Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

489 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.55%—Wedevs User FrontendAI26/2/202617/6/2026
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext'…
AnalizadaCrítica (10)1.0%💥 PoCAgentfront Enclave25/2/202617/6/2026
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be used to achieve remote code execution (RCE). The issue has been fixed in version 2.11.1.
AplazadaMedia (5.3)0.34%—Nmedia Frontend File ManagerAI19/2/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.5.
AplazadaMedia (6.1)0.46%💥 ExploitFrontend Post Submission Manager LiteAI18/2/202617/6/2026
The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to insufficient validation on the 'requested_page' POST parameter in the verify_username_password function. This makes it possible for unauthenticated attackers to redirect…
AplazadaMedia (4.3)0.16%—Frontend User NotesAI18/2/202617/6/2026
The Frontend User Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'funp_ajax_modify_notes' AJAX endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access…
AplazadaMedia (5.8)0.70%💥 ExploitNajeebmedia Frontend File ManagerAI17/2/202617/6/2026
The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded…
AplazadaAlta (7.2)0.46%—Wcfm Frontend ManagerAI10/2/202617/6/2026
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'WCFM_Settings_Controller::processing' function in all versions up to,…
AnalizadaMedia (6.4)0.23%—Agentfront Enclave6/2/202617/6/2026
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers of security in enclave-vm are insufficient: The AST sanitization can be bypassed with dynamic property accesses, the hardening of the error objects does not cover the peculiar behavior or the vm…
AnalizadaCrítica (9.8)1.2%—Microsoft Azure Front Door5/2/202617/6/2026
Azure Front Door Elevation of Privilege Vulnerability
AplazadaAlta (8.8)0.41%—Infor Storefront B2BAI30/1/202617/6/2026
Infor Storefront B2B 1.0 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'usr_name' parameter in login requests. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'usr_name' parameter to potentially extract or modify database…
AplazadaAlta (7.5)0.34%—Najeebmedia Frontend File ManagerAI28/1/202617/6/2026
The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_email' AJAX action in all versions up to, and including, 23.5. This makes it possible for unauthenticated attackers to share arbitrary uploaded files via email by…
AplazadaAlta (7.2)0.24%—User Submitted Posts Enable Users TO Submit Posts From THE Front ENDAI24/1/202617/6/2026
The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom fields in all versions up to, and including, 20251210 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaAlta (7.2)0.36%—Frontis BlocksAI24/1/202617/6/2026
The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.6. This is due to insufficient restriction on the 'url' parameter in the 'template_proxy' function. This makes it possible for unauthenticated attackers to make web requests to arbitrary…
AnalizadaCrítica (9.8)0.86%💥 PoCMicrosoft Azure Front Door22/1/202617/6/2026
Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
AplazadaAlta (7.1)0.22%—Jegtheme Jnews Frontend SubmitAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews - Frontend Submit jnews-frontend-submit allows Reflected XSS.This issue affects JNews - Frontend Submit: from n/a through <= 11.0.0.
AplazadaAlta (7.2)0.29%—Wpmessiah Frontis BlocksAI22/1/202617/6/2026
Server-Side Request Forgery (SSRF) vulnerability in WP Messiah Frontis Blocks frontis-blocks allows Server Side Request Forgery.This issue affects Frontis Blocks: from n/a through <= 1.1.5.
AnalizadaCrítica (10)0.76%💥 PoCAgentfront Enclave14/1/202617/6/2026
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in enclave-vm that allows untrusted, sandboxed JavaScript code to execute arbitrary code in the host Node.js runtime. When a tool invocation fails, enclave-vm exposes a…
AplazadaAlta (7.2)0.29%—Dynamiapps Frontend AdminAI9/1/202617/6/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parameter in the 'frontend_admin/forms/update_field' AJAX action in all versions up to, and including, 3.28.23 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaCrítica (9.1)0.38%—Dynamiapps Frontend AdminAI9/1/202617/6/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for unauthenticated attackers to delete…
AplazadaCrítica (9.8)0.72%💥 PoCDynamiapps Frontend AdminAI9/1/202617/6/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for…
AplazadaMedia (5.3)0.27%—WP Front User SubmitAI7/1/202617/6/2026
The Guest posting / Frontend Posting / Front Editor – WP Front User Submit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bfe/v1/revert' REST API endpoint in all versions up to, and including, 5.0.0. This makes it possible for unauthenticated…
AplazadaAlta (7.7)0.27%—Najeebmedia Frontend File ManagerAI7/1/20267/10/2026
The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server
AplazadaMedia (5.3)0.90%💥 ExploitWedevs WP User FrontendAI2/1/202617/6/2026
The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'Frontend_Form_Ajax::submit_post' function in all versions up to, and including,…
AplazadaMedia (5.3)0.32%—Frontend Post Submission Manager LiteAI25/12/20255/10/2026
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to an incorrect authorization check on the 'media_delete_action' function in all versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers…
AplazadaMedia (5.3)0.28%—Frontend Post Submission Manager LiteAI21/12/202517/6/2026
The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.5. This is due to missing authorization checks on the post update functionality in the fpsml_form_process AJAX action. This makes it possible for unauthenticated attackers to…
Orbitaley — Vulnerabilidades