | 17/6/2026 | The Companion Portfolio – Responsive Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'companion-portfolio' shortcode in all versions up to, and including, 2.4.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Crítica (9.8) | 1.2% | — | Sv100 CompanionAI | 6/12/2024 | 17/6/2026 | The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the settings_import() function in all versions up to, and including, 2.0.02. This makes it possible for unauthenticated attackers to update arbitrary… | |
| Analizada | Crítica (9.8) | 9.1% | 💥 Exploit | Themehunk Hunk Companion | 11/10/2024 | 17/6/2026 | The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to install and activate… | |
| Modificada | Media (5.4) | 0.26% | — | Horea Radu ONE Page Express Companion | 7/6/2024 | 17/6/2026 | The One Page Express Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's one_page_express_contact_form shortcode in all versions up to, and including, 1.6.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.4) | 0.32% | — | Extendthemes Materialis Companion | 6/6/2024 | 17/6/2026 | The Materialis Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's materialis_contact_form shortcode in all versions up to, and including, 1.3.41 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (4.9) | 0.26% | — | Creativethemes Blocksy Companion | 3/6/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Creative Themes Blocksy Companion blocksy-companion.This issue affects Blocksy Companion: from n/a through <= 2.0.42. | |
| Modificada | Media (5.4) | 0.43% | — | Creativethemes Blocksy Companion | 14/5/2024 | 17/6/2026 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up to, and including, 2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject… | |
| Aplazada | Media (6.4) | 0.33% | — | Extendthemes Mesmerize CompanionAI | 8/5/2024 | 17/6/2026 | The Mesmerize Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mesmerize_contact_form' shortcode in all versions up to, and including, 1.6.148 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.31% | — | Machothemes CPO CompanionAI | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MachoThemes CPO Companion allows Stored XSS.This issue affects CPO Companion: from n/a through 1.1.0. | |
| Modificada | Alta (8.8) | 0.21% | — | Creativethemes Blocksy Companion | 11/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CreativeThemes Blocksy Companion.This issue affects Blocksy Companion: from n/a through 2.0.28. | |
| Modificada | Media (5.4) | 0.34% | — | Creativethemes Blocksy Companion | 22/3/2024 | 17/6/2026 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (5.4) | 0.31% | — | Codeworkweb CWW Companion | 12/3/2024 | 17/6/2026 | The CWW Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Module2 widget in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Modificada | Alta (7.6) | 0.32% | — | SAP Companion | 13/2/2024 | 17/6/2026 | SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information and cause minor impact on the integrity of the web application. | |
| Modificada | Media (5.4) | 0.31% | — | Wpoperation Ultra Companion | 10/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPoperation Ultra Companion – Companion plugin for WPoperation Themes allows Stored XSS.This issue affects Ultra Companion – Companion plugin for WPoperation Themes: from n/a through 1.1.9. | |
| Modificada | Crítica (9.8) | 25% | 💥 PoC | Atlassian Companion | 6/12/2023 | 17/6/2026 | Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code. | |
| Modificada | Alta (7.3) | 0.31% | — | M-files WEB Companion | 20/10/2023 | 17/6/2026 | Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types | |
| Modificada | Alta (7.8) | 0.33% | — | M-files WEB Companion | 20/10/2023 | 17/6/2026 | Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution | |
| Modificada | Alta (8.8) | 0.28% | — | Home-assistant Home Assistant Companion | 19/10/2023 | 17/6/2026 | The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious links/QRs to victims that, when visited, will make the victim to call arbitrary services in their Home Assistant installation. Combined with this security advisory, may… | |
| Modificada | Alta (7.8) | 0.17% | 💥 PoC | Home-assistant Home Assistant Companion | 19/10/2023 | 17/6/2026 | Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL loading in a WebView. This enables all sorts of attacks, including arbitrary JavaScript execution, limited native code execution, and credential theft. This issue has… | |
| Modificada | Media (5.5) | 0.18% | — | Hcltech Traveler Companion | 11/8/2023 | 17/6/2026 | When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred which may reveal sensitive information. | |
| Modificada | Media (6.1) | 1.00% | 💥 Exploit | Codeermeneer Companion Sitemap Generator | 10/7/2023 | 17/6/2026 | The Companion Sitemap Generator WordPress plugin before 4.5.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (4.3) | 0.55% | — | Creativethemes Blocksy Companion | 2/5/2023 | 17/6/2026 | The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example | |
| Modificada | Media (5.4) | 0.34% | — | Creativethemes Blocksy Companion | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Codeermeneer Companion Sitemap Generator | 13/3/2023 | 17/6/2026 | The Companion Sitemap Generator WordPress plugin through 4.5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.60% | — | Extendthemes Materialis Companion | 6/2/2023 | 17/6/2026 | The Materialis Companion WordPress plugin before 1.3.40 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… |