Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

489 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.47%💥 PoCNajeebmedia Frontend File ManagerAI26/6/202626/6/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin…
AplazadaAlta (7.5)0.41%—Najeebmedia Frontend File ManagerAI23/6/202623/6/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin through 23.6 by iterating identifiers.
AplazadaMedia (5.4)0.23%—Najeebmedia Frontend File ManagerAI23/6/202623/6/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the frontend file-rename endpoint before storing it as post meta and rendering it back on the admin File Manager listing, leading to a Stored Cross-Site Scripting vulnerability exploitable by users with…
AplazadaAlta (8.5)0.35%—Effress Woocommerce Frontend Manager UltimateAI17/6/202617/6/2026
Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.
AplazadaMedia (4.3)0.26%—Weplugins User FrontendAI9/6/202623/7/2026
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2. This makes it…
AplazadaMedia (4.3)0.19%—Frontend User NotesAI6/6/202623/7/2026
The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the funp_ajax_modify_notes function. This makes it possible for unauthenticated attackers to trick a logged-in user into visiting…
AplazadaAlta (8.8)0.43%—Frontier X Mobile ApplicationAISeil X2AI29/5/202622/7/2026
The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations,…
AplazadaMedia (4.9)0.29%—Dynamiapps Frontend AdminAI29/5/202621/7/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 3.28.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaAlta (8.8)1.2%—Dynamiapps Frontend AdminAI28/5/202617/6/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. This is due to insecure form submission handling that accepts arbitrary form definitions from user input instead of securely loading them from the backend. When…
AplazadaAlta (8.8)0.75%—Dynamiapps Frontend AdminAI28/5/202617/6/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaAlta (8.8)0.77%—Dynamiapps Frontend AdminAI15/5/202617/6/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive capabilities for the admin_form post type. The admin_form custom post…
AplazadaMedia (5.7)0.39%—Taiga FrontAI11/5/202617/6/2026
Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is fixed in 6.9.1.
AplazadaAlta (8.8)1.3%—Wedevs User FrontendAI8/5/202617/6/2026
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insufficient input validation and type checking on the wpuf_files parameter during form…
AplazadaMedia (6.5)0.34%—Najeebmedia Frontend File ManagerAI3/5/202617/6/2026
During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user…
AplazadaMedia (6.5)0.33%—Wedevs WP User FrontendAI29/4/202617/6/2026
Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.
AnalizadaAlta (7.5)0.42%—Agentfront @frontmcp/adaptersAgentfront @frontmcp/sdkAgentfront FrontmcpFrontmcp Mcp-from-openapi8/4/202624/7/2026
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in OpenAPI specifications without configuring any URL restrictions or custom resolvers. A malicious OpenAPI specification…
AplazadaMedia (5.3)0.30%—Glowlogix WP Frontend ProfileAI8/4/202624/7/2026
Missing Authorization vulnerability in Glowlogix WP Frontend Profile wp-front-end-profile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Frontend Profile: from n/a through <= 1.3.9.
AplazadaMedia (5.3)0.42%—Projectzealous PZ Frontend ManagerAI8/4/202624/7/2026
The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.6. The pzfm_user_request_action_callback() function, registered via the wp_ajax_pzfm_user_request_action action hook, lacks both capability checks and nonce verification. This function handles…
AplazadaAlta (7.2)1.0%—Dynamiapps Frontend AdminAI26/3/202617/6/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31. This is due to the use of WordPress's `maybe_unserialize()` function without class restrictions on user-controllable…
AplazadaAlta (7.5)0.38%—Wedevs WP User FrontendAI25/3/202617/6/2026
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8.
AplazadaMedia (6.5)0.31%—Wedevs WP User FrontendAI25/3/202617/6/2026
Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.5.
AplazadaMedia (5.3)0.19%—User FrontendAI16/3/202617/6/2026
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the draft_post() function in all versions up to, and including, 4.2.8. This makes it possible for…
AplazadaMedia (5.9)0.22%—Guest Posting Frontend Posting Front EditorAI11/3/202617/6/2026
The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to regenerate a .json file based on demo data that it initially creates. If an administrator modifies the demo form and enables admin notifications in the Guest posting / Frontend Posting / Front Editor…
AplazadaMedia (4.3)0.16%—WP Frontend ProfileAI7/3/202617/6/2026
The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This is due to missing nonce validation on the 'update_action' function. This makes it possible for unauthenticated attackers to approve or reject user account registrations via a…
AplazadaAlta (7.1)0.26%—Sizam RH Frontend Publishing PROAI5/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sizam RH Frontend Publishing Pro rh-frontend allows Reflected XSS.This issue affects RH Frontend Publishing Pro: from n/a through < 4.3.4.
Orbitaley — Vulnerabilidades