Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

88 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.59%—Sequelizejs Sequelize-typescript24/11/202317/6/2026
Prototype Pollution in GitHub repository robinbuschmann/sequelize-typescript prior to 2.1.6.
ModificadaAlta (8.8)0.33%—Cyberwire PRO Mime Types9/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Sybre Waaijer Pro Mime Types – Manage file media types plugin <= 1.0.7 versions.
ModificadaAlta (8.8)0.21%—Rolandmurg Current Menu Item FOR Custom Post Types6/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Roland Murg Current Menu Item for Custom Post Types plugin <= 1.5 versions.
ModificadaMedia (4.8)0.32%—Totalpress Custom Post Types26/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in TotalPress.Org Custom post types, Custom Fields & more plugin <= 4.0.12 versions.
ModificadaAlta (8.8)0.44%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV5/10/202317/6/2026
A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.7.3 is able to address this issue. The identifier of…
ModificadaMedia (6.1)0.38%—Pixelgrade Pixtypes4/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pixelgrade PixTypes plugin <= 1.4.15 versions.
ModificadaAlta (8.8)0.26%—Pixelgrade Pixtypes11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade PixTypes plugin <= 1.4.14 versions.
ModificadaMedia (4.8)0.37%—GMO Typesquare Webfonts FOR Conoha4/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GMO Internet Group, Inc. TypeSquare Webfonts for ConoHa plugin <= 2.0.3 versions.
ModificadaMedia (4.8)0.37%—Wpchill CPO Content Types23/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill CPO Content Types plugin <= 1.1.0 versions.
ModificadaMedia (4.8)0.47%—Cozmoslabs Custom Post Types AND Custom Fields Creator16/1/202317/6/2026
The Custom Post Types and Custom Fields creator WordPress plugin before 2.3.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).
ModificadaMedia (4.2)0.42%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV17/10/202217/6/2026
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce
ModificadaAlta (7.2)1.1%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV17/10/202217/6/2026
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin
ModificadaCrítica (9.8)1.8%—Typescript Deep Merge Project Typescript Deep Merge9/8/202217/6/2026
The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function.
ModificadaAlta (7.2)1.3%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV27/6/202217/6/2026
The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks
ModificadaAlta (8.8)0.55%—Typesettercms Typesetter25/3/20229/7/2026
TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.
ModificadaMedia (4.8)0.65%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV28/2/202217/6/2026
The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues
ModificadaAlta (8)0.54%—WP Extra File Types Project WP Extra File Types24/1/202217/6/2026
The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks
ModificadaMedia (5.7)0.42%—Catchplugins Catch Scroll Progress BARCatchplugins Catch Sticky MenuCatchplugins Catch Themes Demo ImportCatchplugins Catch Under Construction+618/10/202117/6/2026
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before…
ModificadaMedia (6.1)0.83%—Typesettercms Typesetter21/6/20215/7/2026
Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,
ModificadaMedia (4.8)0.70%—Typesettercms Typesetter11/12/202017/6/2026
Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI. NOTE: the significance of this report is disputed because "admins are considered trustworthy.
ModificadaAlta (7.2)16%—Typesettercms Typesetter19/9/202017/6/2026
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our security policy" and is being fixed for 5.2
ModificadaAlta (8.8)5.9%—Microsoft Azure Storage ExplorerMicrosoft TypescriptMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+114/7/202017/6/2026
An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'.
ModificadaMedia (4.3)0.41%—Typesettercms Typesetter5/1/202017/6/2026
The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability. The logout function of the admin panel is not protected by any CSRF tokens. An attacker can logout the user using this vulnerability.
ModificadaCrítica (9.8)2.0%—Typestack Class-validator Project Typestack Class-validator24/10/201917/6/2026
In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most…
ModificadaAlta (8.8)0.65%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV14/8/201917/6/2026
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.