Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
205 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.25% | — | Clicksend SMS Contact Form 7 NotificationsAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in clicksend SMS Contact Form 7 Notifications by ClickSend clicksend-contactform7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Contact Form 7 Notifications by ClickSend: from n/a through <= 1.4.0. | |
| Analizada | Alta (8.8) | 0.55% | — | Microsoft Azure Notification Service | 23/10/2025 | 17/6/2026 | Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Crítica (9.3) | 0.49% | — | Cozyvision SMS Alert Order NotificationsAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.5. | |
| Aplazada | Media (4.3) | 0.13% | — | Notification BARAI | 3/10/2025 | 17/6/2026 | The Notification Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the 'subscriber-list-empty.php' file. This makes it possible for unauthenticated attackers to empty the subscriber list via a forged… | |
| Aplazada | Media (5.9) | 0.22% | — | Proof Factor LLC Proof Factor Social Proof NotificationsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proof Factor LLC Proof Factor – Social Proof Notifications proof-factor-social-proof-notifications allows Stored XSS.This issue affects Proof Factor – Social Proof Notifications: from n/a through <= 1.0.5. | |
| Aplazada | Media (6.5) | 0.21% | — | Buddydev Buddypress Notifications WidgetAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev BuddyPress Notification Widget buddypress-notifications-widget allows Stored XSS.This issue affects BuddyPress Notification Widget: from n/a through <= 1.3.3. | |
| Aplazada | Media (5.9) | 0.23% | — | Wpdever WP Notification BellAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdever WP Notification Bell wp-notification-bell allows Stored XSS.This issue affects WP Notification Bell: from n/a through <= 1.4.6. | |
| Aplazada | Media (4.3) | 0.14% | — | Andreamarinucci Notification FOR TelegramAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in rainafarai Notification for Telegram notification-for-telegram allows Cross Site Request Forgery.This issue affects Notification for Telegram: from n/a through <= 3.5. | |
| Aplazada | Media (5.9) | 0.18% | — | Pusheco Pushe WEB Push NotificationAI | 5/9/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pusheco Pushe Web Push Notification pushe-webpush allows Stored XSS.This issue affects Pushe Web Push Notification: from n/a through <= 0.5.0. | |
| Aplazada | Media (6.5) | 0.27% | — | Codesolz Ultimate Push NotificationsAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in CodeSolz Ultimate Push Notifications ultimate-push-notifications allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Push Notifications: from n/a through <= 1.2.0. | |
| Aplazada | Crítica (9.1) | 0.36% | — | Mediawiki DiscordnotificationsAI | 10/7/2025 | 17/6/2026 | DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel. DiscordNotifications allows sending requests via curl and file_get_contents to arbitrary URLs set via $wgDiscordIncomingWebhookUrl and $wgDiscordAdditionalIncomingWebhookUrls. This allows for DOS… | |
| Analizada | Media (4.3) | 0.15% | — | Skywavesolutions WP Firebase Push Notification | 4/7/2025 | 17/6/2026 | The WP Firebase Push Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the wfpn_brodcast_notification_message() function. This makes it possible for unauthenticated attackers to send… | |
| Aplazada | Alta (7.1) | 0.25% | — | Smartiolabs Smart NotificationAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smartiolabs Smart Notification allows Reflected XSS. This issue affects Smart Notification: from n/a through 10.3. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Smartiolabs Smart NotificationAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart Notification allows Blind SQL Injection. This issue affects Smart Notification: from n/a through 10.3. | |
| Aplazada | Media (4.3) | 0.37% | — | Slack Notifications BY DorzkiAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Dor Zuberi Slack Notifications by dorzki dorzki-notifications-to-slack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slack Notifications by dorzki: from n/a through <= 2.0.7. | |
| Aplazada | Media (6.5) | 0.25% | — | Appcheap Push Notification FOR Mobile AND WEB APPAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in App Cheap Push notification for Mobile and Web app push-notification-mobile-and-web-app allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Push notification for Mobile and Web app: from n/a through <= 2.0.3. | |
| Analizada | Crítica (9.8) | 2.8% | — | Pnfpb Push Notification FOR Post AND Buddypress | 15/5/2025 | 17/6/2026 | The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | |
| Modificada | Crítica (9.8) | 0.38% | — | Cozyvision SMS Alert Order Notifications | 12/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.1. | |
| Analizada | Media (5.4) | 0.28% | — | Cozyvision SMS Alert Order Notifications | 10/5/2025 | 17/6/2026 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Alta (8.8) | 0.46% | — | Cozyvision SMS Alert Order Notifications | 10/5/2025 | 17/6/2026 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (5.1) | 0.34% | — | Q2apro-on-site-notificationsAI | 7/5/2025 | 3/9/2026 | A vulnerability, which was classified as problematic, was found in q2apro q2apro-on-site-notifications up to 1.4.6. This affects the function process_request of the file q2apro-onsitenotifications-page.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to… | |
| Aplazada | Media (5.9) | 0.27% | — | Apasionados Email-notification-on-loginAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in apasionados Email Notification on Login email-notification-on-login allows Stored XSS.This issue affects Email Notification on Login: from n/a through <= 1.7.0. | |
| Aplazada | Alta (7.1) | 0.15% | — | Gtlwpdev ALL Push Notification FOR WPAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gtlwpdev All push notification for WP all-push-notification allows Reflected XSS.This issue affects All push notification for WP: from n/a through <= 1.5.3. | |
| Aplazada | Alta (7.1) | 0.29% | — | Push-notification-by-feedifyAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in feedify Feedify – Web Push Notifications push-notification-by-feedify allows Reflected XSS.This issue affects Feedify – Web Push Notifications: from n/a through <= 2.4.5. | |
| Aplazada | Alta (8.8) | 0.37% | — | Aweos Gmbh Email Notifications FOR UpdatesAI | 15/4/2025 | 17/6/2026 | Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Privilege Escalation.This issue affects Email Notifications for Updates: from n/a through <= 1.1.6. |