Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.26% | — | Vcita Contact Form AND Calls TO ActionAI | 31/1/2025 | 17/6/2026 | The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae and vcita_ajax_toggle_contact functions in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.31% | — | Contact Form AND Calls TO Action BY VcitaAI | 31/1/2025 | 17/6/2026 | The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler ' shortcode in all versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Aplazada | Media (6.4) | 0.34% | — | Automatically Hierarchic Categories IN MenuAI | 30/1/2025 | 17/6/2026 | The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autocategorymenu' shortcode in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.22% | — | Callnowbutton Call NOW ButtonAI | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jerry Rietveld Call Now Button call-now-button allows Cross Site Request Forgery.This issue affects Call Now Button: from n/a through <= 1.4.13. | |
| Aplazada | Alta (7.1) | 0.39% | — | Lampd Call TO Action PopupAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lampd Call To Action Popup call-to-action-popup allows Reflected XSS.This issue affects Call To Action Popup: from n/a through <= 1.0.2. | |
| Aplazada | Alta (7.1) | 0.15% | 💥 PoC | NGO Thang IT PPO Call TO ActionsAI | 21/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ngô Thắng IT PPO Call To Actions ppo-call-to-actions allows Cross Site Request Forgery.This issue affects PPO Call To Actions: from n/a through <= 0.1.3. | |
| Aplazada | Alta (7.1) | 0.18% | — | Lokalyze Call ME NOWAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tussendoor B.V. Call me Now call-me-now allows Stored XSS.This issue affects Call me Now: from n/a through <= 1.0.5. | |
| Aplazada | Media (6.1) | 0.45% | — | Opencode Mobile Collect CallAI | 9/1/2025 | 17/6/2026 | A PHP Code Injection vulnerability that can lead to Remote Code Execution (RCE) and XSS in Opencode Mobile Collect Call v5.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the op_func parameter at /occontrolpanel/index.php. | |
| Aplazada | Media (6.3) | 0.22% | — | Asianmobile CallcolorAI | 6/1/2025 | 17/6/2026 | The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.asianmobile.callcolor.ui.component.call.CallActivity component. | |
| Aplazada | Media (6.5) | 0.26% | — | Callos14 Callscreen ColorphoneAI | 6/1/2025 | 17/6/2026 | The com.callos14.callscreen.colorphone (aka iCall OS17 - Color Phone Flash) application through 4.3 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callos14.callscreen.colorphone.DialerActivity component. | |
| Aplazada | Alta (7.7) | 0.17% | — | Windymob Callscreen Ringtone Callcolor ColorphoneAIFrovis AndroidbaseAI | 6/1/2025 | 17/6/2026 | The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes) application through 1.1.2 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.frovis.androidbase.call.DialerActivity component. | |
| Aplazada | Media (6.3) | 0.22% | — | Callerscreen Colorphone Themes CallflashAI | 6/1/2025 | 17/6/2026 | The com.callerscreen.colorphone.themes.callflash (aka Color Call Theme & Call Screen) application through 1.0.7 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.android.call.color.app.activities.DialerActivity component. | |
| Aplazada | Crítica (9.1) | 0.35% | — | Remi Color Phone Call Screen ThemeAI | 6/1/2025 | 17/6/2026 | The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the… | |
| Aplazada | Crítica (9.1) | 0.35% | — | Glitter Caller ScreenAI | 6/1/2025 | 17/6/2026 | The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.glitter.caller.screen.DialerActivity component. | |
| Aplazada | Alta (8.2) | 0.36% | — | Gricemobile Com.grice.callAI | 4/12/2024 | 17/6/2026 | The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.iui.mobile.presentation.MobileActivity. | |
| Analizada | Baja (3.3) | 0.15% | — | Samsung Smart Touch Call | 3/12/2024 | 17/6/2026 | Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability. | |
| Aplazada | Alta (7.1) | 0.16% | — | Springthistle Aprils Call PostsAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in springthistle April's Call Posts aprils-call-posts allows Stored XSS.This issue affects April's Call Posts: from n/a through <= 2.1.1. | |
| Analizada | Media (6.5) | 0.33% | — | Cisco IP Conference Phone 7832 FirmwareCisco IP Conference Phone 7832 With Multiplatform FirmwareCisco IP Conference Phone 8832 FirmwareCisco IP Conference Phone 8832 With Multiplatform Firmware+30 | 18/11/2024 | 17/6/2026 | Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) implementations for Cisco IP Phone Series 68xx/78xx/88xx could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP phone. These vulnerabilities are due to… | |
| Aplazada | Media (4) | 0.19% | — | Callassistant AI Call Assistant ScreenerAI | 7/11/2024 | 17/6/2026 | The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callassistant.android.ui.call.incall.InCallActivity component. | |
| Modificada | Media (5.4) | 0.25% | — | Hafizuddinahmed Crazy Call TO Action BOX | 18/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hafiz Uddin Ahmed Crazy Call To Action Box crazy-call-to-action-box allows DOM-Based XSS.This issue affects Crazy Call To Action Box: from n/a through <= 1.0.5. | |
| Aplazada | Media (6.5) | 0.25% | — | Atakanau Automatically Hierarchic Categories IN MenuAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atakan Au Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu allows Stored XSS.This issue affects Automatically Hierarchic Categories in Menu: from n/a through <= 2.0.5. | |
| Analizada | Crítica (9.8) | 0.60% | — | Plechevandrey Wp-recall | 6/9/2024 | 17/6/2026 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plugin not properly verifying a user's identity during new order creation. This makes it possible for unauthenticated… | |
| Analizada | Media (4.7) | 0.56% | — | Apidaze Widget4call | 28/6/2024 | 17/6/2026 | The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Media (5.4) | 0.18% | — | Plechevandrey Wp-recallAI | 8/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.6. | |
| Modificada | Media (5.3) | 0.39% | — | Plechevandrey Wp-recall | 6/6/2024 | 17/6/2026 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_payment' function in all versions up to, and including, 16.26.6. This makes it possible for unauthenticated attackers to delete arbitrary payments. |