Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

98 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.40%—Stormconsultancy Oauth Twitter Feed FOR Developers1/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy (Storm Consultancy) oAuth Twitter Feed for Developers plugin <= 2.3.0 versions.
ModificadaMedia (4.8)0.37%—Devbuddy Twitter Feed25/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eji Osigwe DevBuddy Twitter Feed plugin <= 4.0.0 versions.
ModificadaCrítica (9.8)46%💥 ExploitMiniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin)29/6/202317/6/2026
The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for…
ModificadaMedia (6.1)0.59%—Bestwebsoft Twitter31/5/202317/6/2026
A vulnerability was found in BestWebSoft Twitter Plugin up to 1.3.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function twttr_settings_page of the file twitter.php. The manipulation of the argument twttr_url_twitter/bws_license_key/bws_license_plugin leads to cross site…
ModificadaAlta (8.8)0.43%—Bestwebsoft Twitter31/5/202316/6/2026
A vulnerability was found in BestWebSoft Twitter Plugin up to 2.14 on WordPress. It has been classified as problematic. Affected is the function twttr_settings_page of the file twitter.php of the component Settings Page. The manipulation leads to cross-site request forgery. It is possible to launch the attack…
ModificadaAlta (8.8)0.25%—Smashballoon Custom Twitter Feeds29/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions.
ModificadaAlta (8.8)0.26%—Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin)23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
ModificadaMedia (4.8)0.37%—Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin)25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
ModificadaAlta (7.5)1.1%—Twitter Recommendation Algorithm3/4/202317/6/2026
The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coordinate negative signals regarding a target account, such as unfollowing, muting, blocking, and reporting, as exploited in the wild in…
ModificadaAlta (8.1)1.8%—IRC Twitter Announcer BOT Project IRC Twitter Announcer BOT20/3/202317/6/2026
A vulnerability, which was classified as critical, was found in Zarthus IRC Twitter Announcer Bot up to 1.1.0. This affects the function get_tweets of the file lib/twitterbot/plugins/twitter_announcer.rb. The manipulation of the argument tweet leads to command injection. It is possible to initiate the attack remotely.…
ModificadaMedia (6.1)0.52%—Twitter-post-fetcher Project Twitter-post-fetcher29/12/202217/6/2026
A vulnerability classified as problematic has been found in Twitter-Post-Fetcher up to 17.x. This affects an unknown part of the file js/twitterFetcher.js of the component Link Target Handler. The manipulation leads to use of web link to untrusted target with window.opener access. It is possible to initiate the attack…
ModificadaMedia (5.4)0.65%—Bplugins Easy Twitter Feed18/10/202117/6/2026
The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode
ModificadaMedia (6.1)0.90%—Twitter Friends Widget Project Twitter Friends Widget9/9/202117/6/2026
The Twitter Friends Widget WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the pmc_TF_user and pmc_TF_password parameter found in the ~/twitter-friends-widget.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.1.
ModificadaMedia (5.9)0.88%—Twitter-stream Project Twitter-stream19/2/202117/6/2026
In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused).
ModificadaMedia (5.4)86%💥 ExploitTwitter-server29/12/202017/6/2026
server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.
ModificadaMedia (5.8)1.8%—Twitter Secure Headers23/1/202017/6/2026
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0. If user-supplied input was passed into append/override_content_security_policy_directives, a semicolon could be injected leading to directive injection. This could be used to e.g.…
ModificadaMedia (5.8)1.1%—Twitter Secure Headers23/1/202017/6/2026
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into append/override_content_security_policy_directives, a newline could be injected leading to limited header injection. Upon seeing a newline in the…
ModificadaAlta (7.4)1.0%—Twitter KIT7/10/201917/6/2026
The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned certificates, there are certain implementation errors such as a lack of hostname verification. NOTE: this is an end-of-life product.
ModificadaMedia (6.1)0.91%—Rimons Twitter Widget Project Rimons Twitter Widget20/8/201917/6/2026
The rimons-twitter-widget plugin before 1.3 for WordPress has XSS.
ModificadaMedia (6.1)1.7%💥 ExploitBestwebsoft Twitter Button12/8/201917/6/2026
The twitter-plugin plugin before 2.55 for WordPress has XSS.
ModificadaAlta (8.8)0.69%—Wpdeveloper Twitter Cards Meta12/8/201917/6/2026
The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.
ModificadaMedia (6.1)0.92%—Wpdeveloper Twitter Cards Meta12/8/201917/6/2026
The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS.
ModificadaMedia (5.4)0.38%—Twitter KIT6/5/201917/6/2026
This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. In the final step of "Login with Twitter" authentication information…
ModificadaAlta (8.8)1.8%—Jenkins Twitter30/4/201917/6/2026
Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaMedia (6.1)1.0%—Webdados Open Graph FOR Facebook, Google+ AND Twitter Card Tags14/5/201817/6/2026
Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Orbitaley — Vulnerabilidades