Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
111 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.6) | 0.47% | — | Langgenius Dify | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log functionality. The vulnerability arises because certain HTML tags like <input> and <form> are not disallowed, allowing an attacker to inject malicious HTML into the log via prompts. When an admin… | |
| Analizada | Alta (7.5) | 0.60% | — | Dify | 20/3/2025 | 17/6/2026 | langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due to improper handling of the api_endpoint parameter, allowing an attacker to make direct requests to internal network services. This can lead to unauthorized access to internal servers and potentially… | |
| Analizada | Media (4.3) | 0.48% | — | Langgenius Dify | 20/3/2025 | 17/6/2026 | A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to modify Orchestrate instructions for a chatbot created by an admin user. The issue arises because the application does not properly enforce access controls on the endpoint… | |
| Analizada | Alta (7.2) | 0.81% | — | Langgenius Dify | 20/3/2025 | 17/6/2026 | A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading to the deletion of the entire sandbox… | |
| Analizada | Media (6.5) | 0.33% | — | Astoundify Jobify | 24/1/2025 | 17/6/2026 | The Jobify - Job Board WordPress Theme for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'download_image_via_ai' and 'generate_image_via_ai' functions in all versions up to, and including, 4.2.7. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.4) | 0.59% | — | FedifyAI | 20/1/2025 | 17/6/2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. This vulnerability allows a user to maneuver the Webfinger mechanism to perform a GET request to any internal resource on any Host, Port, URL combination regardless of present security mechanisms, and forcing… | |
| Aplazada | Media (6.1) | 0.37% | — | FeedifyAI | 20/12/2024 | 17/6/2026 | The Feedify – Web Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'platform', 'phone', 'email', and 'store_url' parameters. in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Modificada | Crítica (9.8) | 0.66% | — | Xtendify Woffice | 16/12/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice woffice allows Authentication Bypass.This issue affects Woffice: from n/a through <= 5.4.14. | |
| Modificada | Crítica (9.8) | 0.37% | — | Astoundify Jobify | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Astoundify Jobify jobify.This issue affects Jobify: from n/a through < 4.3.0. | |
| Analizada | Media (6.1) | 0.29% | — | Astoundify WP JOB Manager | 4/12/2024 | 17/6/2026 | The WP Job Manager – Company Profiles plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'company' parameter in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Alta (8.8) | 0.19% | — | Astoundify Jobify | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Astoundify Jobify jobify allows Cross Site Request Forgery.This issue affects Jobify: from n/a through < 4.3.0. | |
| Modificada | Media (5.4) | 0.28% | — | Astoundify Jobify | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify Jobify jobify allows Stored XSS.This issue affects Jobify: from n/a through < 4.3.0. | |
| Modificada | Alta (7.5) | 0.67% | — | Astoundify Jobify | 28/11/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Astoundify Jobify jobify allows Relative Path Traversal.This issue affects Jobify: from n/a through < 4.3.0. | |
| Analizada | Crítica (9.8) | 0.50% | — | Xtendify Woffice | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WofficeIO Woffice Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woffice Core: from n/a through 5.4.8. | |
| Analizada | Media (5.4) | 0.31% | — | Tahoe Debrandify | 18/10/2024 | 17/6/2026 | The Debrandify · Remove or Replace WordPress Branding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… | |
| Analizada | Media (6.1) | 0.49% | — | Xtendify Simple Calendar | 25/9/2024 | 17/6/2026 | The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Crítica (9.8) | 0.62% | — | Xtendify Woffice | 13/8/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10. | |
| Aplazada | Alta (7.5) | 0.62% | — | AudifyAI | 10/7/2024 | 17/6/2026 | All versions of the package audify are vulnerable to Improper Validation of Array Index when frameSize is provided to the new OpusDecoder().decode or new OpusDecoder().decodeFloat functions it is not checked for negative values. This can lead to a process crash. | |
| Aplazada | Alta (7.2) | 0.60% | — | FedifyAI | 5/7/2024 | 17/6/2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. At present, when Fedify needs to retrieve an object or activity from a remote activitypub server, it makes a HTTP request to the `@id` or other resources present within the activity it has received from the… | |
| Modificada | Media (6.1) | 0.33% | — | Xtendify Woffice | 4/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.8. | |
| Analizada | Media (6.1) | 0.29% | — | Xtendify Woffice | 4/7/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Astoundify Simple Registration FOR WoocommerceAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Astoundify Simple Registration for WooCommerce allows Privilege Escalation.This issue affects Simple Registration for WooCommerce: from n/a through 1.5.6. | |
| Aplazada | Media (6.4) | 0.39% | — | Extendify EditorskitAI | 30/3/2024 | 17/6/2026 | The Gutenberg Block Editor Toolkit – EditorsKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'editorskit' shortcode in all versions up to, and including, 1.40.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Alta (7.2) | 1.5% | — | Extendify Editorskit | 5/2/2024 | 17/6/2026 | The EditorsKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the 'import_styles' function in versions up to, and including, 1.40.3. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the… | |
| Modificada | Crítica (9.8) | 0.83% | — | Addify Free Gifts | 1/11/2023 | 17/6/2026 | SQL injection vulnerability in addify Addifyfreegifts v.1.0.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the getrulebyid function in the AddifyfreegiftsModel.php component. |