Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

102 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.35%—Fdfranklin06 Video Embed OptimizerAI7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fdfranklin06 Video Embed Optimizer video-embed-optimizer allows Stored XSS.This issue affects Video Embed Optimizer: from n/a through <= 1.0.0.
AplazadaMedia (4.3)0.65%—Kraken.io Image OptimizerAI9/12/202417/6/2026
Missing Authorization vulnerability in Karim Salman Kraken.io Image Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kraken.io Image Optimizer: from n/a through 2.6.7.
AplazadaMedia (6.1)0.36%—WP Media OptimizerAI6/12/202417/6/2026
The WP Media Optimizer (.webp) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wpmowebp-css-resources’ and 'wpmowebp-js-resources' parameters in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
ModificadaAlta (8.8)0.39%—Shortpixel Image Optimizer1/11/202417/6/2026
Missing Authorization vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShortPixel Image Optimizer: from n/a through <= 5.6.3.
AplazadaMedia (6.5)0.50%—Creative Motion Robin Image OptimizerAI1/11/202417/6/2026
Missing Authorization vulnerability in Creative Motion Robin image optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robin image optimizer: from n/a through 1.6.9.
AnalizadaMedia (4.3)0.32%—Giuliopanda Bulk Images Optimizer18/10/202417/6/2026
The Bulk images optimizer: Resize, optimize, convert to webp, rename … plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_configuration' function in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.6)0.45%—Shortpixel Image OptimizerAI17/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Blind SQL Injection.This issue affects ShortPixel Image Optimizer: from n/a through <= 5.6.3.
AnalizadaCrítica (9.8)0.85%—Siteground Speed Optimizer16/10/202417/6/2026
The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0.12 due to incorrect use of an access control attribute on the switch_php function called via the /switch-php REST API route. This allows…
AplazadaAlta (8.8)1.9%—Image-optimizerAI5/5/202417/6/2026
image-optimizer before 1.7.3 allows PHAR deserialization, e.g., the phar:// protocol in arguments to file_exists().
AplazadaMedia (5.3)0.52%—Siteground Speed OptimizerAI17/4/202412/8/2026
Missing Authorization vulnerability in SiteGround Speed Optimizer.This issue affects Speed Optimizer: from n/a through 7.4.6.
AplazadaMedia (4.3)0.25%—Nosilver4u Ewww Image OptimizerAI10/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in nosilver4u EWWW Image Optimizer ewww-image-optimizer.This issue affects EWWW Image Optimizer: from n/a through <= 7.2.3.
AnalizadaMedia (4.3)0.22%—Wordpress Ping Optimizer Project Wordpress Ping Optimizer10/4/202417/6/2026
The WordPress Ping Optimizer WordPress plugin through 2.35.1.3.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as clearing logs.
ModificadaMedia (4.3)0.20%—Marketingoptimizer Marketing Optimizer29/2/202417/6/2026
The Marketing Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20200925. This is due to missing or incorrect nonce validation via the admin/main-settings-page.php file. This makes it possible for unauthenticated attackers to update the plugin's settings…
ModificadaAlta (8.8)0.21%—Yevhenkotelnytskyi JS & CSS Script Optimizer8/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Yevhen Kotelnytskyi JS & CSS Script Optimizer.This issue affects JS & CSS Script Optimizer: from n/a through 0.3.3.
ModificadaMedia (6.1)0.46%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Teller field.
ModificadaAlta (7.5)0.36%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature.
ModificadaAlta (7.5)0.58%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field.
ModificadaMedia (6.1)0.46%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode field of a container.
ModificadaMedia (5.3)0.38%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field.
ModificadaAlta (7.5)0.58%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field.
ModificadaMedia (4.3)0.47%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing the journal to be displayed, despite the option being disabled.
ModificadaMedia (6.1)0.46%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log.
ModificadaMedia (4.8)0.44%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the User ID field when creating a new system user.
ModificadaMedia (5.5)0.17%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack.
ModificadaMedia (4.8)0.31%—Sesami Cash Point & Transport Optimizer25/12/202317/6/2026
An issue was discovered in SESAMI planfocus CPTO (Cash Point & Transport Optimizer) 6.3.8.6 718. There is XSS via the Name field when modifying a client.