Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
720 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Social Slider FeedAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions. | |
| Aplazada | Crítica (9.1) | 0.82% | — | Metaslider Responsive SliderAI | 15/6/2026 | 17/6/2026 | Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions. | |
| Aplazada | Media (6.3) | 0.25% | — | Ljapps WP Google Review SliderAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions. | |
| Aplazada | Media (5.3) | 0.10% | — | Wordpress Lazy Content SliderAI | 15/6/2026 | 17/6/2026 | WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_admin.php to modify… | |
| Aplazada | Media (5.3) | 0.24% | — | Essentialplugin WP Logo Showcase Responsive Slider AND CarouselAI | 11/6/2026 | 23/7/2026 | Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider and Carousel allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Logo Showcase Responsive Slider and Carousel: from n/a through 3.6. | |
| Aplazada | Media (4.6) | 0.14% | — | Yith Woocommerce Product Slider CarouselAI | 11/6/2026 | 29/9/2026 | Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Request Forgery. This issue affects YITH WooCommerce Product Slider Carousel: from n/a through 1.16.0. | |
| Aplazada | Alta (8.8) | 0.29% | — | Apptha Slider GalleryAI | 9/6/2026 | 21/7/2026 | Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the albid parameter. Attackers can send GET requests with crafted SQL payloads in the albid parameter to extract sensitive database information… | |
| Aplazada | Alta (8.7) | 0.64% | — | Apptha Slider GalleryAI | 9/6/2026 | 21/7/2026 | Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the imgname parameter. Attackers can send requests to asgallDownload.php with directory traversal sequences ../ to access sensitive files outside the intended directory. | |
| Aplazada | Media (6.5) | 0.42% | — | Themepunch Slider RevolutionAI | 9/6/2026 | 23/7/2026 | The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. This is due to three compounding design flaws: (1) the plugin leaks a valid backend AJAX nonce (revslider_actions) to all authenticated users including Subscribers via the admin_footer hook; (2) the… | |
| Aplazada | Media (4.9) | 0.84% | — | Nextendweb Smart Slider 3AI | 6/6/2026 | 23/7/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can… | |
| Aplazada | Media (6.4) | 0.33% | — | Simple SEO SlideshowAI | 6/6/2026 | 23/7/2026 | The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Crítica (10) | 2.0% | 💥 Exploit | Shapedplugin LLC Product Slider PRO FOR WoocommerceAI | 5/6/2026 | 23/7/2026 | Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4. | |
| Aplazada | Alta (8.8) | 0.26% | — | Google Review SliderAI | 4/6/2026 | 22/7/2026 | WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with malicious 'tid' values to extract… | |
| Aplazada | Media (4.3) | 0.26% | — | Themepunch Slider RevolutionAI | 2/6/2026 | 22/7/2026 | The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (4.3) | 0.28% | — | Themepunch Slider RevolutionAI | 2/6/2026 | 22/7/2026 | The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw social media API… | |
| Aplazada | Alta (8.7) | 0.60% | — | Banana SlidesAI | 1/6/2026 | 22/7/2026 | Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated attackers to read arbitrary image-format files outside the intended uploads directory by exploiting an incomplete path prefix check… | |
| Aplazada | Media (6.5) | 0.22% | — | Averta Master SliderAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider allows DOM-Based XSS. This issue affects Master Slider: from n/a through 3.10.8. | |
| Aplazada | Media (6.4) | 0.32% | — | Content SlideshowAI | 27/5/2026 | 17/6/2026 | The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject… | |
| Aplazada | Media (6.4) | 0.32% | — | Jquery GoogleslidesAI | 27/5/2026 | 17/6/2026 | The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortcode in all versions up to, and including, 1.3. This is due to insufficient input sanitization and output escaping on user supplied attributes (userid, albumid, authkey, imgmax, maxresults, random,… | |
| Aplazada | Alta (8.6) | 0.18% | — | Flash Slideshow Maker ProfessionalAI | 25/5/2026 | 24/7/2026 | Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload and paste it into the Name and Code fields of the Help > Register dialog… | |
| Aplazada | Alta (8.6) | 0.18% | — | Socusoft 3GP Photo SlideshowAI | 25/5/2026 | 24/7/2026 | Socusoft 3GP Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft malicious input in the Registration Name and Registration Key fields to overwrite the SEH chain… | |
| Aplazada | Alta (8.6) | 0.18% | — | Socusoft Ipod Photo SlideshowAI | 25/5/2026 | 24/7/2026 | SocuSoft iPod Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft malicious input in the Registration Name and Registration Key fields to trigger a stack-based… | |
| Aplazada | Alta (8.6) | 0.18% | — | Socusoft DVD Photo Slideshow ProfessionalAI | 25/5/2026 | 23/7/2026 | SocuSoft DVD Photo Slideshow Professional 8.07 contains a stack-based buffer overflow vulnerability in the registration name field that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious text file with carefully constructed payload containing… | |
| Aplazada | Media (4.3) | 0.42% | — | Slider BY SoliloquyAI | 22/5/2026 | 23/7/2026 | The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 via the map_meta_cap. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract draft slider… | |
| Aplazada | Media (5.3) | 0.36% | — | Themepunch Slider RevolutionAI | 20/5/2026 | 24/7/2026 | The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes it possible for unauthenticated attackers to extract sensitive data including published password-protected post, page, and product content. |