Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.0% | — | Ewww Image Optimizer | 30/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a through 7.2.0. | |
| Modificada | Media (6.1) | 0.85% | — | 10web Image Optimizer | 16/8/2023 | 17/6/2026 | The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a… | |
| Modificada | Media (4.3) | 0.38% | — | Ewww Image Optimizer | 12/7/2023 | 17/6/2026 | The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a… | |
| Modificada | Baja (2.7) | 0.66% | — | 10web Image Optimizer | 30/5/2023 | 17/6/2026 | The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root. | |
| Modificada | Alta (7.5) | 0.84% | — | Apng Optimizer Project Apng Optimizer | 17/4/2023 | 17/6/2026 | APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png. | |
| Modificada | Alta (8.8) | 0.22% | — | Wordpress Ping Optimizer Project Wordpress Ping Optimizer | 27/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pankaj Jha WordPress Ping Optimizer plugin <= 2.35.1.2.3 versions. | |
| Modificada | Media (6.5) | 0.68% | — | Kraken.io Image Optimizer | 1/2/2023 | 17/6/2026 | The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset image optimizations. | |
| Modificada | Media (4.8) | 0.47% | — | Sirv Image Optimizer, Resizer AND CDN | 2/1/2023 | 17/6/2026 | The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.3) | 0.51% | — | Resmush.it Image Optimizer | 14/11/2022 | 17/6/2026 | The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them. | |
| Modificada | Media (6.5) | 0.34% | — | Resmush.it Image Optimizer | 14/11/2022 | 17/6/2026 | The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF checks for any of its AJAX actions, allowing an attackers to trick logged in users to perform various actions on their behalf on the site. | |
| Modificada | Media (4.8) | 0.44% | — | Abpressoptimizer AB Press Optimizer | 17/10/2022 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology AB Press Optimizer plugin <= 1.1.1 on WordPress. | |
| Modificada | Media (4.8) | 0.55% | — | Resmush.it Image Optimizer | 10/10/2022 | 17/6/2026 | The reSmush.it WordPress plugin before 0.4.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when unfiltered_html is disallowed. | |
| Modificada | Alta (8.8) | 0.36% | — | Kraken.io Image Optimizer | 23/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kraken.io Image Optimizer plugin <= 2.6.5 at WordPress. | |
| Modificada | Media (4.3) | 0.34% | — | Wordpress Ping Optimizer Project Wordpress Ping Optimizer | 19/9/2022 | 17/6/2026 | The WordPress Ping Optimizer WordPress plugin before 2.35.1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Alta (8.8) | 0.67% | — | Link Optimizer Lite Project Link Optimizer Lite | 6/9/2022 | 17/6/2026 | The Link Optimizer Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 1.4.5. This is due to missing nonce validation on the admin_page function found in the ~/admin.php file. This makes it possible for unauthenticated attackers to modify the… | |
| Modificada | Crítica (9.8) | 2.9% | — | Siteground Security Optimizer | 19/4/2022 | 17/6/2026 | The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA for pending accounts. Upon successful… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Crítica (10) | 3.7% | — | Ewww Image Optimizer | 5/5/2021 | 17/6/2026 | EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5. | |
| Modificada | Media (5.3) | 2.1% | — | Thrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+16 | 12/4/2021 | 17/6/2026 | The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive… | |
| Modificada | Alta (7.8) | 3.4% | — | Deutschepost Mailoptimizer | 5/3/2021 | 17/6/2026 | Deutsche Post Mailoptimizer 4.3 before 2020-11-09 allows Directory Traversal via a crafted ZIP archive to the Upload feature or the MO Connect component. This can lead to remote code execution. | |
| Modificada | Alta (7.8) | 1.1% | — | Dell Precision Optimizer | 24/4/2018 | 17/6/2026 | An exploitable dll hijacking vulnerability exists in the poaService.exe service component of the Dell Precision Optimizer software version 3.5.5.0. A specifically named malicious dll file located in one of directories pointed to by the PATH environment variable will lead to privilege escalation. An attacker with local… | |
| Modificada | Alta (7.5) | 6.3% | — | HP Cloud Optimizer | 15/2/2018 | 17/6/2026 | A Remote Disclosure of Information vulnerability in HPE Cloud Optimizer version v3.0x was found. | |
| Modificada | Media (4.3) | 2.1% | — | Ewww Image Optimizer Plugin Project Ewww Image Optimizer Plugin | 10/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the EWWW Image Optimizer plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the error parameter in the ewww-image-optimizer.php page to wp-admin/options-general.php, which is not properly handled in a pngout error message. | |
| Modificada | Alta (7.5) | 5.5% | — | HP Application Information Optimizer | 26/2/2014 | 17/6/2026 | The Web Console in HP Application Information Optimizer (formerly HP Database Archiving) 6.2, 6.3, 6.4, 7.0, and 7.1 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, aka ZDI-CAN-2004. | |
| Modificada | Alta (7.5) | 5.5% | — | HP Application Information Optimizer | 26/2/2014 | 17/6/2026 | The Web Console in HP Application Information Optimizer (formerly HP Database Archiving) 6.2, 6.3, 6.4, 7.0, and 7.1 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, aka ZDI-CAN-1656. |