Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

216 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.3)0.76%—Request A Quote FOR Woocommerce AND ElementorAI23/11/202417/6/2026
The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation plugin for WordPress is vulnerable to arbitrary shortcode execution via fire_contact_form AJAX action in all versions up to, and including, 1.4. This is due to the software allowing users to…
AnalizadaMedia (6.1)0.36%—Scriptonite Music Request Manager12/9/202417/6/2026
The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators
AnalizadaMedia (6.1)0.33%—Scriptonite Music Request Manager12/9/202417/6/2026
The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
AnalizadaMedia (6.1)0.19%—Scriptonite Music Request Manager12/9/202417/6/2026
The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
AnalizadaAlta (7.8)0.19%—Steveklabnik Request Store23/8/202417/6/2026
RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users to execute arbitrary code. This version was published in 2017, and most production environments do not allow access for…
AnalizadaMedia (5.9)0.37%—Emarketdesign Request A Quote23/7/202417/6/2026
The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AplazadaAlta (8.1)0.43%—Woocommerce Warranty RequestsAI19/6/202417/6/2026
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.1.9.
ModificadaMedia (5.3)0.31%—Woocommerce Returns AND Warranty Requests14/6/202417/6/2026
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.
ModificadaMedia (6.5)0.36%—Woocommerce Returns AND Warranty Requests14/6/202417/6/2026
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.
AplazadaMedia (5.6)0.34%—RequestsAI20/5/202417/6/2026
Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of `verify`. This behavior…
AplazadaMedia (5.5)0.36%—SAP MY Travel RequestsAI14/5/202417/6/2026
SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the confidentiality, integrity and…
ModificadaMedia (5.4)0.32%—Whodunit Gdpr Data Request Form8/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Audrasjb GDPR Data Request Form allows Stored XSS.This issue affects GDPR Data Request Form: from n/a through 1.6.
ModificadaMedia (6.5)0.94%—Xwiki Change Request4/12/202317/6/2026
XWiki Change Request is an XWiki application allowing to request changes on a wiki without publishing directly the changes. Change request allows to edit any page by default, and the changes are then exported in an XML file that anyone can download. So it's possible for an attacker to obtain password hash of users by…
ModificadaAlta (7.5)0.60%—Bestpractical Request Tracker3/11/202317/6/2026
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.
ModificadaAlta (7.5)0.70%—Bestpractical Request Tracker3/11/202317/6/2026
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.
ModificadaAlta (7.5)0.72%—Bestpractical Request Tracker3/11/202317/6/2026
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.
ModificadaCrítica (9.6)71%—Xwiki Change Request12/10/202317/6/2026
Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. Starting in version 0.11 and prior to version 1.9.2, it's possible for a user without any specific right to perform script injection and remote code execution just by inserting an appropriate title when…
ModificadaAlta (7.5)0.68%—Jenkins Bitbucket Push AND Pull Request6/9/202317/6/2026
Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted…
ModificadaMedia (6.1)0.38%—Woocommerce Returns AND Warranty Requests30/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Returns and Warranty Requests plugin <= 2.1.6 versions.
ModificadaAlta (7.8)0.73%—Github Pull Requests AND Issues11/7/202317/6/2026
Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability
ModificadaAlta (7.5)0.74%—Requests-xml Project Requests-xml29/6/202317/6/2026
requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.
ModificadaMedia (4.8)0.37%—Piwebsolution Cancel Order Request / Return Order / Repeat Order / Reorder FOR Woocommerce26/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Cancel order request / Return order / Repeat Order / Reorder for WooCommerce plugin <= 1.3.2 versions.
ModificadaMedia (6.1)3.0%—Python RequestsFedoraproject Fedora26/5/202317/6/2026
Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rebuild_proxies` to reattach the `Proxy-Authorization` header to requests. For HTTP connections sent through the tunnel,…
ModificadaMedia (5.3)0.52%—Jenkins Assembla Merge Request Builder12/4/202317/6/2026
A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.
ModificadaMedia (6.5)6.6%—Rbaskets Request Baskets31/3/20239/7/2026
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.