Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

129 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.17%—Wpwebinfotech Social Auto Poster24/7/202417/6/2026
The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete post meta and plugin options.
ModificadaAlta (7.5)0.29%—Wpwebinfotech Social Auto Poster24/7/202417/6/2026
The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.3.14. This makes it possible for unauthenticated attackers to add, modify, or delete post meta and plugin…
AplazadaMedia (6.5)0.34%—Northernbeacheswebsites WP GotowebinarAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson WP GoToWebinar allows Stored XSS.This issue affects WP GoToWebinar: from n/a through 15.7.
AplazadaMedia (6.4)0.29%—Webico Slider Flatsome AddonsAI9/7/202417/6/2026
The Webico Slider Flatsome Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wbc_image shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
ModificadaCrítica (9.8)0.66%—Webinane Lifeline Donation20/6/202417/6/2026
The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.6. This is due to insufficient verification on the user being supplied during the checkout through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on…
AplazadaMedia (4.3)0.41%—Northernbeacheswebsites WP GotowebinarAI9/6/202417/6/2026
Missing Authorization vulnerability in Martin Gibson WP GoToWebinar.This issue affects WP GoToWebinar: from n/a through 14.46.
AnalizadaCrítica (9.8)0.51%—Webidsupport Webid22/5/202417/6/2026
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.
AplazadaCrítica (9.8)0.72%—Saleswonder WebinarignitionAI17/5/202417/6/2026
Improper Privilege Management vulnerability in Saleswonder Team WebinarIgnition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through 3.05.0.
AplazadaAlta (7.1)0.23%—WebinarpressAI14/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.17.
AplazadaCrítica (9.8)0.83%—E-webinformationco Fs-ezviewer WEBAI29/4/202417/6/2026
E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and database host IP…
AplazadaMedia (6.4)0.38%—Webikon Superfaktura WoocommerceAI24/4/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in 2day.Sk, Webikon SuperFaktura WooCommerce.This issue affects SuperFaktura WooCommerce: from n/a through 1.40.3.
AnalizadaAlta (8.8)0.74%—Webidsupport Webid19/4/202417/6/2026
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation).
ModificadaAlta (8.8)0.24%—Saleswonder Webinarignition15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition.This issue affects WebinarIgnition: from n/a through <= 3.05.8.
AplazadaAlta (7.1)0.37%—WebinarpressAI7/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebinarPress allows Reflected XSS.This issue affects WebinarPress: from n/a through 1.33.10.
AplazadaMedia (6.5)0.36%—Wppool Webinar AND Video Conference With Jitsi MeetAI29/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Webinar and Video Conference with Jitsi Meet allows Stored XSS.This issue affects Webinar and Video Conference with Jitsi Meet: from n/a through 2.6.3.
ModificadaCrítica (9.8)0.57%—Saleswonder Webinarignition31/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream &…
ModificadaAlta (8.8)0.62%—Saleswonder Webinarignition29/12/202317/6/2026
Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition: from n/a through…
ModificadaMedia (6.5)0.71%—Kaifa Webitr Attendance System15/12/202317/6/2026
Kaifa Technology WebITR is an online attendance system, it has insufficient validation for user input within a special function. A remote attacker with regular user privilege can exploit this vulnerability to inject arbitrary SQL commands to read database.
ModificadaAlta (8.8)0.89%—Kaifa Webitr Attendance System15/12/202317/6/2026
Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
ModificadaMedia (4.3)0.57%—Kaifa Webitr Attendance System15/12/202317/6/2026
Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial sensitive system information from error message.
ModificadaCrítica (9.8)0.57%—Kaifa Webitr Attendance System15/12/202317/6/2026
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including administrator’s account, to execute login…
ModificadaCrítica (9.8)0.96%—Webidsupport Webid8/11/202317/6/2026
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
AnalizadaMedia (4.8)0.42%—Northernbeacheswebsites WP Gotowebinar25/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson WP GoToWebinar plugin <= 14.45 versions.
ModificadaMedia (4.8)0.39%—Webiny25/8/202317/6/2026
@webiny/react-rich-text-renderer before 5.37.2 allows XSS attacks by content managers. This is a react component to render data coming from Webiny Headless CMS and Webiny Form Builder. Webiny is an open-source serverless enterprise CMS. The @webiny/react-rich-text-renderer package depends on the editor.js rich text…
ModificadaAlta (7.5)1.0%—Tel-ster Telwin Scada Webinterface3/8/202317/6/2026
External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system.
Orbitaley — Vulnerabilidades