Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.42% | — | Templateinvaders TI Woocommerce WishlistAI | 13/12/2025 | 17/6/2026 | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the plugin accepting hidden fields and not limiting the values or data that can input and is later output. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (4.3) | 0.24% | — | Contact Form 7 Drag AND Drop Template BuilderAI | 12/12/2025 | 17/6/2026 | The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized post duplication due to a missing capability check on the 'rednumber_duplicate' function in all versions up to, and including, 6.3.3. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (6.4) | 0.22% | — | APP Landing Template BlocksAI | 12/12/2025 | 17/6/2026 | The App Landing Template Blocks for WPBakery (Visual Composer) Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'atvc_video_play' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Analizada | Crítica (9.3) | 0.52% | — | Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+8 | 9/12/2025 | 17/6/2026 | Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocumented page. Attackers can exploit the hidden endpoint by using the hard-coded password 'Selea781830' to enable configuration upload and overwrite device settings. | |
| Modificada | Alta (8.5) | 0.25% | — | Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+8 | 9/12/2025 | 17/6/2026 | Selea Targa IP OCR-ANPR Camera contains a cross-site request forgery vulnerability that allows attackers to create administrative users without authentication. Attackers can craft a malicious web page that submits a form to add a new admin user with full system privileges when a logged-in user visits the page. | |
| Analizada | Media (5.1) | 0.30% | — | Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+8 | 9/12/2025 | 17/6/2026 | Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session. | |
| Analizada | Crítica (9.3) | 2.6% | — | Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+8 | 9/12/2025 | 17/6/2026 | Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion… | |
| Analizada | Alta (8.7) | 0.47% | — | Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+8 | 9/12/2025 | 17/6/2026 | Selea Targa IP OCR-ANPR Camera contains an unauthenticated vulnerability that allows remote attackers to access live video streams without authentication. Attackers can directly connect to RTP/RTSP or M-JPEG streams by requesting specific endpoints like p1.mjpg or p1.264 to view camera footage. | |
| Aplazada | Media (4.3) | 0.35% | — | Wpgogo Custom Field TemplateAI | 9/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Hiroaki Miyashita Custom Field Template custom-field-template allows Retrieve Embedded Sensitive Data.This issue affects Custom Field Template: from n/a through <= 2.7.6. | |
| Aplazada | Alta (8.8) | 14% | — | Starter TemplatesAI | 6/12/2025 | 17/6/2026 | The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This makes it possible… | |
| Aplazada | Media (4.3) | 0.18% | — | Wpkoi Templates FOR ElementorAI | 13/11/2025 | 17/6/2026 | Missing Authorization vulnerability in wpkoithemes WPKoi Templates for Elementor wpkoi-templates-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPKoi Templates for Elementor: from n/a through <= 3.4.4. | |
| Aplazada | Media (5.3) | 0.32% | — | Bitplatform BoilerplateAIMicrosoft Visual StudioAIMicrosoft NETAI | 13/11/2025 | 17/6/2026 | Bitplatform Boilerplate is a Visual studio and .NET project template. Versions prior to 9.11.3 are affected by a cross-site scripting (XSS) vulnerability in the WebInteropApp/WebAppInterop, potentially allowing attackers to inject malicious scripts that compromise the security and integrity of web applications.… | |
| Aplazada | Media (5.9) | 0.18% | — | Villatheme Email Template Customizer FOR WoocommerceAI | 29/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Email Template Customizer for WooCommerce email-template-customizer-for-woo allows Stored XSS.This issue affects Email Template Customizer for WooCommerce: from n/a through <= 1.2.17. | |
| Aplazada | Media (4.9) | 0.15% | — | Codeless Slider TemplatesAI | 27/10/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Codeless Slider Templates slider-templates allows Server Side Request Forgery.This issue affects Slider Templates: from n/a through <= 1.0.3. | |
| Aplazada | Media (4.3) | 0.14% | — | Clifton Griffin Simple Content Templates FOR Blog Posts AND PagesAI | 27/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Clifton Griffin Simple Content Templates for Blog Posts & Pages simple-post-template allows Cross Site Request Forgery.This issue affects Simple Content Templates for Blog Posts & Pages: from n/a through <= 2.2.61. | |
| Aplazada | Media (4.3) | 0.13% | — | Disable Content Editor FOR Specific TemplateAI | 24/10/2025 | 17/6/2026 | The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing nonce validation on template configuration updates. This makes it possible for unauthenticated attackers to add or delete template… | |
| Aplazada | Media (6.9) | 0.34% | — | Mediawiki Multiboilerplate ExtensionAIWikimedia MediawikiAI | 20/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - MultiBoilerplate Extensionmaste allows Stored XSS.This issue affects Mediawiki - MultiBoilerplate Extensionmaste: from master before 1.39. | |
| Analizada | Alta (7.5) | 0.31% | — | Flocksafety License Plate Reader Firmware | 2/10/2025 | 17/6/2026 | Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartext in production firmware. | |
| Aplazada | Media (5.3) | 0.28% | — | Templateinvaders TI Woocommerce WishlistAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.10.0. | |
| Aplazada | Media (6.5) | 0.21% | — | Wpkoi Templates FOR ElementorAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpkoithemes WPKoi Templates for Elementor wpkoi-templates-for-elementor allows DOM-Based XSS.This issue affects WPKoi Templates for Elementor: from n/a through <= 3.4.3. | |
| Aplazada | Media (4.3) | 0.14% | — | Steve Truman WP Email TemplateAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Steve Truman WP Email Template wp-email-template allows Cross Site Request Forgery.This issue affects WP Email Template: from n/a through <= 2.8.5. | |
| Aplazada | Media (6.4) | 0.24% | — | Templatescoder Spexo Addons FOR ElementorAI | 24/8/2025 | 17/6/2026 | The Spexo Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.0.23 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Crítica (10) | 0.49% | — | Wpdeveloper TemplatelyAI | 20/8/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data. This issue affects Templately: from n/a through 3.2.7. | |
| Aplazada | Media (4.3) | 0.41% | 💥 PoC | Eventontemplates Eventon LiteAI | 15/8/2025 | 17/6/2026 | The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4.6 via the add_single_eventon and add_eventon shortcodes due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from… | |
| Aplazada | Media (6.5) | 0.17% | — | Wpbakery TemplateraAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbakery Templatera templatera allows DOM-Based XSS.This issue affects Templatera: from n/a through <= 2.3.0. |