Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
250 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.25% | — | IBM Openpages With Watson | 20/2/2025 | 17/6/2026 | IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages with Watson Assistant chat feature enabled the application establishes a session when a user logs in and uses chat, but the chat session is still left active after logout. | |
| Analizada | Media (5.4) | 0.27% | — | IBM Openpages With Watson | 20/2/2025 | 17/6/2026 | IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation of user-supplied input of text fields used to construct workflow email notifications. A remote authenticated attacker could exploit this vulnerability using HTML tags in a text field of an object to… | |
| Analizada | Alta (8.2) | 0.37% | — | IBM Openpages With Watson | 20/2/2025 | 17/6/2026 | IBM OpenPages with Watson 8.3 and 9.0 could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit this vulnerability to gain access to sensitive information disclosed through email notifications generated by OpenPages or disrupt notification delivery. | |
| Analizada | Media (6.5) | 0.57% | — | IBM Openpages With Watson | 20/2/2025 | 17/6/2026 | IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration… | |
| Analizada | Media (6.5) | 0.28% | — | IBM Openpages With Watson | 20/2/2025 | 17/6/2026 | IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enabled per the System Tracing feature. | |
| Analizada | Media (4.3) | 0.24% | — | IBM Openpages With Watson | 20/2/2025 | 17/6/2026 | IBM OpenPages with Watson 8.3 and 9.0 application could allow an authenticated user to manipulate data in the Questionnaires application allowing the user to spoof other users' responses. | |
| Analizada | Crítica (9.8) | 1.6% | ⚠ Explotación activa | Microsoft Power Pages | 19/2/2025 | 17/6/2026 | An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the… | |
| Aplazada | Alta (7.1) | 0.25% | — | Johannes VAN Poelgeest Admin Options PagesAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johannes van Poelgeest Admin Options Pages admin-options-pages allows Reflected XSS.This issue affects Admin Options Pages: from n/a through <= 0.9.7. | |
| Analizada | Media (4.8) | 0.31% | — | Mijnpress Simple ADD Pages OR Posts | 8/2/2025 | 17/6/2026 | The Simple add pages or posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in… | |
| Analizada | Media (5.4) | 0.23% | — | IBM Openpages With Watson | 27/1/2025 | 17/6/2026 | IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Media (5.9) | 0.38% | — | Kylephillips Nested PagesAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages wp-nested-pages allows Stored XSS.This issue affects Nested Pages: from n/a through <= 3.2.9. | |
| Aplazada | Alta (7.1) | 0.22% | — | Madeglobal Better Protected PagesAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in madeglobal Better Protected Pages better-protected-pages allows Stored XSS.This issue affects Better Protected Pages: from n/a through <= 1.0. | |
| Analizada | Media (5.3) | 0.30% | — | Ciandt Pages Restriction Access | 9/1/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pages Restriction Access: from 2.0.0 before 2.0.3. | |
| Aplazada | Alta (7.1) | 0.32% | — | Otwthemes Widgetize Pages LightAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Reflected XSS.This issue affects Widgetize Pages Light: from n/a through <= 3.0. | |
| Analizada | Media (5.4) | 0.28% | — | IBM Openpages With Watson | 9/1/2025 | 17/6/2026 | IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privileged users. | |
| Aplazada | Media (6.5) | 0.35% | — | Benhuson List Pages AT DepthAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ben Huson List Pages at Depth list-pages-at-depth allows Stored XSS.This issue affects List Pages at Depth: from n/a through <= 1.5. | |
| Aplazada | Media (6.1) | 0.20% | — | Mijnpress Simple ADD Pages OR PostsAI | 7/1/2025 | 17/6/2026 | The Simple add pages or posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request… | |
| Aplazada | Media (4.3) | 0.18% | — | Wplegalpages WP Legal PagesAI | 25/12/2024 | 17/6/2026 | The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.6. This is due to missing or incorrect nonce validation on the 'create_popup_delete_process' function. This makes it… | |
| Analizada | Media (6.1) | 0.29% | — | Ampforwp Accelerated Mobile Pages | 18/12/2024 | 17/6/2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Analizada | Media (4.4) | 0.21% | — | IBM Openpages With Watson | 11/12/2024 | 17/6/2026 | IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained by a privileged user. | |
| Aplazada | Media (5.3) | 0.51% | — | Webflow PagesAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Webflow Webflow Pages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Webflow Pages: from n/a through 1.0.8. | |
| Analizada | Alta (8.8) | 0.29% | — | Ampforwp Accelerated Mobile Pages | 25/10/2024 | 17/6/2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated attackers to send the logged in user's… | |
| Analizada | Media (4.3) | 0.30% | — | IBM Openpages GRC PlatformIBM Openpages With Watson | 10/9/2024 | 17/6/2026 | IBM OpenPages 8.3 and 9.0 potentially exposes information about client-side source code through use of JavaScript source maps to unauthorized users. | |
| Analizada | Media (6.5) | 0.44% | — | IBM Openpages GRC PlatformIBM Openpages With Watson | 22/8/2024 | 17/6/2026 | IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs. | |
| Modificada | Media (5.4) | 0.33% | — | Ampforwp Accelerated Mobile Pages | 24/7/2024 | 17/6/2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.96.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and… |