Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
191 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.21% | — | Rstheme Ultimate Coming Soon & Maintenance | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allows Cross Site Request Forgery.This issue affects Ultimate Coming Soon & Maintenance: from n/a through <= 1.0.9. | |
| Modificada | Media (4.3) | 0.22% | — | Rstheme Ultimate Coming Soon & Maintenance | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allows Cross Site Request Forgery.This issue affects Ultimate Coming Soon & Maintenance: from n/a through <= 1.0.9. | |
| Aplazada | Media (4.3) | 0.34% | — | Maintenance Coming Soon Redirect AnimationAI | 20/12/2024 | 17/6/2026 | The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wploti_add_whitelisted_roles_option', 'wploti_remove_whitelisted_roles_option', 'wploti_add_whitelisted_users_option',… | |
| Aplazada | Alta (7.1) | 0.21% | — | Lionscripts Site Maintenance AND Noindex NofollowAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.com LionScripts: Site Maintenance & Noindex Nofollow Plugin maintenance-and-noindex-nofollow allows Stored XSS.This issue affects LionScripts: Site Maintenance & Noindex Nofollow Plugin: from n/a through <= 2.1. | |
| Aplazada | Media (5.3) | 0.52% | — | 8degreethemes Coming Soon Landing Page AND Maintenance ModeAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in 8Degree Themes Coming Soon Landing Page and Maintenance Mode WordPress Plugin allows Retrieve Embedded Sensitive Data.This issue affects Coming Soon Landing Page and Maintenance Mode WordPress Plugin: from n/a through 2.2.0. | |
| Modificada | Media (5.3) | 0.37% | — | Rstheme Ultimate Coming Soon & Maintenance | 6/12/2024 | 17/6/2026 | The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ucsm_activate_lite_template_lite function in all versions up to, and including, 1.0.9. This makes it possible for unauthenticated attackers to change the template used… | |
| Modificada | Media (4.3) | 0.34% | — | Rstheme Ultimate Coming Soon & Maintenance | 6/12/2024 | 17/6/2026 | The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ucsm_update_template_name_lite' function in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Alta (7.1) | 0.21% | — | Themefusecom Themefuse Maintenance ModeAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themefusecom ThemeFuse Maintenance Mode themefuse-maintenance-mode allows Stored XSS.This issue affects ThemeFuse Maintenance Mode: from n/a through <= 1.1.3. | |
| Modificada | Media (6.1) | 0.29% | — | Mattroyal Woocommerce Maintenance Mode | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt Royal WooCommerce Maintenance Mode woocommerce-maintenance-mode allows Reflected XSS.This issue affects WooCommerce Maintenance Mode: from n/a through <= 2.0.1. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Automatic Systems Maintenance SlimlaneAI | 14/10/2024 | 17/6/2026 | Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the PassageAutoServer.php page. | |
| Aplazada | Media (6.1) | 0.32% | — | Automatic Systems Maintenance SlimlaneAI | 14/10/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php component. | |
| Aplazada | Media (5.9) | 0.27% | — | Seedprod Coming Soon Page Under Construction Maintenance ModeAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Stored XSS.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <=… | |
| Aplazada | Baja (3.7) | 0.34% | — | Peter Hardy-vandoorn Jf3-maintenance-modeAI | 23/9/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Peter Hardy-vanDoorn Maintenance Redirect jf3-maintenance-mode.This issue affects Maintenance Redirect: from n/a through <= 2.0.1. | |
| Aplazada | Baja (3.7) | 0.36% | — | Ilyasine Maintenance AND Coming Soon Redirect AnimationAI | 29/8/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in ilyasine Maintenance & Coming Soon Redirect Animation maintenance-coming-soon-redirect-animation allows Identity Spoofing.This issue affects Maintenance & Coming Soon Redirect Animation: from n/a through <= 2.3.3. | |
| Modificada | Media (4.8) | 0.33% | — | Wpexperts WP Secure Maintenance | 12/7/2024 | 17/6/2026 | The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (5.3) | 0.25% | — | WP MaintenanceAI | 19/6/2024 | 17/6/2026 | The WP Maintenance plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.1.9.2 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass maintenance… | |
| Modificada | Media (5.3) | 0.30% | — | Acurax Under Construction / Maintenance Mode | 10/6/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Acurax Under Construction / Maintenance Mode from Acurax allows Authentication Bypass.This issue affects Under Construction / Maintenance Mode from Acurax: from n/a through 2.6. | |
| Modificada | Media (5.4) | 0.44% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 8/6/2024 | 17/6/2026 | The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_ajax functions in all versions up to, and including, 2.38. This makes it possible for authenticated attackers, with… | |
| Aplazada | Baja (3.7) | 0.34% | — | Wpdevart Coming Soon AND Maintenance ModeAI | 4/6/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in wpdevart Coming soon and Maintenance mode allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming soon and Maintenance mode: from n/a through 3.7.3. | |
| Aplazada | Baja (3.7) | 0.34% | — | WP MaintenanceAI | 4/6/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in WP Maintenance allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Maintenance: from n/a through 6.1.3. | |
| Aplazada | Baja (3.7) | 0.37% | — | Helderk Maintenance ModeAI | 17/5/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in helderk Maintenance Mode allows Functionality Bypass.This issue affects Maintenance Mode: from n/a through 3.0.1. | |
| Aplazada | Baja (3.7) | 0.48% | — | Pippin Williamson CGC Maintenance ModeAI | 17/5/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Pippin Williamson CGC Maintenance Mode allows Functionality Bypass.This issue affects CGC Maintenance Mode: from n/a through 1.2. | |
| Aplazada | Alta (7.2) | 0.17% | — | B&R Industrial Automation Scene ViewerAIB&R Industrial Automation Mapp VisionAIB&R Industrial Automation Mapp ViewAIB&R Industrial Automation Mapp CockpitAI+21 | 14/5/2024 | 17/6/2026 | An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation… | |
| Aplazada | Media (5.4) | 0.21% | — | Brijeshk89 Smart Maintenance ModeAI | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brijesh Kothari Smart Maintenance Mode.This issue affects Smart Maintenance Mode: from n/a through 1.4.4. | |
| Analizada | Media (6.1) | 0.37% | — | Oracle Complex Maintenance Repair AND Overhaul | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance,… |