Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.27% | — | Effectmatrix Total Video Converter Command LineAI | 13/2/2025 | 17/6/2026 | A Structured Exception Handler based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when a specially crafted file is passed to the -ff parameter. The vulnerability occurs due to improper handling of file input with overly long characters, leading to memory… | |
| Aplazada | Media (5.5) | 0.27% | — | Effectmatrix Total Video Converter Command LineAI | 13/2/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when an overly long string is passed to the "-f" parameter. This can lead to memory corruption, potentially allowing arbitrary code execution or causing a denial of service via specially crafted input. | |
| Analizada | Alta (8.1) | 0.47% | 💥 PoC | Convertplug Convertplus | 12/2/2025 | 17/6/2026 | The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cp_dismiss_notice' AJAX endpoint in all versions up to, and including, 3.5.30. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Analizada | Alta (7.5) | 0.59% | — | Moreconvert Woocommerce Wishlist | 30/1/2025 | 17/6/2026 | The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.7 via the download_pdf_file() function due to missing validation on a user controlled key. This makes it… | |
| Aplazada | Alta (7.1) | 0.25% | — | David Anderson Redux ConverterAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Anderson / Team Updraft Redux Converter redux-converter allows Reflected XSS.This issue affects Redux Converter: from n/a through <= 1.1.3.1. | |
| Aplazada | Media (6.5) | 0.26% | — | Jorisderuiter ConvertcalculatorAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jorisderuiter ConvertCalculator for WordPress convertcalculator allows Stored XSS.This issue affects ConvertCalculator for WordPress: from n/a through <= 1.1.1. | |
| Aplazada | Media (5.3) | 0.34% | — | Ruslan Suhar ConvertfulAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Ruslan Suhar Convertful – Your Ultimate On-Site Conversion Tool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Convertful – Your Ultimate On-Site Conversion Tool: from n/a through 2.5. | |
| Aplazada | Media (6.4) | 0.28% | — | Currency Converter Widget PROAI | 12/12/2024 | 17/6/2026 | The Currency Converter Widget ⚡ PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'currency-converter-widget-pro' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (5.4) | 0.22% | — | Convert Forms Project Convert Forms | 4/12/2024 | 17/6/2026 | Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8. | |
| Analizada | Crítica (9.8) | 0.52% | — | Convert Forms Project Convert Forms | 4/12/2024 | 17/6/2026 | Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8. | |
| Aplazada | Crítica (9.1) | 0.49% | — | Davor Zeljkovic Convert Docx2postAI | 16/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Davor Zeljkovic Convert Docx2post convert-docx2post allows Upload a Web Shell to a Web Server.This issue affects Convert Docx2post: from n/a through <= 1.4. | |
| Aplazada | Media (6.4) | 0.85% | — | ConvertcalculatorAI | 16/11/2024 | 17/6/2026 | The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'type' parameters in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (6.5) | 0.40% | — | Automattic Newspack Content ConverterAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Automattic Newspack Content Converter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack Content Converter: from n/a through 0.1.5. | |
| Modificada | Media (5.4) | 0.25% | — | Crossedcode Bverse Convert | 18/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edwin Rivera bVerse Convert bverse-convert allows Stored XSS.This issue affects bVerse Convert: from n/a through <= 1.3.7.1. | |
| Analizada | Alta (8.5) | 0.21% | — | Vso-software Convertxtodvd | 17/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in VSO ConvertXtoDvd 7.0.0.83. Affected is an unknown function in the library avcodec.dll of the file ConvertXtoDvd.exe. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and… | |
| Aplazada | Alta (7.1) | 0.35% | — | Appmaker - Convert Woocommerce TO Android & IOS Native Mobile AppsAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Appmaker Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps allows Reflected XSS.This issue affects Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps: from n/a through 1.36.12. | |
| Aplazada | Crítica (9.1) | 0.49% | — | Spreadsheetconverter Import Spreadsheets From Microsoft ExcelAI | 12/7/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Code Injection.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.4. | |
| Modificada | Media (5.3) | 0.37% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 21/6/2024 | 17/6/2026 | The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to… | |
| Modificada | Crítica (9.8) | 0.57% | — | Brainstormforce Convert PRO | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Convert Pro.This issue affects Convert Pro: from n/a through 1.7.5. | |
| Modificada | Media (5.3) | 0.41% | — | Moreconvert Woocommerce Wishlist | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.2. | |
| Aplazada | Media (5.3) | 0.32% | — | Moreconvert MC Woocommerce WishlistAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.8. | |
| Aplazada | Alta (7.5) | 0.59% | — | Convertplug ConvertplusAI | 16/5/2024 | 17/6/2026 | The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_modal' shortcode. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Alta (8.8) | 0.77% | — | ConvertplugAI | 4/5/2024 | 17/6/2026 | The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_info_bar' shortcode. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (5.4) | 0.37% | — | ConvertplugAI | 4/5/2024 | 17/6/2026 | The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cp_dismiss_notice() function in all versions up to, and including, 3.5.25. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary… | |
| Aplazada | Alta (7.1) | 0.33% | — | Organic Themes Bulk Block ConverterAI | 17/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Organic Themes Bulk Block Converter allows Reflected XSS.This issue affects Bulk Block Converter: from n/a through 1.0.1. |