Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

70 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.56%—Wpmudev SmartcrawlAI2/5/202417/6/2026
The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to unauthorized ld+json description injection due to a missing capability check on the save_settings function in all versions up to, and including, 3.10.2. This makes it possible for unauthenticated attackers to save…
ModificadaMedia (4.8)0.34%—Wpmudev Broken Link Checker15/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Broken Link Checker allows Stored XSS.This issue affects Broken Link Checker: from n/a through 2.2.3.
ModificadaAlta (8.6)0.78%💥 PoCWpmudev Hustle13/3/202417/6/2026
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via hardcoded API Keys. This makes it possible for unauthenticated attackers to extract sensitive data including PII.
AnalizadaAlta (7.5)0.66%—Cloudevents GO SDK6/3/202417/6/2026
Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints. When the transport is…
ModificadaAlta (7.5)0.48%—Wpmudev Defender Security8/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPMU DEV Defender Security – Malware Scanner, Login Security & Firewall.This issue affects Defender Security – Malware Scanner, Login Security & Firewall: from n/a through 4.1.0.
ModificadaAlta (7.5)0.76%—Wpmudev Smartcrawl18/12/202317/6/2026
The SmartCrawl WordPress plugin before 3.8.3 does not prevent unauthorised users from accessing password-protected posts' content.
ModificadaMedia (5.3)2.2%💥 ExploitWpmudev Defender Security16/10/202317/6/2026
The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.
ModificadaMedia (4.3)0.56%—Wpmudev Defender Security12/7/202317/6/2026
The Defender Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.6. This is due to missing or incorrect nonce validation on the verify_otp_login_time() function. This makes it possible for unauthenticated attackers to verify a one time login via a forged…
ModificadaMedia (6.1)0.56%—Wpmudev Broken Link Checker8/4/202317/6/2026
A vulnerability was found in Broken Link Checker Plugin up to 1.10.5 on WordPress. It has been rated as problematic. Affected by this issue is the function print_module_list/show_warnings_section_notice/status_text/ui_get_action_links. The manipulation leads to cross site scripting. The attack may be launched…
ModificadaMedia (6.1)0.79%—Wpmudev Smush Image Compression AND Optimization30/5/202217/6/2026
The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back in an admin page when uploading a malicious preset configuration, leading to a Reflected Cross-Site Scripting. For the attack to be successful, an attacker would need an admin to upload a malicious…
ModificadaAlta (8.8)0.65%—Wpmudev Custom Sidebars14/8/201917/6/2026
The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.
ModificadaAlta (8.8)0.65%—Wpmudev Custom Sidebars14/8/201917/6/2026
The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions.
ModificadaAlta (7.5)2.5%—Wpmudev Smush Image Compression AND Optimization6/10/201717/6/2026
The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal.
ModificadaMedia (6.9)0.35%—Udev Project Udev25/1/201116/6/2026
The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via crafted USB data, as demonstrated by keyboard and mouse data sent by malware on a smartphone that the…
ModificadaMedia (4)2.3%—Dracut Project DracutUdev Project Udev7/12/201016/6/2026
plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.
ModificadaBaja (2.1)0.54%—Udev Project UdevSuse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise Desktop+417/4/200916/6/2026
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
ModificadaAlta (7.2)80%💥 ExploitUdev Project UdevSuse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise Desktop+517/4/200916/6/2026
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
ModificadaMedia (4.4)0.32%—NzbgetUudeview16/5/200816/6/2026
uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.
ModificadaAlta (7.2)0.37%—Uudeview31/12/200416/6/2026
UUDeview 0.5.20 and earlier handles temporary files insecurely during decoding, with unknown attack vectors and impact.
ModificadaAlta (10)24%💥 ExploitOpenpkgUudeviewWinzipGentoo Linux23/11/200416/6/2026
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.
Orbitaley — Vulnerabilidades