Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

299 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.26%—Vcita Contact Form AND Calls TO ActionAI31/1/202517/6/2026
The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae and vcita_ajax_toggle_contact functions in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers,…
AplazadaMedia (6.4)0.31%—Contact Form AND Calls TO Action BY VcitaAI31/1/202517/6/2026
The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler ' shortcode in all versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
AplazadaMedia (6.4)0.34%—Automatically Hierarchic Categories IN MenuAI30/1/202517/6/2026
The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autocategorymenu' shortcode in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (4.3)0.22%—Callnowbutton Call NOW ButtonAI24/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Jerry Rietveld Call Now Button call-now-button allows Cross Site Request Forgery.This issue affects Call Now Button: from n/a through <= 1.4.13.
AplazadaAlta (7.1)0.39%—Lampd Call TO Action PopupAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lampd Call To Action Popup call-to-action-popup allows Reflected XSS.This issue affects Call To Action Popup: from n/a through <= 1.0.2.
AplazadaAlta (7.1)0.15%💥 PoCNGO Thang IT PPO Call TO ActionsAI21/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ngô Thắng IT PPO Call To Actions ppo-call-to-actions allows Cross Site Request Forgery.This issue affects PPO Call To Actions: from n/a through <= 0.1.3.
AplazadaAlta (7.1)0.18%—Lokalyze Call ME NOWAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tussendoor B.V. Call me Now call-me-now allows Stored XSS.This issue affects Call me Now: from n/a through <= 1.0.5.
AplazadaMedia (6.1)0.45%—Opencode Mobile Collect CallAI9/1/202517/6/2026
A PHP Code Injection vulnerability that can lead to Remote Code Execution (RCE) and XSS in Opencode Mobile Collect Call v5.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the op_func parameter at /occontrolpanel/index.php.
AplazadaMedia (6.3)0.22%—Asianmobile CallcolorAI6/1/202517/6/2026
The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.asianmobile.callcolor.ui.component.call.CallActivity component.
AplazadaMedia (6.5)0.26%—Callos14 Callscreen ColorphoneAI6/1/202517/6/2026
The com.callos14.callscreen.colorphone (aka iCall OS17 - Color Phone Flash) application through 4.3 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callos14.callscreen.colorphone.DialerActivity component.
AplazadaAlta (7.7)0.17%—Windymob Callscreen Ringtone Callcolor ColorphoneAIFrovis AndroidbaseAI6/1/202517/6/2026
The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes) application through 1.1.2 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.frovis.androidbase.call.DialerActivity component.
AplazadaMedia (6.3)0.22%—Callerscreen Colorphone Themes CallflashAI6/1/202517/6/2026
The com.callerscreen.colorphone.themes.callflash (aka Color Call Theme & Call Screen) application through 1.0.7 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.android.call.color.app.activities.DialerActivity component.
AplazadaCrítica (9.1)0.35%—Remi Color Phone Call Screen ThemeAI6/1/202517/6/2026
The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the…
AplazadaCrítica (9.1)0.35%—Glitter Caller ScreenAI6/1/202517/6/2026
The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.glitter.caller.screen.DialerActivity component.
AplazadaAlta (8.2)0.36%—Gricemobile Com.grice.callAI4/12/202417/6/2026
The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.iui.mobile.presentation.MobileActivity.
AnalizadaBaja (3.3)0.15%—Samsung Smart Touch Call3/12/202417/6/2026
Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.
AplazadaAlta (7.1)0.16%—Springthistle Aprils Call PostsAI2/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in springthistle April's Call Posts aprils-call-posts allows Stored XSS.This issue affects April's Call Posts: from n/a through <= 2.1.1.
AnalizadaMedia (6.5)0.33%—Cisco IP Conference Phone 7832 FirmwareCisco IP Conference Phone 7832 With Multiplatform FirmwareCisco IP Conference Phone 8832 FirmwareCisco IP Conference Phone 8832 With Multiplatform Firmware+3018/11/202417/6/2026
Multiple vulnerabilities in the Cisco&nbsp;Discovery Protocol and Link Layer Discovery Protocol (LLDP) implementations for Cisco&nbsp;IP Phone Series 68xx/78xx/88xx could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP phone. These vulnerabilities are due to…
AplazadaMedia (4)0.19%—Callassistant AI Call Assistant ScreenerAI7/11/202417/6/2026
The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callassistant.android.ui.call.incall.InCallActivity component.
ModificadaMedia (5.4)0.25%—Hafizuddinahmed Crazy Call TO Action BOX18/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hafiz Uddin Ahmed Crazy Call To Action Box crazy-call-to-action-box allows DOM-Based XSS.This issue affects Crazy Call To Action Box: from n/a through <= 1.0.5.
AplazadaMedia (6.5)0.25%—Atakanau Automatically Hierarchic Categories IN MenuAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atakan Au Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu allows Stored XSS.This issue affects Automatically Hierarchic Categories in Menu: from n/a through <= 2.0.5.
AnalizadaCrítica (9.8)0.60%—Plechevandrey Wp-recall6/9/202417/6/2026
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plugin not properly verifying a user's identity during new order creation. This makes it possible for unauthenticated…
AnalizadaMedia (4.7)0.56%—Apidaze Widget4call28/6/202417/6/2026
The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaMedia (5.4)0.18%—Plechevandrey Wp-recallAI8/6/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.6.
ModificadaMedia (5.3)0.39%—Plechevandrey Wp-recall6/6/202417/6/2026
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_payment' function in all versions up to, and including, 16.26.6. This makes it possible for unauthenticated attackers to delete arbitrary payments.
Orbitaley — Vulnerabilidades