Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

1971 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.5%—Wordable7/6/202317/6/2026
The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This is due to the use of a user supplied hashing algorithm passed to the hash_hmac() function and the use of a loose comparison on the hash which allows an attacker to trick the function into thinking it…
ModificadaAlta (7.5)0.75%—Angrybyte Wordpress Exit BOX Lite5/6/202316/6/2026
A vulnerability, which was classified as problematic, has been found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this issue is some unknown functionality of the file wordpress-exit-box-lite.php. The manipulation leads to information disclosure. The attack may be launched remotely. Upgrading to version…
ModificadaAlta (8.8)0.43%—Angrybte Wordpress Exit BOX Lite5/6/202316/6/2026
A vulnerability classified as problematic was found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this vulnerability is the function exitboxadmin of the file wordpress-exit-box-lite.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. Upgrading to version 1.10…
ModificadaMedia (5.4)0.43%—Accesspressthemes Frontend Post Wordpress Plugin5/6/202317/6/2026
The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to an arbitrary domain.
ModificadaAlta (8.8)0.43%—Wordpress Blogger Importer4/6/202316/6/2026
A vulnerability was found in Blogger Importer Plugin up to 0.5 on WordPress. It has been classified as problematic. Affected is the function start/restart of the file blogger-importer.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. Upgrading to version 0.6 is…
ModificadaCrítica (9.8)0.53%—Wordapp31/5/202317/6/2026
El plugin Wordapp para WordPress es vulnerable a una omisión de autorización debido al uso de una firma criptográfica insuficientemente única en la función "wa_pdx_op_config_set" en versiones hasta la 1.5.0 inclusive. Esto hace posible que atacantes no autenticados al plugin cambien el "validation_token" en la…
ModificadaAlta (8.8)0.26%—Wordpress Performance LAB25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WordPress Performance Team Performance Lab plugin <= 2.2.0 versions.
ModificadaAlta (8.8)0.27%—Wordpress Health Check & Troubleshooting25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions.
ModificadaAlta (8.8)0.27%—Viadat Store Locator FOR Wordpress With Google Maps24/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Viadat Creations Store Locator for WordPress with Google Maps – LotsOfLocales plugin <= 3.98.7 versions.
ModificadaAlta (8.8)0.26%—Hmplugin Wordpress Books Gallery23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin WordPress Books Gallery plugin <= 4.4.8 versions.
ModificadaAlta (8.8)0.26%—Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin)23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
ModificadaMedia (6.1)80%💥 ExploitWordpress17/5/202317/6/2026
WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload…
ModificadaAlta (7.8)0.47%—Soft-o Free Password Manager12/5/202317/6/2026
A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.
ModificadaAlta (7.5)1.2%—Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 20h2+129/5/202317/6/2026
Microsoft Word Security Feature Bypass Vulnerability
ModificadaMedia (4.8)0.37%—Kanbanwp Kanban Boards FOR Wordpress9/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kanban for WordPress Kanban Boards for WordPress plugin <= 2.5.20 versions.
ModificadaMedia (4.8)0.37%—Blueglass Jobs FOR Wordpress3/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.10.2 versions.
ModificadaMedia (5.4)0.36%—Wpdownloadmanager Gutenberg Blocks FOR Wordpress Download Manager3/5/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8 versions.
ModificadaMedia (4.9)0.90%—Changingtec Mobile ONE Time Password27/4/202317/6/2026
ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files.
ModificadaAlta (7.8)0.81%—Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO26/4/202317/6/2026
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to…
ModificadaMedia (4.8)0.37%—Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin)25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
ModificadaMedia (4.8)0.37%—Wordpress Custom Settings Project Wordpress Custom Settings23/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Davinder Singh Custom Settings plugin <= 1.0 versions.
ModificadaMedia (5.4)0.39%—Blueglass Jobs FOR Wordpress23/4/202317/6/2026
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.11.2 versions.
ModificadaMedia (5.3)0.46%—Mendix Forgot Password11/4/202317/6/2026
A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.1), Mendix Forgot Password (Mendix 9 compatible) (All versions < V5.1.1). The affected versions of the module contain an observable response…
ModificadaMedia (4.8)0.44%—Wordpress Amazon S3 Project Wordpress Amazon S310/4/202317/6/2026
The WordPress Amazon S3 Plugin WordPress plugin before 1.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.38%—Cimatti Wordpress Contact Forms7/4/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.
Orbitaley — Vulnerabilidades