Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.41% | — | Happyforms | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Happyforms Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms allows Reflected XSS.This issue affects Form builder to get in touch with visitors, grow your email list… | |
| Modificada | Media (5.4) | 0.40% | — | Happybox Newsletter & Bulk Email Sender | 25/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in HappyBox Newsletter & Bulk Email Sender – Email Newsletter Plugin for WordPress plugin <= 2.0.1 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Wedevs Happy Addons FOR Elementor | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Happy addons Happy Elementor Addons Pro plugin <= 2.8.0 versions. | |
| Modificada | Alta (8.8) | 0.88% | — | Nbs&happysoftwechat | 18/8/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in NBS&HappySoftWeChat 1.1.6. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this… | |
| Modificada | Media (4.3) | 0.93% | 💥 PoC | Wphappycoders Comments Like Dislike | 17/8/2023 | 17/6/2026 | The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers with minimal permissions, such as a… | |
| Modificada | Alta (8.8) | 0.32% | — | Wedevs Happy Addons FOR Elementor | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in weDevs Happy Addons for Elementor plugin <= 3.8.2 versions. | |
| Modificada | Media (5.4) | 0.50% | — | Happyforms | 6/2/2023 | 17/6/2026 | The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.3) | 0.98% | — | Wphappycoders Comments Like Dislike | 21/6/2021 | 17/6/2026 | The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying the AJAX request to add a like. This allows any user (even unauthenticated) to add unlimited like/dislike to any comment. The plugin appears to have some Restriction modes,… | |
| Modificada | Media (5.4) | 0.64% | — | Wedevs Happy Addons FOR Elementor | 17/5/2021 | 17/6/2026 | The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_tag”… | |
| Modificada | Alta (8.1) | 1.2% | — | Happypointcard Happypoint | 1/8/2019 | 17/6/2026 | When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL. | |
| Modificada | Alta (7.8) | 1.5% | — | Akabei Soft2 Happy Wardrobe | 2/9/2016 | 17/6/2026 | AKABEi SOFT2 games allow remote attackers to execute arbitrary OS commands via crafted saved data, as demonstrated by Happy Wardrobe. | |
| Modificada | Media (4.3) | 0.97% | — | Tuttophp Happy Chat | 1/1/2015 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in profilo.php in Happy Chat 1.0 allows remote attackers to inject arbitrary web script or HTML via the nick parameter. | |
| Modificada | Media (5.4) | 1.1% | — | Happycloud Happy | 19/10/2014 | 17/6/2026 | The HAPPY (aka com.tw.knowhowdesign.sinfonghuei) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Happylabs Hotel Story\ | 9/9/2014 | 17/6/2026 | The Hotel Story: Resort Simulation (aka com.happylabs.hotelstory) application 1.7.9B for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 2.7% | — | Happyworm Jplayer | 17/8/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.23 allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, a different vulnerability than CVE-2013-1942 and CVE-2013-2023, as… | |
| Modificada | Media (4.3) | 2.8% | — | Happyworm Jplayer | 15/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to incomplete blacklists, a different vulnerability than CVE-2013-1942 and… | |
| Modificada | Media (4.3) | 5.5% | 💥 Exploit | Happyworm JplayerOwncloudOwncloud Server | 15/8/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.20, as used in ownCloud Server before 5.0.4 and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, as… | |
| Modificada | Alta (7.5) | 5.5% | 💥 Exploit | Wf-sectionsXoops Happy Linux Xfsection ModuleXoops Zmagazine Module | 12/4/2007 | 16/6/2026 | SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modules such as (1) Zmagazine 1.0, (2) Happy Linux XFsection 1.07 and earlier, and possibly other modules, allows remote attackers to execute arbitrary SQL commands via the articleid… | |
| Modificada | Media (6.8) | 3.9% | 💥 Exploit | Happycgi.com Happymall | 16/6/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter. | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Happycgi Happymall | 16/6/2003 | 16/6/2026 | Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter. | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Happycgi Happymall | 27/5/2003 | 16/6/2026 | Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts. |