Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
114 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.7) | 0.48% | — | Heateor Sassy Social Share | 26/4/2024 | 17/6/2026 | The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Analizada | Media (4.8) | 0.50% | — | Heateor Super Socializer | 15/4/2024 | 17/6/2026 | The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (5.4) | 0.34% | — | Heateor Fancy Comments | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Fancy Comments WordPress allows Stored XSS.This issue affects Fancy Comments WordPress: from n/a through 1.2.14. | |
| Modificada | Media (5.4) | 0.51% | — | Heateor Sassy Social Share | 6/3/2024 | 17/6/2026 | The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Sassy_Social_Share' shortcode in all versions up to, and including, 3.3.58 due to insufficient input sanitization and output escaping on user supplied attributes such as 'url'. This makes… | |
| Modificada | Media (6.4) | 0.47% | — | Heateor Sassy Social Share | 29/2/2024 | 17/6/2026 | The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.3.56 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.32% | — | Heateor Social Login | 10/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login WordPress allows Stored XSS.This issue affects Heateor Social Login WordPress: from n/a through 1.1.30. | |
| Modificada | Media (6.8) | 0.73% | 💥 PoC | Alpha-innotec Heat Pumps FirmwareNovelan Heat Pumps Firmware | 30/1/2024 | 17/6/2026 | An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file. | |
| Modificada | Media (4.8) | 0.39% | — | Slimndap Theater FOR Wordpress | 23/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Theater for WordPress plugin <= 0.18.3 versions. | |
| Modificada | Media (4.8) | 0.50% | — | Plerdy Heatmap | 22/11/2023 | 17/6/2026 | The Website Optimization – Plerdy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tracking code settings in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.29% | — | Userlocal Userheat Plugin | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in User Local Inc UserHeat Plugin.This issue affects UserHeat Plugin: from n/a through 1.1.6. | |
| Modificada | Alta (7.8) | 0.46% | 💥 PoC | Echo Anti Cheat Tool | 11/10/2023 | 17/6/2026 | An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys component. NOTE: the vendor's position is that the reported ability for user-mode applications to execute code as NT AUTHORITY\SYSTEM was "deactivated by Microsoft itself." | |
| Modificada | Media (5) | 0.71% | — | Openstack HeatRedhat Openstack Platform | 24/9/2023 | 17/6/2026 | An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system. | |
| Modificada | Media (5.4) | 0.42% | — | Heateor Super Socializer | 20/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor Super Socializer plugin <= 7.13.52 versions. | |
| Modificada | Media (6.1) | 6.0% | 💥 Exploit | Heator Social Share, Social Login AND Social Comments | 19/6/2023 | 17/6/2026 | The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (5.4) | 0.38% | — | Heateor Social Comments | 4/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor WordPress Social Comments Plugin for Vkontakte Comments and Disqus Comments plugin <= 1.6.1 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Heateor Fancy Comments | 30/3/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Team Heateor Fancy Comments WordPress plugin <= 1.2.10 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Heateor Super Socializer | 16/1/2023 | 17/6/2026 | The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used… | |
| Modificada | Media (5.4) | 0.47% | — | Heateor Sassy Social Share | 16/1/2023 | 17/6/2026 | The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (5.5) | 0.25% | — | Openstack Tripleo Heat Templates | 26/8/2022 | 17/6/2026 | A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager. | |
| Modificada | Media (4.3) | 0.56% | — | Jenkins Openstack Heat | 27/7/2022 | 17/6/2026 | Jenkins Openstack Heat Plugin 1.5 and earlier does not perform permission checks in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. | |
| Modificada | Media (4.3) | 0.57% | — | Jenkins Openstack Heat | 27/7/2022 | 17/6/2026 | A missing permission check in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL. | |
| Modificada | Media (6.5) | 0.44% | — | Jenkins Openstack Heat | 27/7/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers to connect to an attacker-specified URL. | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Heateor Super Socializer | 11/4/2022 | 17/6/2026 | The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site… | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Heateor Sassy Social Share | 28/3/2022 | 17/6/2026 | The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue. | |
| Modificada | Media (4.3) | 0.79% | — | Openstack Tripleo Heat TemplatesRedhat Openstack | 23/3/2022 | 17/6/2026 | An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is visible to all end users) in configuration files. This would give sensitive information which may aid… |