Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.56% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_swap function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products. | |
| Modificada | Media (4.3) | 0.32% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulk_delete_products function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they can… | |
| Modificada | Media (4.3) | 0.31% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobe_bulkoperations_delete function. This makes it possible for authenticated attackers, with subscriber access or higher, to delete products. | |
| Modificada | Media (4.3) | 0.32% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_delete function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they can… | |
| Modificada | Media (4.3) | 0.56% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products. | |
| Modificada | Media (4.3) | 0.32% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_visibility function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted… | |
| Modificada | Media (4.3) | 0.32% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_swap function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they can… | |
| Modificada | Media (4.3) | 0.31% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_apply_default_combination function. This makes it possible for unauthenticated attackers to manipulate products via a forged… | |
| Modificada | Media (4.3) | 0.31% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the create_profile function. This makes it possible for unauthenticated attackers to create profiles via a forged request granted they can trick a site… | |
| Modificada | Alta (8.8) | 0.36% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_save_options function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they… | |
| Modificada | Media (4.3) | 0.53% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 18/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products. | |
| Modificada | Media (6.1) | 0.41% | — | Bearthemes Sermon'e - Sermons Online | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0 versions. | |
| Modificada | Media (5.4) | 0.51% | — | Bearsthemes Sermons Online | 19/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0 versions. | |
| Modificada | Alta (8.8) | 0.30% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions. | |
| Modificada | Alta (7.5) | 0.60% | — | Smartbear Zephyr Enterprise | 8/3/2023 | 17/6/2026 | There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances. | |
| Modificada | Alta (8.1) | 0.51% | — | Smartbear Zephyr Enterprise | 8/3/2023 | 17/6/2026 | There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts. | |
| Modificada | Alta (7.5) | 0.64% | — | Smartbear Zephyr Enterprise | 8/3/2023 | 17/6/2026 | SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a denial of service condition. | |
| Modificada | Crítica (9.8) | 1.3% | — | Smartbear Zephyr Enterprise | 8/3/2023 | 17/6/2026 | SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users. | |
| Modificada | Crítica (9.8) | 0.81% | — | Bearadmin Project Bearadmin | 17/2/2023 | 17/6/2026 | File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint. | |
| Modificada | Media (6.5) | 0.72% | — | Jenkins Bearychat | 26/1/2023 | 17/6/2026 | A missing permission check in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL. | |
| Modificada | Alta (8.8) | 0.56% | — | Jenkins Bearychat | 26/1/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified URL. | |
| Modificada | Crítica (9.8) | 4.8% | 💥 Exploit | Beardev Joomsport | 19/12/2022 | 17/6/2026 | The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users | |
| Modificada | Alta (7.5) | 1.5% | — | Dropbear SSH Project Dropbear SSHDebian Linux | 12/10/2022 | 17/6/2026 | An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass additional security measures such as FIDO2 tokens or SSH-Askpass.… | |
| Modificada | Media (4.9) | 1.5% | — | Beardev Joomsport | 6/9/2022 | 17/6/2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-page-extrafields page in versions up to, and including, 5.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Modificada | Media (4.9) | 1.5% | — | Beardev Joomsport | 6/9/2022 | 17/6/2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-events-form page in versions up to, and including, 5.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… |