Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
198 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.41% | — | Rocketelements Split Test FOR ElementorAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rocketelements Split Test For Elementor split-test-for-elementor allows Stored XSS.This issue affects Split Test For Elementor: from n/a through <= 1.8.4. | |
| Aplazada | Alta (7.1) | 0.39% | — | Muneeb Mobile Rocket-wp-mobileAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muneeb Mobile rocket-wp-mobile allows Reflected XSS.This issue affects Mobile: from n/a through <= 1.3.3. | |
| Analizada | Media (6.1) | 0.29% | — | Berocket Advanced Ajax Product Filters | 28/2/2025 | 17/6/2026 | The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 1.6.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (7.1) | 0.15% | — | Jinhan Park Rocket Media Library Mime TypeAI | 23/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in JinHan Park Rocket Media Library Mime Type rocket-media-library-mime-type allows Stored XSS.This issue affects Rocket Media Library Mime Type: from n/a through <= 2.1.0. | |
| Aplazada | Media (6.3) | 0.38% | — | Shiprocket ModuleAIOpencartAI | 20/1/2025 | 17/6/2026 | A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?route=extension/module/rest_api&action=getOrders of the component REST API Module. The manipulation of the argument contentHash leads to incorrect… | |
| Aplazada | Media (6.9) | 0.39% | — | Shiprocket ModuleAIOpencartAI | 20/1/2025 | 17/6/2026 | A vulnerability was found in Shiprocket Module 3/4 on OpenCart. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php?route=extension/shiprocket/module/restapi of the component REST API Module. The manipulation of the argument x-username leads to sql… | |
| Modificada | Media (5.4) | 0.31% | — | Wpsocialrocket Social Rocket | 7/1/2025 | 17/6/2026 | The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialrocket-floating' shortcode in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.3) | 0.39% | — | Wpsocialrocket Social Rocket | 7/1/2025 | 17/6/2026 | The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tweet_settings_save() and tweet_settings_update() functions in all versions up to, and including, 1.3.4. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.38% | — | FlickrocketAI | 7/1/2025 | 17/6/2026 | The WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'start_date’ and 'end_date' parameters in all versions up to, and including, 4.75 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.50% | — | Berocket Brands FOR WoocommerceAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brands for WooCommerce: from n/a through <= 3.8.2.2. | |
| Analizada | Media (6.1) | 0.34% | — | Rockettheme Gantry | 18/10/2024 | 17/6/2026 | The Gantry 4 Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'override_id' parameter in all versions up to, and including, 4.1.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (6.7) | 0.55% | — | Rocket.chat MobileAI | 7/10/2024 | 17/6/2026 | The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they have the appropriate time and resources. | |
| Modificada | Media (5.4) | 0.35% | — | Rocket.chat | 25/9/2024 | 17/6/2026 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps. | |
| Aplazada | Alta (7.5) | 0.41% | — | Rocket.chatAI | 25/9/2024 | 17/6/2026 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to send ephemeral messages as if they were any other user they choose. | |
| Modificada | Alta (7.5) | 0.59% | — | Rocket.chat | 25/9/2024 | 17/6/2026 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser. | |
| Modificada | Media (6.1) | 0.33% | — | Rocket.chat | 25/9/2024 | 17/6/2026 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method to forge a message that contains an XSS payload. | |
| Modificada | Media (5.4) | 0.29% | — | Rocket.chat | 2/9/2024 | 17/6/2026 | The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser upon encountering third-party external actions from PDF documents. | |
| Modificada | Alta (8.6) | 3.2% | 💥 Exploit | Rocket.chat | 5/8/2024 | 17/6/2026 | A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1. | |
| Modificada | Alta (8.8) | 0.89% | — | Apache Rocketmq | 22/7/2024 | 17/6/2026 | For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even if RocketMQ is enabled with authentication and authorization functions. An attacker, possessing regular user privileges or listed in the IP whitelist, could potentially… | |
| Modificada | Media (6.1) | 0.31% | — | Wpsocialrocket Social Rocket | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Social Rocket allows Reflected XSS.This issue affects Social Rocket: from n/a through 1.3.3. | |
| Analizada | Media (4.8) | 0.76% | 💥 Exploit | Rocketsoft Rocket LMS | 17/5/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications. | |
| Aplazada | Crítica (9.1) | 0.32% | — | Rocket.chat AuditAIFilecachetoolsAI | 18/3/2024 | 17/6/2026 | Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI. | |
| Modificada | Alta (8.8) | 0.23% | — | Rocketelements Split Test FOR Elementor | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rocket Elements Split Test For Elementor.This issue affects Split Test For Elementor: from n/a through 1.6.9. | |
| Modificada | Media (6.1) | 0.45% | — | Berocket Advanced Ajax Product Filters | 16/1/2024 | 17/6/2026 | The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting issue. | |
| Modificada | Alta (8.8) | 0.78% | — | Woorockets Corsa | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WooRockets Corsa.This issue affects Corsa: from n/a through 1.5. |