Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.49% | — | Plainware Locatoraid | 9/6/2023 | 17/6/2026 | The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (5.4) | 0.44% | — | Wpexperts WP Multi Store Locator | 5/6/2023 | 17/6/2026 | The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.27% | — | Viadat Store Locator FOR Wordpress With Google Maps | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Viadat Creations Store Locator for WordPress with Google Maps – LotsOfLocales plugin <= 3.98.7 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Plainware Locatoraid | 15/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.11 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Agilelogix Store Locator | 23/1/2023 | 17/6/2026 | The Store Locator WordPress plugin before 1.4.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Media (6.1) | 0.25% | — | Agilelogix Store Locator | 18/11/2022 | 17/6/2026 | Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordPress. | |
| Modificada | Crítica (9.8) | 0.86% | — | Rust-osdev Linked-list-allocator | 7/9/2022 | 17/6/2026 | linked_list_allocator is an allocator usable for no_std systems. Prior to version 0.10.2, the heap initialization methods were missing a minimum size check for the given heap size argument. This could lead to out-of-bound writes when a heap was initialized with a size smaller than `3 * size_of::<usize>` because of… | |
| Modificada | Alta (8.8) | 1.7% | — | Instawp String Locator | 6/9/2022 | 17/6/2026 | The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path' parameter in versions up to, and including 2.5.0. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an… | |
| Modificada | Media (4.9) | 1.4% | — | String Locator Project String Locator | 28/3/2022 | 17/6/2026 | The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will… | |
| Modificada | Alta (7.8) | 0.23% | — | NI Service Locator | 12/11/2021 | 17/6/2026 | There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges. | |
| Modificada | Media (6.1) | 0.83% | — | De-baat Store Locator Plus | 17/5/2021 | 17/6/2026 | There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages. | |
| Modificada | Alta (8.8) | 1.1% | — | De-baat Store Locator Plus | 17/5/2021 | 17/6/2026 | There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin. | |
| Modificada | Alta (7.2) | 1.6% | — | Xtremelocator | 13/9/2019 | 17/6/2026 | The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter. | |
| Modificada | Alta (8.8) | 1.7% | — | Jenkins Port Allocator | 11/7/2019 | 17/6/2026 | Jenkins Port Allocator Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Crítica (9.8) | 3.0% | — | Store Locator Project Store Locator | 16/10/2017 | 17/6/2026 | SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php. | |
| Modificada | Media (6.5) | 1.0% | — | Store Locator Project Store Locator | 16/6/2015 | 17/6/2026 | SQL injection vulnerability in the Store Locator (locator) extension before 3.3.1 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Affinitycu Affinity Mobile ATM Locator | 20/10/2014 | 17/6/2026 | The Affinity Mobile ATM Locator (aka com.collegemobile.affinity.locator) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Flane Cisco Class Locator Fast Lane | 9/9/2014 | 17/6/2026 | The Cisco Class Locator Fast Lane (aka com.tabletkings.mycompany.fastlane.cisco) application for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.3% | — | Joachim Ruhs Locator | 16/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Joachim Ruhs Locator | 16/8/2013 | 16/6/2026 | SQL injection vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (10) | 1.9% | — | Joachim Ruhs Locator | 16/8/2013 | 16/6/2026 | Unspecified vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 has unknown impact and remote attack vectors, related to "Insecure Unserialize." | |
| Modificada | Alta (7.5) | 1.1% | — | Joachim Ruhs Locator | 22/7/2010 | 16/6/2026 | SQL injection vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Joachim Ruhs Locator | 22/7/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | V-gn Userlocator | 6/1/2009 | 16/6/2026 | SQL injection vulnerability in locator.php in the Userlocator module 3.0 for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the y parameter in a get_user action. | |
| Modificada | Baja (3.6) | 2.3% | 💥 Exploit | Plutostatus Locator | 19/2/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. |