Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.17% | — | Wpwebinfotech Social Auto Poster | 24/7/2024 | 17/6/2026 | The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete post meta and plugin options. | |
| Modificada | Alta (7.5) | 0.29% | — | Wpwebinfotech Social Auto Poster | 24/7/2024 | 17/6/2026 | The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.3.14. This makes it possible for unauthenticated attackers to add, modify, or delete post meta and plugin… | |
| Aplazada | Media (6.5) | 0.34% | — | Northernbeacheswebsites WP GotowebinarAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson WP GoToWebinar allows Stored XSS.This issue affects WP GoToWebinar: from n/a through 15.7. | |
| Aplazada | Media (6.4) | 0.29% | — | Webico Slider Flatsome AddonsAI | 9/7/2024 | 17/6/2026 | The Webico Slider Flatsome Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wbc_image shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Crítica (9.8) | 0.66% | — | Webinane Lifeline Donation | 20/6/2024 | 17/6/2026 | The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.6. This is due to insufficient verification on the user being supplied during the checkout through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on… | |
| Aplazada | Media (4.3) | 0.41% | — | Northernbeacheswebsites WP GotowebinarAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson WP GoToWebinar.This issue affects WP GoToWebinar: from n/a through 14.46. | |
| Analizada | Crítica (9.8) | 0.51% | — | Webidsupport Webid | 22/5/2024 | 17/6/2026 | WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php. | |
| Aplazada | Crítica (9.8) | 0.72% | — | Saleswonder WebinarignitionAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Saleswonder Team WebinarIgnition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through 3.05.0. | |
| Aplazada | Alta (7.1) | 0.23% | — | WebinarpressAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.17. | |
| Aplazada | Crítica (9.8) | 0.83% | — | E-webinformationco Fs-ezviewer WEBAI | 29/4/2024 | 17/6/2026 | E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and database host IP… | |
| Aplazada | Media (6.4) | 0.38% | — | Webikon Superfaktura WoocommerceAI | 24/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in 2day.Sk, Webikon SuperFaktura WooCommerce.This issue affects SuperFaktura WooCommerce: from n/a through 1.40.3. | |
| Analizada | Alta (8.8) | 0.74% | — | Webidsupport Webid | 19/4/2024 | 17/6/2026 | Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation). | |
| Modificada | Alta (8.8) | 0.24% | — | Saleswonder Webinarignition | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition.This issue affects WebinarIgnition: from n/a through <= 3.05.8. | |
| Aplazada | Alta (7.1) | 0.37% | — | WebinarpressAI | 7/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebinarPress allows Reflected XSS.This issue affects WebinarPress: from n/a through 1.33.10. | |
| Aplazada | Media (6.5) | 0.36% | — | Wppool Webinar AND Video Conference With Jitsi MeetAI | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Webinar and Video Conference with Jitsi Meet allows Stored XSS.This issue affects Webinar and Video Conference with Jitsi Meet: from n/a through 2.6.3. | |
| Modificada | Crítica (9.8) | 0.57% | — | Saleswonder Webinarignition | 31/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream &… | |
| Modificada | Alta (8.8) | 0.62% | — | Saleswonder Webinarignition | 29/12/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition: from n/a through… | |
| Modificada | Media (6.5) | 0.71% | — | Kaifa Webitr Attendance System | 15/12/2023 | 17/6/2026 | Kaifa Technology WebITR is an online attendance system, it has insufficient validation for user input within a special function. A remote attacker with regular user privilege can exploit this vulnerability to inject arbitrary SQL commands to read database. | |
| Modificada | Alta (8.8) | 0.89% | — | Kaifa Webitr Attendance System | 15/12/2023 | 17/6/2026 | Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service. | |
| Modificada | Media (4.3) | 0.57% | — | Kaifa Webitr Attendance System | 15/12/2023 | 17/6/2026 | Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial sensitive system information from error message. | |
| Modificada | Crítica (9.8) | 0.57% | — | Kaifa Webitr Attendance System | 15/12/2023 | 17/6/2026 | Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including administrator’s account, to execute login… | |
| Modificada | Crítica (9.8) | 0.96% | — | Webidsupport Webid | 8/11/2023 | 17/6/2026 | WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php. | |
| Analizada | Media (4.8) | 0.42% | — | Northernbeacheswebsites WP Gotowebinar | 25/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson WP GoToWebinar plugin <= 14.45 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Webiny | 25/8/2023 | 17/6/2026 | @webiny/react-rich-text-renderer before 5.37.2 allows XSS attacks by content managers. This is a react component to render data coming from Webiny Headless CMS and Webiny Form Builder. Webiny is an open-source serverless enterprise CMS. The @webiny/react-rich-text-renderer package depends on the editor.js rich text… | |
| Modificada | Alta (7.5) | 1.0% | — | Tel-ster Telwin Scada Webinterface | 3/8/2023 | 17/6/2026 | External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system. |