Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.59% | — | Sequelizejs Sequelize-typescript | 24/11/2023 | 17/6/2026 | Prototype Pollution in GitHub repository robinbuschmann/sequelize-typescript prior to 2.1.6. | |
| Modificada | Alta (8.8) | 0.33% | — | Cyberwire PRO Mime Types | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sybre Waaijer Pro Mime Types – Manage file media types plugin <= 1.0.7 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Rolandmurg Current Menu Item FOR Custom Post Types | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Roland Murg Current Menu Item for Custom Post Types plugin <= 1.5 versions. | |
| Modificada | Media (4.8) | 0.32% | — | Totalpress Custom Post Types | 26/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in TotalPress.Org Custom post types, Custom Fields & more plugin <= 4.0.12 versions. | |
| Modificada | Alta (8.8) | 0.44% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 5/10/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.7.3 is able to address this issue. The identifier of… | |
| Modificada | Media (6.1) | 0.38% | — | Pixelgrade Pixtypes | 4/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pixelgrade PixTypes plugin <= 1.4.15 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Pixelgrade Pixtypes | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade PixTypes plugin <= 1.4.14 versions. | |
| Modificada | Media (4.8) | 0.37% | — | GMO Typesquare Webfonts FOR Conoha | 4/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GMO Internet Group, Inc. TypeSquare Webfonts for ConoHa plugin <= 2.0.3 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Wpchill CPO Content Types | 23/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill CPO Content Types plugin <= 1.1.0 versions. | |
| Modificada | Media (4.8) | 0.47% | — | Cozmoslabs Custom Post Types AND Custom Fields Creator | 16/1/2023 | 17/6/2026 | The Custom Post Types and Custom Fields creator WordPress plugin before 2.3.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |
| Modificada | Media (4.2) | 0.42% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 17/10/2022 | 17/6/2026 | The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allow any authenticated users to access some of the plugin features if they manage to get the related nonce | |
| Modificada | Alta (7.2) | 1.1% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 17/10/2022 | 17/6/2026 | The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin | |
| Modificada | Crítica (9.8) | 1.8% | — | Typescript Deep Merge Project Typescript Deep Merge | 9/8/2022 | 17/6/2026 | The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function. | |
| Modificada | Alta (7.2) | 1.3% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 27/6/2022 | 17/6/2026 | The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks | |
| Modificada | Alta (8.8) | 0.55% | — | Typesettercms Typesetter | 25/3/2022 | 9/7/2026 | TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request. | |
| Modificada | Media (4.8) | 0.65% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 28/2/2022 | 17/6/2026 | The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues | |
| Modificada | Alta (8) | 0.54% | — | WP Extra File Types Project WP Extra File Types | 24/1/2022 | 17/6/2026 | The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks | |
| Modificada | Media (5.7) | 0.42% | — | Catchplugins Catch Scroll Progress BARCatchplugins Catch Sticky MenuCatchplugins Catch Themes Demo ImportCatchplugins Catch Under Construction+6 | 18/10/2021 | 17/6/2026 | Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before… | |
| Modificada | Media (6.1) | 0.83% | — | Typesettercms Typesetter | 21/6/2021 | 5/7/2026 | Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes, | |
| Modificada | Media (4.8) | 0.70% | — | Typesettercms Typesetter | 11/12/2020 | 17/6/2026 | Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI. NOTE: the significance of this report is disputed because "admins are considered trustworthy. | |
| Modificada | Alta (7.2) | 16% | — | Typesettercms Typesetter | 19/9/2020 | 17/6/2026 | Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our security policy" and is being fixed for 5.2 | |
| Modificada | Alta (8.8) | 5.9% | — | Microsoft Azure Storage ExplorerMicrosoft TypescriptMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+1 | 14/7/2020 | 17/6/2026 | An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'. | |
| Modificada | Media (4.3) | 0.41% | — | Typesettercms Typesetter | 5/1/2020 | 17/6/2026 | The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability. The logout function of the admin panel is not protected by any CSRF tokens. An attacker can logout the user using this vulnerability. | |
| Modificada | Crítica (9.8) | 2.0% | — | Typestack Class-validator Project Typestack Class-validator | 24/10/2019 | 17/6/2026 | In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most… | |
| Modificada | Alta (8.8) | 0.65% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 14/8/2019 | 17/6/2026 | The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF. |