Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
99 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.43% | — | Wordpress Blogger Importer | 4/6/2023 | 16/6/2026 | A vulnerability was found in Blogger Importer Plugin up to 0.5 on WordPress. It has been classified as problematic. Affected is the function start/restart of the file blogger-importer.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. Upgrading to version 0.6 is… | |
| Modificada | Alta (8.8) | 0.26% | — | Secondlinethemes Auto Youtube Importer | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SecondLineThemes Auto YouTube Importer plugin <= 1.0.3 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Json-content-importer Json Content Importer | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bernhard Kux JSON Content Importer plugin <= 1.3.15 versions. | |
| Modificada | Media (6.5) | 0.77% | — | Mendix Excel Importer | 12/7/2022 | 17/6/2026 | A vulnerability has been identified in Mendix Excel Importer Module (Mendix 8 compatible) (All versions < V9.2.2), Mendix Excel Importer Module (Mendix 9 compatible) (All versions < V10.1.2). The affected component is vulnerable to XML Entity Expansion Injection. An attacker may use this to compromise the availability… | |
| Modificada | Media (6.1) | 0.79% | — | Visser Woocommerce - Product Importer | 11/7/2022 | 17/6/2026 | The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.79% | — | Ultimate Woocommerce CSV Importer Project Ultimate Woocommerce CSV Importer | 27/6/2022 | 17/6/2026 | The Ultimate WooCommerce CSV Importer WordPress plugin through 2.0 does not sanitise and escape the imported data before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (8.1) | 0.48% | — | Accesspressthemes Access Demo Importer | 18/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (posts / pages / media). | |
| Modificada | Media (6.5) | 0.49% | — | Accesspressthemes Access Demo Importer | 18/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any installed plugin. | |
| Modificada | Alta (7.2) | 1.5% | — | Secondlinethemes Podcast Importer Secondline | 11/4/2022 | 17/6/2026 | The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file | |
| Modificada | Alta (8.1) | 1.1% | — | Hashthemes Demo Importer | 1/11/2021 | 17/6/2026 | The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads. | |
| Modificada | Media (4.8) | 0.99% | — | Indeed-job-importer Project Indeed-job-importer | 19/10/2021 | 17/6/2026 | The Indeed Job Importer WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/indeed-job-importer/trunk/indeed-job-importer.php file which allowed attackers with administrative user access to inject arbitrary web… | |
| Modificada | Alta (8.8) | 1.7% | — | Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+39 | 11/10/2021 | 17/6/2026 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the… | |
| Modificada | Alta (7.5) | 1.7% | — | Podcast Importer Secondline | 7/7/2021 | 17/6/2026 | Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for WordPress via the podcast_feed parameter in a secondline_import_initialize action to the secondlinepodcastimport page. | |
| Modificada | Media (4.3) | 0.76% | — | Mendix Excel Importer | 12/5/2021 | 17/6/2026 | A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML File results in an exception that could expose information about the Application-Server and the used XML-Framework. | |
| Modificada | Alta (8.8) | 0.65% | — | Themegrill Demo Importer | 5/5/2021 | 17/6/2026 | themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database. | |
| Modificada | Crítica (9.1) | 4.1% | 💥 Exploit | Themegrill Demo Importer | 5/5/2021 | 17/6/2026 | themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook. | |
| Modificada | Alta (8.8) | 1.6% | — | Cyberchimps Gutenberg & Elementor Templates Importer FOR Responsive | 23/4/2020 | 17/6/2026 | The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests. | |
| Modificada | Alta (8.2) | 0.59% | — | Jenkins Spira Importer | 17/12/2019 | 17/6/2026 | Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM. | |
| Modificada | Media (5.5) | 0.32% | — | Jenkins Spira Importer | 21/11/2019 | 17/6/2026 | Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Media (6.5) | 0.97% | — | Kubevirt Containerized-data-importer | 28/6/2019 | 17/6/2026 | A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine whether the requesting user has permission to access the Persistent Volume Claim (PVC) in the source namespace. This could allow users to clone any PVC in the cluster into… | |
| Modificada | Media (6.8) | 0.53% | — | Kubevirt Containerized Data Importer | 25/3/2019 | 17/6/2026 | Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when importing data into PVCs from container registries. This could enable man-in-the-middle attacks between a container registry and the virt-cdi-component, leading to possible undetected tampering of… | |
| Modificada | Media (4) | 1.1% | — | Open Graph Importer Project Open Graph Importer | 15/6/2015 | 17/6/2026 | The Open Graph Importer (og_tag_importer) 7.x-1.x for Drupal does not properly check the create permission for content types created during import, which allows remote authenticated users to bypass intended restrictions by leveraging the "import og_tag_importer" permission. | |
| Modificada | Media (6.8) | 3.4% | — | Sourceforge Wordperfect Document Importer-exporter | 16/3/2007 | 16/6/2026 | Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file, a different vulnerability than… | |
| Modificada | Alta (7.5) | 6.1% | — | Comdev CSV Importer | 3/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) Comdev Events Calendar 3.1, (4) Comdev FAQ Support 3.1, (5) Comdev Guestbook 3.1, (6) Comdev Links Directory 3.1, (7) Comdev News Publisher… |