Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.56%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_swap function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
ModificadaMedia (4.3)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulk_delete_products function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they can…
ModificadaMedia (4.3)0.31%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobe_bulkoperations_delete function. This makes it possible for authenticated attackers, with subscriber access or higher, to delete products.
ModificadaMedia (4.3)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_delete function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they can…
ModificadaMedia (4.3)0.56%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
ModificadaMedia (4.3)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_visibility function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted…
ModificadaMedia (4.3)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_swap function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they can…
ModificadaMedia (4.3)0.31%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_apply_default_combination function. This makes it possible for unauthenticated attackers to manipulate products via a forged…
ModificadaMedia (4.3)0.31%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the create_profile function. This makes it possible for unauthenticated attackers to create profiles via a forged request granted they can trick a site…
ModificadaAlta (8.8)0.36%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_save_options function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they…
ModificadaMedia (4.3)0.53%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional18/10/202317/6/2026
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
ModificadaMedia (6.1)0.41%—Bearthemes Sermon'e - Sermons Online27/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0 versions.
ModificadaMedia (5.4)0.51%—Bearsthemes Sermons Online19/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0 versions.
ModificadaAlta (8.8)0.30%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional28/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions.
ModificadaAlta (7.5)0.60%—Smartbear Zephyr Enterprise8/3/202317/6/2026
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
ModificadaAlta (8.1)0.51%—Smartbear Zephyr Enterprise8/3/202317/6/2026
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts.
ModificadaAlta (7.5)0.64%—Smartbear Zephyr Enterprise8/3/202317/6/2026
SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a denial of service condition.
ModificadaCrítica (9.8)1.3%—Smartbear Zephyr Enterprise8/3/202317/6/2026
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.
ModificadaCrítica (9.8)0.81%—Bearadmin Project Bearadmin17/2/202317/6/2026
File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.
ModificadaMedia (6.5)0.72%—Jenkins Bearychat26/1/202317/6/2026
A missing permission check in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
ModificadaAlta (8.8)0.56%—Jenkins Bearychat26/1/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified URL.
ModificadaCrítica (9.8)4.8%💥 ExploitBeardev Joomsport19/12/202217/6/2026
The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
ModificadaAlta (7.5)1.5%—Dropbear SSH Project Dropbear SSHDebian Linux12/10/202217/6/2026
An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass additional security measures such as FIDO2 tokens or SSH-Askpass.…
ModificadaMedia (4.9)1.5%—Beardev Joomsport6/9/202217/6/2026
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-page-extrafields page in versions up to, and including, 5.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient…
ModificadaMedia (4.9)1.5%—Beardev Joomsport6/9/202217/6/2026
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-events-form page in versions up to, and including, 5.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
Orbitaley — Vulnerabilidades