Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

75 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.49%—Plainware Locatoraid9/6/202317/6/2026
The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaMedia (5.4)0.44%—Wpexperts WP Multi Store Locator5/6/202317/6/2026
The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (8.8)0.27%—Viadat Store Locator FOR Wordpress With Google Maps24/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Viadat Creations Store Locator for WordPress with Google Maps – LotsOfLocales plugin <= 3.98.7 versions.
ModificadaAlta (8.8)0.25%—Plainware Locatoraid15/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.11 versions.
ModificadaMedia (5.4)0.47%—Agilelogix Store Locator23/1/202317/6/2026
The Store Locator WordPress plugin before 1.4.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
ModificadaMedia (6.1)0.25%—Agilelogix Store Locator18/11/202217/6/2026
Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordPress.
ModificadaCrítica (9.8)0.86%—Rust-osdev Linked-list-allocator7/9/202217/6/2026
linked_list_allocator is an allocator usable for no_std systems. Prior to version 0.10.2, the heap initialization methods were missing a minimum size check for the given heap size argument. This could lead to out-of-bound writes when a heap was initialized with a size smaller than `3 * size_of::<usize>` because of…
ModificadaAlta (8.8)1.7%—Instawp String Locator6/9/202217/6/2026
The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path' parameter in versions up to, and including 2.5.0. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an…
ModificadaMedia (4.9)1.4%—String Locator Project String Locator28/3/202217/6/2026
The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will…
ModificadaAlta (7.8)0.23%—NI Service Locator12/11/202117/6/2026
There is an Unquoted Service Path in NI Service Locator (nisvcloc.exe) in versions prior to 18.0 on Windows. This may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges.
ModificadaMedia (6.1)0.83%—De-baat Store Locator Plus17/5/202117/6/2026
There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages.
ModificadaAlta (8.8)1.1%—De-baat Store Locator Plus17/5/202117/6/2026
There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.
ModificadaAlta (7.2)1.6%—Xtremelocator13/9/201917/6/2026
The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.
ModificadaAlta (8.8)1.7%—Jenkins Port Allocator11/7/201917/6/2026
Jenkins Port Allocator Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
ModificadaCrítica (9.8)3.0%—Store Locator Project Store Locator16/10/201717/6/2026
SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.
ModificadaMedia (6.5)1.0%—Store Locator Project Store Locator16/6/201517/6/2026
SQL injection vulnerability in the Store Locator (locator) extension before 3.3.1 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (5.4)0.27%—Affinitycu Affinity Mobile ATM Locator20/10/201417/6/2026
The Affinity Mobile ATM Locator (aka com.collegemobile.affinity.locator) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Flane Cisco Class Locator Fast Lane9/9/201417/6/2026
The Cisco Class Locator Fast Lane (aka com.tabletkings.mycompany.fastlane.cisco) application for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.3%—Joachim Ruhs Locator16/8/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.4%—Joachim Ruhs Locator16/8/201316/6/2026
SQL injection vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (10)1.9%—Joachim Ruhs Locator16/8/201316/6/2026
Unspecified vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 has unknown impact and remote attack vectors, related to "Insecure Unserialize."
ModificadaAlta (7.5)1.1%—Joachim Ruhs Locator22/7/201016/6/2026
SQL injection vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.0%—Joachim Ruhs Locator22/7/201016/6/2026
Cross-site scripting (XSS) vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)0.97%💥 ExploitV-gn Userlocator6/1/200916/6/2026
SQL injection vulnerability in locator.php in the Userlocator module 3.0 for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the y parameter in a get_user action.
ModificadaBaja (3.6)2.3%💥 ExploitPlutostatus Locator19/2/200816/6/2026
Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
Orbitaley — Vulnerabilidades