Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

305 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.27%—Effectmatrix Total Video Converter Command LineAI13/2/202517/6/2026
A Structured Exception Handler based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when a specially crafted file is passed to the -ff parameter. The vulnerability occurs due to improper handling of file input with overly long characters, leading to memory…
AplazadaMedia (5.5)0.27%—Effectmatrix Total Video Converter Command LineAI13/2/202517/6/2026
A stack-based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when an overly long string is passed to the "-f" parameter. This can lead to memory corruption, potentially allowing arbitrary code execution or causing a denial of service via specially crafted input.
AnalizadaAlta (8.1)0.47%💥 PoCConvertplug Convertplus12/2/202517/6/2026
The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cp_dismiss_notice' AJAX endpoint in all versions up to, and including, 3.5.30. This makes it possible for authenticated attackers, with Subscriber-level…
AnalizadaAlta (7.5)0.59%—Moreconvert Woocommerce Wishlist30/1/202517/6/2026
The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.7 via the download_pdf_file() function due to missing validation on a user controlled key. This makes it…
AplazadaAlta (7.1)0.25%—David Anderson Redux ConverterAI24/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Anderson / Team Updraft Redux Converter redux-converter allows Reflected XSS.This issue affects Redux Converter: from n/a through <= 1.1.3.1.
AplazadaMedia (6.5)0.26%—Jorisderuiter ConvertcalculatorAI2/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jorisderuiter ConvertCalculator for WordPress convertcalculator allows Stored XSS.This issue affects ConvertCalculator for WordPress: from n/a through <= 1.1.1.
AplazadaMedia (5.3)0.34%—Ruslan Suhar ConvertfulAI2/1/202517/6/2026
Missing Authorization vulnerability in Ruslan Suhar Convertful – Your Ultimate On-Site Conversion Tool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Convertful – Your Ultimate On-Site Conversion Tool: from n/a through 2.5.
AplazadaMedia (6.4)0.28%—Currency Converter Widget PROAI12/12/202417/6/2026
The Currency Converter Widget ⚡ PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'currency-converter-widget-pro' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AnalizadaMedia (5.4)0.22%—Convert Forms Project Convert Forms4/12/202417/6/2026
Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8.
AnalizadaCrítica (9.8)0.52%—Convert Forms Project Convert Forms4/12/202417/6/2026
Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.
AplazadaCrítica (9.1)0.49%—Davor Zeljkovic Convert Docx2postAI16/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Davor Zeljkovic Convert Docx2post convert-docx2post allows Upload a Web Shell to a Web Server.This issue affects Convert Docx2post: from n/a through <= 1.4.
AplazadaMedia (6.4)0.85%—ConvertcalculatorAI16/11/202417/6/2026
The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'type' parameters in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…
AplazadaMedia (6.5)0.40%—Automattic Newspack Content ConverterAI1/11/202417/6/2026
Missing Authorization vulnerability in Automattic Newspack Content Converter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack Content Converter: from n/a through 0.1.5.
ModificadaMedia (5.4)0.25%—Crossedcode Bverse Convert18/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edwin Rivera bVerse Convert bverse-convert allows Stored XSS.This issue affects bVerse Convert: from n/a through <= 1.3.7.1.
AnalizadaAlta (8.5)0.21%—Vso-software Convertxtodvd17/10/202417/6/2026
A vulnerability, which was classified as critical, was found in VSO ConvertXtoDvd 7.0.0.83. Affected is an unknown function in the library avcodec.dll of the file ConvertXtoDvd.exe. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and…
AplazadaAlta (7.1)0.35%—Appmaker - Convert Woocommerce TO Android & IOS Native Mobile AppsAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Appmaker Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps allows Reflected XSS.This issue affects Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps: from n/a through 1.36.12.
AplazadaCrítica (9.1)0.49%—Spreadsheetconverter Import Spreadsheets From Microsoft ExcelAI12/7/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Code Injection.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.4.
ModificadaMedia (5.3)0.37%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages21/6/202417/6/2026
The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to…
ModificadaCrítica (9.8)0.57%—Brainstormforce Convert PRO19/6/202417/6/2026
Missing Authorization vulnerability in Brainstorm Force Convert Pro.This issue affects Convert Pro: from n/a through 1.7.5.
ModificadaMedia (5.3)0.41%—Moreconvert Woocommerce Wishlist11/6/202417/6/2026
Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.2.
AplazadaMedia (5.3)0.32%—Moreconvert MC Woocommerce WishlistAI11/6/202417/6/2026
Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.8.
AplazadaAlta (7.5)0.59%—Convertplug ConvertplusAI16/5/202417/6/2026
The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_modal' shortcode. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaAlta (8.8)0.77%—ConvertplugAI4/5/202417/6/2026
The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_info_bar' shortcode. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaMedia (5.4)0.37%—ConvertplugAI4/5/202417/6/2026
The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cp_dismiss_notice() function in all versions up to, and including, 3.5.25. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary…
AplazadaAlta (7.1)0.33%—Organic Themes Bulk Block ConverterAI17/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Organic Themes Bulk Block Converter allows Reflected XSS.This issue affects Bulk Block Converter: from n/a through 1.0.1.
Orbitaley — Vulnerabilidades