Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 1.1% | — | Gorilla SchemaAI | 1/7/2024 | 17/6/2026 | gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens it up to malicious attacks regarding memory allocations, taking advantage of the sparse slice functionality. Any use of `schema.Decoder.Decode()`… | |
| Aplazada | Media (6.5) | 0.59% | — | WP Schema PRO Schema PROAI | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WP SCHEMA PRO Schema Pro.This issue affects Schema Pro: from n/a through 2.7.8. | |
| Aplazada | Media (4.3) | 0.25% | — | Schemaapp Schema APP Structured DataAI | 14/6/2024 | 17/6/2026 | The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the MarkUpdate function. This makes it possible for unauthenticated attackers to update and delete post metadata via a… | |
| Modificada | Media (4.3) | 0.34% | — | Schemaapp Schema APP Structured Data | 24/5/2024 | 17/6/2026 | The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the MarkupUpdate function in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber access or higher, to update or delete… | |
| Aplazada | Alta (8.1) | 0.80% | — | Json-schema-ref-parserAI | 20/5/2024 | 17/6/2026 | A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle()`, `parse()`, `resolve()`, `dereference() functions. | |
| Aplazada | Media (6.4) | 0.33% | — | Schema AND Structured Data FOR WP AND AMPAI | 23/4/2024 | 17/6/2026 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "How To" and "FAQ" Blocks in all versions up to, and including, 1.29 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (4.3) | 0.45% | — | Brainstormforce Schema | 25/3/2024 | 17/6/2026 | The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode | |
| Modificada | Media (5.4) | 0.37% | — | Magazine3 Schema & Structured Data FOR WP & AMP | 29/2/2024 | 17/6/2026 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom schema in all versions up to, and including, 1.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Media (4.3) | 0.43% | — | Magazine3 Schema & Structured Data FOR WP & AMP | 29/2/2024 | 17/6/2026 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saswp_reviews_form_render' function in all versions up to, and including, 1.26. This makes it possible for authenticated attackers, with contributor access and… | |
| Modificada | Media (5.4) | 0.33% | — | Structured-data-for-wp Download Schema & Structured Data FOR WP & AMP | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magazine3 Schema & Structured Data for WP & AMP allows Stored XSS.This issue affects Schema & Structured Data for WP & AMP: from n/a through 1.23. | |
| Modificada | Media (5.4) | 0.34% | — | Magazine3 Schema & Structured Data FOR WP & AMP | 31/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magazine3 Schema & Structured Data for WP & AMP allows Stored XSS.This issue affects Schema & Structured Data for WP & AMP: from n/a through 1.25. | |
| Modificada | Media (4.3) | 0.43% | — | Radiustheme Review Schema | 31/1/2024 | 17/6/2026 | The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtrs_review_edit() function in all versions up to, and including, 2.1.14. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.30% | — | Brainstormforce Schema | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro: from n/a through 2.7.7. | |
| Modificada | Media (4.3) | 0.39% | — | Websitescanner Remove Schema | 1/7/2023 | 17/6/2026 | The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the validate() function. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted… | |
| Analizada | Alta (8.8) | 0.26% | — | Brainstormforce Schema | 26/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Terakoya Markup (json-ld) Structured IN Schema.org | 21/2/2023 | 17/6/2026 | The Markup (JSON-LD) structured in schema.org WordPress plugin through 4.8.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.52% | — | Schema Project Schema | 12/7/2022 | 17/6/2026 | The schema (aka Embedding schema.org vocabulary) extension before 1.13.1 and 2.x before 2.5.1 for TYPO3 allows XSS. | |
| Modificada | Media (5.4) | 0.60% | — | Fivestarplugins Five Star Business Profile AND Schema | 21/2/2022 | 17/6/2026 | The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of… | |
| Modificada | Crítica (9.8) | 3.8% | — | Json-schema Project Json-schemaDebian Linux | 13/11/2021 | 17/6/2026 | json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Modificada | Alta (7.5) | 2.1% | — | Schema-inspector Project Schema-inspectorNetapp E-series Performance AnalyzerNetapp Oncommand Insight | 19/3/2021 | 17/6/2026 | Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example… | |
| Modificada | Alta (8) | 2.1% | — | Databaseschemareader Project Dbschemareader | 4/11/2020 | 17/6/2026 | DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened. | |
| Modificada | Alta (7.5) | 1.5% | — | Simpl-schema Project Simpl-schema | 7/10/2020 | 17/6/2026 | This affects the package simpl-schema before 1.10.2. | |
| Modificada | Crítica (9.8) | 1.4% | — | Schema-inspector Project Schema-inspector | 22/1/2020 | 17/6/2026 | In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector. | |
| Analizada | Media (6.1) | 0.90% | — | Brainstormforce Schema | 21/8/2019 | 17/6/2026 | The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page. | |
| Modificada | Alta (8.8) | 0.87% | — | Tibco Messaging - Apache Kafka Distribution - Schema Repository | 6/11/2018 | 17/6/2026 | The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition contains a vulnerability which may allow an attacker to perform… |