Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.38% | — | Wpkube Authors ListAI | 11/11/2025 | 17/6/2026 | The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6.1 via the via arbitrary method call from Authors_List_Shortcode class. This makes it possible for authenticated attackers, with Contributor-level access and above, to call methods such as… | |
| Aplazada | Media (6.5) | 0.22% | — | Themeplugs AuthorsyAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeplugs Authorsy authorsy allows Stored XSS.This issue affects Authorsy: from n/a through <= 1.0.5. | |
| Aplazada | Media (5.9) | 0.22% | — | Russelljamieson AuthorsureAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson AuthorSure authorsure allows Stored XSS.This issue affects AuthorSure: from n/a through <= 2.3. | |
| Analizada | Media (6.9) | 0.56% | — | Cisa Thorium | 17/9/2025 | 17/6/2026 | CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote attacker could cause a crash by providing a specially crafted email address or response. Fixed in commit 6a65a27. | |
| Analizada | Media (5.3) | 0.43% | — | Cisa Thorium | 17/9/2025 | 17/6/2026 | CISA Thorium accepts a stream split size of zero then divides by this value. A remote, authenticated attacker could cause the service to crash. Fixed in commit 89101a6. | |
| Analizada | Baja (2.3) | 0.20% | — | Cisa Thorium | 17/9/2025 | 17/6/2026 | CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch service. Fixed in 1.1.2. | |
| Analizada | Baja (2.3) | 0.28% | — | Cisa Thorium | 17/9/2025 | 17/6/2026 | CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log in after a password reset. Fixed in 1.1.1. | |
| Analizada | Media (6.9) | 0.56% | — | Cisa Thorium | 17/9/2025 | 17/6/2026 | CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker can send unlimited messages to a user who is pending verification. Fixed in 1.1.1 by adding a rate limit set by default to 10 minutes. | |
| Analizada | Media (5.3) | 0.30% | — | Cisa Thorium | 17/9/2025 | 17/6/2026 | CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify LDAP authorization data such as group memberships. Fixed in 1.1.1. | |
| Analizada | Media (5.3) | 0.47% | — | Cisa Thorium | 17/9/2025 | 17/6/2026 | CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated attacker could access arbitrary files subject to file system permissions. Fixed in 1.1.2. | |
| Aplazada | Media (4.3) | 0.14% | — | Wpkube Authors ListAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPKube Authors List authors-list allows Cross Site Request Forgery.This issue affects Authors List: from n/a through <= 2.0.6.2. | |
| Aplazada | Media (5.5) | 0.32% | — | John Luetke Media AuthorAI | 5/9/2025 | 5/10/2026 | Incorrect Privilege Assignment vulnerability in John Luetke Media Author media-author allows Privilege Escalation.This issue affects Media Author: from n/a through <= 1.0.4. | |
| Aplazada | Baja (2.8) | 0.17% | — | Heimdalsecurity ThorAI | 20/7/2025 | 17/6/2026 | Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments." | |
| Aplazada | Media (6.5) | 0.19% | — | A Jones Simply Guest Author NameAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A. Jones (Simply) Guest Author Name guest-author-name allows DOM-Based XSS.This issue affects (Simply) Guest Author Name: from n/a through <= 4.36. | |
| Aplazada | Media (5.3) | 0.28% | — | Zealousweb Accept Authorize.net Payments Using Contact Form 7AI | 27/6/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Authorize.NET Payments Using Contact Form 7 accept-authorize-net-payments-using-contact-form-7 allows Retrieve Embedded Sensitive Data.This issue affects Accept Authorize.NET Payments Using Contact Form 7: from n/a through <= 2.5. | |
| Aplazada | Media (5.7) | 0.33% | — | AuthorinoAI | 9/6/2025 | 17/6/2026 | A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster | |
| Aplazada | Media (5.7) | 0.30% | — | Redhat AuthorinoAI | 9/6/2025 | 17/6/2026 | The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with developer persona to add callbacks to be executed to HTTP endpoints once the authorization process is completed. It was found that an attacker with developer persona access… | |
| Aplazada | Alta (7.1) | 0.15% | — | David Shabtai Post AuthorAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in David Shabtai Post Author post-author allows Stored XSS.This issue affects Post Author: from n/a through <= 1.1.1. | |
| Aplazada | Alta (7.1) | 0.27% | — | Sftranna Ec-authorizenetAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sftranna EC Authorize.net ec-authorizenet allows Reflected XSS.This issue affects EC Authorize.net: from n/a through <= 0.3.3. | |
| Aplazada | Media (6.5) | 0.20% | — | Lloyd Saunders Author BOX After PostsAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lloyd Saunders Author Box After Posts author-box-after-posts allows Stored XSS.This issue affects Author Box After Posts: from n/a through <= 1.6. | |
| Aplazada | Media (4.3) | 0.14% | — | Sanjeev Mohindra Author BOX With Different DescriptionAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sanjeev Mohindra Author Box Plugin With Different Description author-box-with-different-description allows Cross Site Request Forgery.This issue affects Author Box Plugin With Different Description: from n/a through <= 1.3.5. | |
| Analizada | Media (4.3) | 0.17% | — | Jfarthing Custom Author Base | 15/5/2025 | 17/6/2026 | The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Aplazada | Alta (7.5) | 0.77% | — | Publishpress AuthorsAI | 7/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress PublishPress Authors publishpress-authors allows PHP Local File Inclusion.This issue affects PublishPress Authors: from n/a through <= 4.7.5. | |
| Aplazada | Media (4.3) | 0.17% | — | Hossni Mubarak Cool Author BOXAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak Cool Author Box hm-cool-author-box-widget allows Cross Site Request Forgery.This issue affects Cool Author Box: from n/a through <= 3.0.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | Claire Ryan Author ShowcaseAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Claire Ryan Author Showcase author-showcase allows Reflected XSS.This issue affects Author Showcase: from n/a through <= 1.4.3. |