Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

282 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.34%—Onion-site-templateAI6/8/202517/6/2026
onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor image if the secrets were copied from an existing onion domain. A website could be compromised if a user shared the baked-in image, or if someone were able to acquire access…
AplazadaMedia (6.5)0.32%💥 PoCWritebot AI Content Generator Saas React TemplateAI5/8/20255/7/2026
File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via a crafted POST request to the /file-upload endpoint.
AplazadaCrítica (9.8)0.36%—Flask-boilerplateAI7/7/202517/6/2026
flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.
AnalizadaBaja (2.4)0.15%—Flocksafety License Plate Reader Firmware27/6/202517/6/2026
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.
AnalizadaMedia (4.6)0.24%—Flocksafety License Plate Reader Firmware27/6/202517/6/2026
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system.
AnalizadaMedia (6.8)0.25%—Flocksafety License Plate Reader Firmware27/6/202517/6/2026
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control.
AnalizadaMedia (4.3)0.14%—Themebon Digital Marketing AND Agency Templates Addons FOR Elementor13/6/202517/6/2026
The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the import_templates() function. This makes it possible for unauthenticated attackers to…
AplazadaMedia (5.9)0.26%—Otowthemes Post Custom Templates LiteAI6/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Post Custom Templates Lite post-custom-templates-lite allows Stored XSS.This issue affects Post Custom Templates Lite: from n/a through <= 1.14.
AplazadaCrítica (10)4.6%💥 ExploitTemplateinvaders TI Woocommerce WishlistAI19/5/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Upload a Web Shell to a Web Server.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.9.2.
AplazadaMedia (6.5)0.24%—Templateinvaders TI Woocommerce WishlistAI19/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Stored XSS.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.10.0.
AplazadaAlta (7.2)0.76%—ADD Custom Page TemplateAI26/4/202517/6/2026
The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'acpt_validate_setting' function. This is due to insufficient sanitization of the 'template_name' parameter. This makes it possible for…
AplazadaCrítica (9.3)0.37%—Webbytemplate Office LocatorAI17/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebbyTemplate Office Locator office-locator allows SQL Injection.This issue affects Office Locator: from n/a through <= 1.3.0.
AplazadaAlta (7.1)0.29%—Aakif Kadiwala Event Espresso - Custom Email Template ShortcodeAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Event Espresso – Custom Email Template Shortcode email-shortcode allows Reflected XSS.This issue affects Event Espresso – Custom Email Template Shortcode: from n/a through <= 1.0.0.
AplazadaMedia (6.5)0.36%—Fbtemplates Nemesis-all-in-oneAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fbtemplates Nemesis All-in-One nemesis-all-in-one allows Stored XSS.This issue affects Nemesis All-in-One: from n/a through <= 1.1.3.
AplazadaMedia (6.5)0.36%—Otwthemes Post Custom Templates LiteAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Post Custom Templates Lite post-custom-templates-lite allows Stored XSS.This issue affects Post Custom Templates Lite: from n/a through <= 1.14.
AnalizadaAlta (8.6)2.4%⚠ Explotación activaReviewdog Action-ast-grepReviewdog Action-composite-templateReviewdog Action-setupReviewdog Action-shellcheck+219/3/202517/6/2026
reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be…
AnalizadaAlta (8.8)0.36%—Irontemplates Soundrise14/3/202517/6/2026
The SoundRise Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on theironMusic_ajax() function in all versions up to, and including, 1.6.11. This makes it possible for authenticated attackers, with subscriber-level…
AplazadaMedia (4.3)0.17%—A Chappard Display Template NameAI11/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in A. Chappard Display Template Name display-template-name allows Cross Site Request Forgery.This issue affects Display Template Name: from n/a through <= 1.7.1.
ModificadaMedia (4.8)0.28%—Shanebp BP Email Assign Templates11/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Stored XSS.This issue affects BP Email Assign Templates: from n/a through <= 1.6.
ModificadaMedia (4.9)0.45%—Shanebp BP Email Assign Templates11/3/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Email Assign Templates: from n/a through <= 1.7.
AnalizadaCrítica (9.1)0.43%—Fancywp Starter Templates8/3/202517/6/2026
The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.0.0 via the 'http_request_host_is_external' filter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web…
AplazadaAlta (8.6)0.31%—Wind Media E-commerce Website TemplateAI4/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Commerce Website Template allows SQL Injection. This issue affects E-Commerce Website Template: before v1.5.
AplazadaMedia (6.4)0.26%—Templatesnext ToolkitAI1/3/202517/6/2026
The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wishlist_table' shortcode in all versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalizadaMedia (4.8)0.85%—Pebbletemplates Pebble Templates27/2/202517/6/2026
Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Name or Path via the include tag. A high privileged attacker can access sensitive local files by crafting malicious notification templates that leverage this tag to include files like /etc/passwd or…
AnalizadaMedia (5.4)0.30%—Apollo13 Rife Elementor Extensions & Templates22/2/202517/6/2026
The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
Orbitaley — Vulnerabilidades