Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6) | 0.34% | — | Zabbix Frontend | 1/12/2025 | 25/9/2026 | An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service. | |
| Analizada | Media (6.8) | 0.29% | — | Zabbix Frontend | 1/12/2025 | 25/9/2026 | An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss. | |
| Aplazada | Media (4.3) | 0.23% | — | Najeebmedia Frontend File ManagerAI | 25/11/2025 | 17/6/2026 | The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 23.4. This is due to the plugin not validating file ownership before processing file rename requests in the '/wpfm/v1/file-rename' REST API endpoint. This makes it possible for… | |
| Aplazada | Media (4.7) | 0.20% | — | Guest Posting Frontend Posting Front EditorAI | 24/11/2025 | 30/9/2026 | The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue | |
| Analizada | Alta (7.5) | 0.59% | — | Openml Frontend | 18/11/2025 | 29/9/2026 | The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup confirmation, password resets, email confirmation resends, and email change confirmation. These tokens are generated by hashing the current timestamp formatted as "%d %H:%M:%S"… | |
| Aplazada | Media (4.3) | 0.19% | — | Nmedia Frontend File ManagerAI | 13/11/2025 | 17/6/2026 | Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.2. | |
| Modificada | Crítica (9.8) | 0.50% | — | Wpeverest Everest Forms Frontend Listing | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing everest-forms-frontend-listing allows Object Injection.This issue affects Everest Forms - Frontend Listing: from n/a through <= 1.0.5. | |
| Analizada | Baja (3.5) | 0.30% | — | Openml Frontend | 29/9/2025 | 29/9/2026 | The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated attacker controlling a user account with a lower user ID can update their email address to that of another user with a higher user ID… | |
| Aplazada | Media (5.4) | 0.23% | — | Wedevs WP User FrontendAI | 22/9/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from n/a through <= 4.1.12. | |
| Aplazada | Media (5.4) | 0.27% | — | Wedevs WP User FrontendAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.1.12. | |
| Aplazada | Media (5.3) | 0.32% | — | Nmedia Frontend File ManagerAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.3. | |
| Aplazada | Media (6.5) | 0.28% | — | Josevega WP Frontend AdminAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Vega WP Frontend Admin display-admin-page-on-frontend allows Stored XSS.This issue affects WP Frontend Admin: from n/a through <= 1.22.7. | |
| Aplazada | Alta (8.5) | 0.27% | — | Dynamiapps Frontend AdminAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-form-element allows Blind SQL Injection.This issue affects Frontend Admin by DynamiApps: from n/a through <= 3.28.3. | |
| Aplazada | Alta (7.5) | 0.32% | — | Najeebmedia Frontend File ManagerAI | 25/7/2025 | 17/6/2026 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete_multiple_files() function in all versions up to, and including, 21.5. This makes it possible for unauthenticated attackers to delete arbitrary posts. | |
| Analizada | Media (6.5) | 0.27% | — | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 9/7/2025 | 17/6/2026 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcfm_redirect_to_setup function in all versions up to, and including, 6.7.16. This makes it possible for… | |
| Aplazada | Media (6.8) | 0.48% | — | Dynamiapps ACF Frontend Form ElementAI | 4/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-form-element allows Path Traversal.This issue affects Frontend Admin by DynamiApps: from n/a through <= 3.28.7. | |
| Aplazada | Media (4.6) | 0.21% | — | Nmedia Frontend File ManagerAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Code Injection.This issue affects Frontend File Manager: from n/a through <= 23.6. | |
| Aplazada | Media (6.5) | 0.32% | — | Openlist FrontendAI | 19/6/2025 | 17/6/2026 | OpenList Frontend is a UI component for OpenList. Prior to version 4.0.0-rc.4, a vulnerability exists in the file preview/browsing feature of the application, where files with a .py extension that contain JavaScript code wrapped in <script> tags may be interpreted and executed as HTML in certain modes. This leads to a… | |
| Aplazada | Crítica (9.8) | 0.59% | — | Themeton Pressgrid - Frontend Publish Reaction & Multimedia ThemeAI | 9/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton PressGrid - Frontend Publish Reaction & Multimedia Theme allows Object Injection. This issue affects PressGrid - Frontend Publish Reaction & Multimedia Theme: from n/a through 1.3.1. | |
| Aplazada | Media (6.5) | 0.25% | — | Buffercode Frontend DashboardAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Frontend Dashboard frontend-dashboard allows Stored XSS.This issue affects Frontend Dashboard: from n/a through <= 2.2.8. | |
| Aplazada | Alta (8.1) | 0.81% | — | Wedevs WP User FrontendAI | 5/6/2025 | 17/6/2026 | The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_avatar_ajax() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… | |
| Aplazada | Alta (8.8) | 0.92% | 💥 PoC | WP User Frontend PROAI | 5/6/2025 | 17/6/2026 | The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on… | |
| Aplazada | Alta (8.8) | 0.43% | — | Buffercode Frontend DashboardAI | 13/5/2025 | 17/6/2026 | The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_admin_setting_form_function() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the plugin’s… | |
| Aplazada | Alta (8.8) | 0.45% | — | Buffercode Frontend DashboardAI | 13/5/2025 | 17/6/2026 | The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_request() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to control where the plugin sends outgoing emails. By… | |
| Aplazada | Crítica (9.8) | 7.4% | 💥 Exploit | Frontend Login AND Registration BlocksAI | 9/5/2025 | 17/6/2026 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email via the… |