Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

80 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.34%—Wprepublic Hide Dashboard Notifications21/6/202417/6/2026
The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'warning_notices_settings' function in all versions up to, and including, 1.3. This makes it possible for authenticated attackers, with contributor access and above, to…
AplazadaMedia (4.3)0.20%—Wprepublic Hide Dashboard NotificationsAI26/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Republic Hide Dashboard Notifications.This issue affects Hide Dashboard Notifications: from n/a through 1.2.3.
ModificadaMedia (4.3)0.24%—Cozyvision SMS Alert Order Notifications13/3/202417/6/2026
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.9. This is due to missing or incorrect nonce validation on the processBulkAction function. This makes it possible for unauthenticated attackers to delete pages and…
ModificadaMedia (5.4)0.43%—Webpushr WEB Push Notifications27/11/202317/6/2026
The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks.
ModificadaAlta (8.8)0.32%—Webpushr WEB Push Notifications13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability leading to Local File Inclusion (LF) in Webpushr Web Push Notifications Web Push Notifications – Webpushr plugin <= 4.34.0 versions.
ModificadaMedia (6.5)0.22%—Disable Wordpress Update Notifications AND Auto-update Email Notifications Project Disable Wordpress Update Notifications AND Auto-update Email Notifications11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Prem Tiwari Disable WordPress Update Notifications and auto-update Email Notifications plugin <= 2.3.3 versions.
ModificadaMedia (6.5)0.54%—Pivotal Cloud Foundry NFS VolumePivotal Cloud Foundry NotificationsPivotal Cloud Foundry SMB Volume16/6/202317/6/2026
Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications: All versions prior to 63; SMB-volume release: All versions prior to 3.1.19; cf-nfs-volume release: 5.0.X versions prior to 5.0.27, 7.1.X versions prior to 7.1.19.
ModificadaAlta (8.8)0.26%—Madewithfuel Better Notifications FOR WP26/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Made with Fuel Better Notifications for WP plugin <= 1.9.2 versions.
ModificadaMedia (6.1)0.54%—Pushassist Push Notifications15/5/202317/6/2026
The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
ModificadaMedia (4.8)0.53%—Jeeng Push Notifications Project Jeeng Push Notifications28/11/202217/6/2026
The Jeeng Push Notifications WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (8.7)0.72%—Amazon Opensearch Notifications11/11/202217/6/2026
OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Custom web-hook etc channels. A potential SSRF issue in OpenSearch Notifications Plugin starting in 2.0.0 and prior to 2.2.1 could allow an existing privileged user to…
ModificadaAlta (8)0.91%—Ultimatesmsnotifications Ultimate SMS Notifications FOR Woocommerce6/9/202217/6/2026
The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First…
ModificadaMedia (4.3)0.51%—Jenkins Build Notifications30/6/202217/6/2026
Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
ModificadaMedia (4.3)0.59%—Jenkins Build Notifications30/6/202217/6/2026
Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
ModificadaAlta (8.8)0.67%—Delitestudio Push Notifications FOR Wordpress24/11/202117/6/2026
Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page.
ModificadaMedia (6.1)0.90%—Feedify WEB Push Notifications10/9/202117/6/2026
The Feedify – Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter found in the ~/includes/base.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.8.
ModificadaMedia (6.1)0.83%—Cozyvision SMS Alert Order Notifications6/9/202117/6/2026
The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.
ModificadaBaja (3.3)0.13%—Google/apple Exposure Notifications28/4/202117/6/2026
GAEN (aka Google/Apple Exposure Notifications) through 2021-04-27 on Android allows attackers to obtain sensitive information, such as a user's location history, in-person social graph, and (sometimes) COVID-19 infection status, because Rolling Proximity Identifiers and MAC addresses are written to the Android system…
ModificadaAlta (8.8)0.72%—Google Exposure Notifications Verification Server31/3/202117/6/2026
A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a carefully crafted request or malicious proxy, to create another user with higher privileges than their own. This occurs…
ModificadaMedia (5.9)2.5%—Exposure Notifications Project Exposure Notifications7/10/202017/6/2026
An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in COVID-19 applications on Android and iOS. The encrypted metadata block with a TX value lacks a checksum, allowing bitflipping to amplify a contamination attack. This can cause metadata deanonymization…
ModificadaMedia (5.7)0.32%—Apple Exposure NotificationsGoogle Exposure Notifications30/9/202017/6/2026
An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in COVID-19 applications on Android and iOS. It allows a user to be put in a position where he or she can be coerced into proving or disproving an exposure notification, because of the persistent state of…
ModificadaMedia (4.3)1.1%—Infosysta In-app & Desktop Notifications1/11/201917/6/2026
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects (with authentication as a Jira user, but without authorization for specific projects) via the plugins/servlet/nfj/NotificationSettings URI.
ModificadaMedia (5.3)1.6%—Infosysta In-app & Desktop Notifications1/11/201917/6/2026
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects without authentication/authorization via the plugins/servlet/nfj/ProjectFilter?searchQuery= URI.
ModificadaMedia (5.3)1.6%—Infosysta In-app & Desktop Notifications31/10/201917/6/2026
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. It is possible to obtain a list of all valid Jira usernames without authentication/authorization via the plugins/servlet/nfj/UserFilter?searchQuery=@ URI.
ModificadaAlta (7.5)2.1%—Infosysta In-app & Desktop Notifications31/10/201917/6/2026
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be read without authentication/authorization. These notifications are then no longer displayed to the…