Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.36% | — | Contributor SQL Injection IN Custom Field TemplateAI | 2/7/2026 | 2/7/2026 | Contributor SQL Injection in Custom Field Template <= 2.7.8 versions. | |
| Pendiente de análisis | Crítica (9) | 0.37% | — | Nvidia ConnectxAINvidia BluefieldAI | 1/7/2026 | 6/10/2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. | |
| Pendiente de análisis | Crítica (9) | 0.37% | — | Nvidia ConnectxAINvidia BluefieldAI | 1/7/2026 | 6/10/2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. | |
| Aplazada | Alta (7.2) | 0.54% | — | Advanced Product FieldsAI | 15/6/2026 | 17/6/2026 | Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions. | |
| Aplazada | Media (6.9) | 0.13% | — | Wordpress More FieldsAI | 15/6/2026 | 17/6/2026 | WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes on the Write/Edit… | |
| Aplazada | Media (5.3) | 0.52% | — | Advancedcustomfields Advanced Custom FieldsAI | 31/5/2026 | 22/7/2026 | The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and… | |
| Aplazada | Crítica (9.8) | 0.87% | 💥 PoC | Acfextended Advanced Custom Fields ExtendedAI | 28/5/2026 | 21/7/2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with… | |
| Aplazada | Media (6.5) | 0.41% | — | Meta Field BlockAI | 28/5/2026 | 17/6/2026 | The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.5.1. This is due to the plugin allowing users to specify arbitrary object IDs and object types via block attributes without validating whether the authenticated user has permission to… | |
| Aplazada | Media (6.5) | 0.22% | — | Advancedcustomfields Font Awesome FieldAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced Custom Fields: Font Awesome Field allows Stored XSS. This issue affects Advanced Custom Fields: Font Awesome Field: from n/a through 5.0.2. | |
| Analizada | Crítica (9.3) | 0.38% | — | Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+4 | 27/5/2026 | 17/6/2026 | The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites. | |
| Aplazada | Media (4.3) | 0.18% | — | Search Simple FieldsAI | 27/5/2026 | 17/6/2026 | The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the search_simple_fields_options() function in functions_admin.php. This makes it possible for unauthenticated attackers to modify the… | |
| Aplazada | Media (6.9) | 0.53% | — | Simple FieldsAI | 17/5/2026 | 17/6/2026 | Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null bytes into the wp_abspath parameter on PHP versions before 5.3.4. Attackers can supply malicious wp_abspath values to simple_fields.php to… | |
| Aplazada | Media (6.4) | 0.35% | — | Advanced Custom Fields Font AwesomeAI | 15/5/2026 | 17/6/2026 | The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due to insufficient input validation of JSON field values and unsafe client-side HTML construction in the update_preview() JavaScript function. This makes it… | |
| Aplazada | Media (6.4) | 0.26% | — | Meta Field BlockAI | 14/5/2026 | 17/6/2026 | The Meta Field Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' block attribute in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,… | |
| Aplazada | Media (6.5) | 0.38% | — | Acfextended Advanced Custom Fields ExtendedAI | 12/5/2026 | 30/9/2026 | The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for… | |
| Analizada | Media (6.4) | 0.21% | 💥 PoC | Cisco IOT Field Network Director | 6/5/2026 | 29/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is due to insufficient input validation of user-supplied data. An attacker could… | |
| Analizada | Media (6.5) | 0.27% | — | Cisco IOT Field Network Director | 6/5/2026 | 30/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerability is due to insufficient file access checks. An attacker could exploit this… | |
| Analizada | Alta (7.7) | 0.27% | — | Cisco IOT Field Network Director | 6/5/2026 | 30/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error handling. An attacker could exploit this vulnerability by… | |
| Aplazada | Alta (8.7) | 0.60% | — | Conditional Fields FOR Contact Form 7AI | 4/5/2026 | 17/6/2026 | Conditional Fields for Contact Form 7 WordPress plugin through version 2.7.2 contains an uncontrolled resource consumption vulnerability in the Wpcf7cfMailParser class where the hide_hidden_mail_fields_regex_callback() method reads an iteration count directly from user-supplied POST parameters without validation or… | |
| Aplazada | Crítica (9.8) | 0.87% | 💥 PoC | User Registration Advanced FieldsAI | 2/5/2026 | 17/6/2026 | The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_AJAX::method_upload' function in all versions up to, and including, 1.6.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected… | |
| Aplazada | Alta (8.7) | 0.74% | — | Buddypress Xprofile Custom Fields TypeAI | 29/4/2026 | 17/6/2026 | BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attackers can modify the field_hiddenfile and field_deleteimg parameters during profile editing to unlink files from the… | |
| Aplazada | Media (5.3) | 0.86% | — | Advancedcustomfields Advanced Custom FieldsAI | 15/4/2026 | 17/6/2026 | The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper… | |
| Aplazada | Media (5.3) | 0.29% | — | Coding Panda Panda Pods Repeater FieldAI | 8/4/2026 | 20/7/2026 | Missing Authorization vulnerability in Coding Panda Panda Pods Repeater Field panda-pods-repeater-field allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panda Pods Repeater Field: from n/a through <= 1.5.12. | |
| Analizada | Crítica (9.6) | 0.59% | — | Stackfield | 3/4/2026 | 24/7/2026 | The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesystem. | |
| Analizada | Media (6.9) | 0.39% | — | Deciphered Filefield Paths | 26/3/2026 | 17/6/2026 | Information disclosure in the file URI processing of File (Field) Paths in Drupal File (Field) Paths 7.x prior to 7.1.3 on Drupal 7.x allows authenticated users to disclose other users’ private files via filename‑collision uploads. This can cause hook_node_insert() consumers (for example, email attachment modules) to… |