Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.35%—Sparkweb Interactive INC Custom Field Bulk EditorAI31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SparkWeb Interactive, Inc. Custom Field Bulk Editor allows Reflected XSS.This issue affects Custom Field Bulk Editor: from n/a through 1.9.1.
ModificadaMedia (5.3)0.36%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional29/3/202417/6/2026
Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.3.
ModificadaMedia (6.1)0.37%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional28/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR allows Reflected XSS.This issue affects BEAR: from n/a through 1.1.4.2.
AplazadaAlta (7.1)0.42%—Madfishdigital Bulk Noindex AND Nofollow ToolkitAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Reflected XSS.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 2.01.
ModificadaMedia (6.5)0.38%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional23/3/202417/6/2026
Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.
ModificadaMedia (4.3)0.42%—Pawaryogesh1989 Bulk Edit Post Titles13/3/202417/6/2026
The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkUpdatePostTitles function in all versions up to, and including, 5.0.0. This makes it possible for authenticated attackers, with subscriber access and above, to modify the…
AnalizadaCrítica (9.8)0.57%—Prestashop Import/update Bulk Product27/2/202417/6/2026
In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions.
ModificadaMedia (4.8)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional8/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net allows Stored XSS.This issue affects BEAR – Bulk Editor and Products Manager Professional for WooCommerce by…
ModificadaMedia (4.3)0.53%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional5/2/202417/6/2026
The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing capability check on the wpbe_create_new_term, wpbe_update_tax_term, and wpbe_delete_tax_term functions in all versions up to, and including, 1.0.8.1.…
ModificadaMedia (4.3)0.31%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional5/2/202417/6/2026
The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8.1. This is due to missing or incorrect nonce validation on the wpbe_create_new_term, wpbe_update_tax_term, and wpbe_delete_tax_term functions.…
ModificadaMedia (6.1)0.33%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional31/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional allows Reflected XSS.This issue affects WOLF – WordPress Posts Bulk Editor and Manager Professional: from n/a through 1.0.8.
ModificadaAlta (8.8)0.25%—Supremo Bulk Comment Remove30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mike Strand Bulk Comment Remove allows Cross Site Request Forgery.This issue affects Bulk Comment Remove: from n/a through 2.
ModificadaAlta (8.8)0.27%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional25/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7.1 versions.
ModificadaMedia (5.4)0.40%—Happybox Newsletter & Bulk Email Sender25/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in HappyBox Newsletter & Bulk Email Sender – Email Newsletter Plugin for WordPress plugin <= 2.0.1 versions.
ModificadaMedia (4.3)0.56%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_swap function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
ModificadaMedia (4.3)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulk_delete_products function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they can…
ModificadaMedia (4.3)0.31%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobe_bulkoperations_delete function. This makes it possible for authenticated attackers, with subscriber access or higher, to delete products.
ModificadaMedia (4.3)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_delete function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they can…
ModificadaMedia (4.3)0.56%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
ModificadaMedia (4.3)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_visibility function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted…
ModificadaMedia (4.3)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_swap function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they can…
ModificadaMedia (4.3)0.31%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_apply_default_combination function. This makes it possible for unauthenticated attackers to manipulate products via a forged…
ModificadaMedia (4.3)0.31%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the create_profile function. This makes it possible for unauthenticated attackers to create profiles via a forged request granted they can trick a site…
ModificadaAlta (8.8)0.36%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_save_options function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they…
ModificadaMedia (6.1)0.33%—Madfishdigital Bulk Noindex & Nofollow Toolkit18/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit plugin <= 1.42 versions.
Orbitaley — Vulnerabilidades