Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.96% | — | Gstreamer Gst-plugins-goodAI | 6/8/2026 | 23/9/2026 | A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever… | |
| Aplazada | Alta (7.5) | 0.39% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 2/8/2026 | 26/8/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the… | |
| Aplazada | Media (4.3) | 0.25% | — | Cleverplugins Clever Mega Menu FOR Visual ComposerAI | 2/8/2026 | 26/8/2026 | The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public… | |
| Aplazada | Media (5.4) | 0.26% | — | Wpplugins Hide MY WP GhostAI | 30/7/2026 | 30/7/2026 | The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting attacker-controllable HTTP headers, allowing unauthenticated attackers to spoof their IP address to bypass the WP Ghost (Hide My WP Ghost) WordPress plugin before… | |
| Pendiente de análisis | Alta (8.3) | 0.42% | — | Linuxfabrik Monitoring-pluginsAIIcingaAINagiosAI | 29/7/2026 | 30/7/2026 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a malicious or compromised BMC to redirect… | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | Linuxfabrik Monitoring-pluginsAIPython Sqlite3AI | 29/7/2026 | 30/7/2026 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable path from /tmp with os.rename() and allowed a local user controlling the plugin account to place a symlink that would… | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Format Plugins | 28/7/2026 | 5/8/2026 | Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Pendiente de análisis | Baja (3.3) | 0.12% | — | Gstreamer Gst-plugins-goodAIMatroskaAIWebmAI | 28/7/2026 | 28/7/2026 | A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a Matroska or WebM container file. The vulnerability is triggered by a boundary check that does not account for the full size of the data being copied, allowing a… | |
| Aplazada | Alta (7.5) | 0.51% | — | Pickplugins Question AnswerAI | 28/7/2026 | 28/7/2026 | The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id' GET parameter in the user profile template combined with the use of wp_unslash() which removes WordPress's magic… | |
| Aplazada | Media (6.5) | 0.22% | — | 100plugins Open User MAPAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions. | |
| Aplazada | Alta (7.4) | 0.39% | — | Wpplugins Hide MY WP GhostAI | 27/7/2026 | 27/7/2026 | Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. | |
| Aplazada | Media (6.4) | 0.42% | — | 100plugins Open User MAPAI | 24/7/2026 | 24/7/2026 | The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.4.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (5.3) | 0.61% | — | Paymentplugins Payment Plugins FOR StripeAI | 24/7/2026 | 24/7/2026 | The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary… | |
| Aplazada | Media (5.3) | 0.33% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 12/8/2026 | Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 23/7/2026 | Administrator PHP Object Injection in Complianz <= 7.5.0 versions. | |
| Aplazada | Media (4.4) | 0.21% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 23/7/2026 | Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. | |
| Aplazada | Alta (7.2) | 0.32% | — | Fantasticplugins Sumo Reward PointsAI | 23/7/2026 | 23/7/2026 | The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller` class unconditionally granting the… | |
| Analizada | Alta (7.1) | 0.21% | — | Verygoodplugins Whatsapp MCP Server | 20/7/2026 | 18/8/2026 | WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint accepts an absolute… | |
| Pendiente de análisis | Crítica (9.3) | 0.88% | — | Moodle Microsoft 365 AND Microsoft Entra ID PluginsAIMoodle Local O365AI | 16/7/2026 | 16/7/2026 | The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn… | |
| Aplazada | Media (4.9) | 0.44% | — | Cleverplugins SEO BoosterAI | 16/7/2026 | 17/7/2026 | The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Media (4.9) | 0.44% | — | Cleverplugins SEO BoosterAI | 16/7/2026 | 16/7/2026 | The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 1.0% | — | I-plugins Whmcs BridgeAI | 8/7/2026 | 8/7/2026 | The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, with Custom-level access and above, to upload arbitrary files on the affected site's… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Plugins WP DebuggingAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions. | |
| Aplazada | Alta (7.5) | 0.49% | — | Gazebo PluginsAI | 1/7/2026 | 2/7/2026 | An improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted geometry_msgs::Twist message. | |
| Aplazada | Media (5.3) | 0.31% | — | Gravityplugins GravityviewAI | 26/6/2026 | 26/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions. |