Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.31% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 22/11/2022 | 17/6/2026 | Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress. | |
| Modificada | Media (6.1) | 0.73% | — | Tipsandtricks-hq WP Video Lightbox | 25/7/2022 | 17/6/2026 | The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | |
| Modificada | Media (4.8) | 0.59% | — | Tipsandtricks-hq Accept Stripe | 17/7/2022 | 17/6/2026 | The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (4.3) | 0.43% | — | Tipsandtricks-hq WP Simple Adsense Insertion | 8/6/2022 | 17/6/2026 | The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via submitting a form. | |
| Modificada | Media (4.7) | 0.75% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 2/5/2022 | 17/6/2026 | The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as… | |
| Modificada | Media (6.5) | 1.4% | — | Tipsandtricks-hq Simple Download Monitor | 14/3/2022 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector. | |
| Modificada | Alta (8.8) | 0.63% | — | Tipsandtricks-hq Simple Download Monitor | 24/1/2022 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads | |
| Modificada | Media (5.4) | 0.61% | — | Tipsandtricks-hq Simple Download Monitor | 24/1/2022 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode. | |
| Modificada | Media (4.3) | 0.68% | — | Tipsandtricks-hq Simple Download Monitor | 8/11/2021 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download. | |
| Modificada | Media (6.1) | 0.83% | — | Tipsandtricks-hq Simple Download Monitor | 8/11/2021 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Alta (7.5) | 1.7% | — | Tipsandtricks-hq Simple Download Monitor | 8/11/2021 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames | |
| Modificada | Crítica (9) | 1.3% | — | Tipsandtricks-hq Simple Download Monitor | 8/11/2021 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review… | |
| Modificada | Media (4.3) | 0.47% | — | Tipsandtricks-hq FAR Future Expiry Header | 1/11/2021 | 17/6/2026 | The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | |
| Modificada | Media (6.5) | 0.57% | — | Tipsandtricks-hq Compact WP Audio Player | 18/10/2021 | 17/6/2026 | The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack. | |
| Modificada | Media (5.4) | 0.65% | — | Tipsandtricks-hq Compact WP Audio Player | 18/10/2021 | 17/6/2026 | The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.8) | 0.69% | — | Tipsandtricks-hq Software License Manager | 11/10/2021 | 17/6/2026 | The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack | |
| Modificada | Media (6.1) | 0.73% | — | Tipsandtricks-hq Software License Manager | 13/9/2021 | 17/6/2026 | The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (5.4) | 0.62% | — | Tipsandtricks-hq WP Video Lightbox | 30/8/2021 | 17/6/2026 | The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.87% | — | Tipsandtricks-hq Software License Manager | 14/7/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (6.1) | 1.5% | — | Tipsandtricks-hq WP Security & Firewall | 10/2/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress. | |
| Modificada | Alta (8.8) | 1.5% | — | Tipsandtricks-hq Simple Download Monitor | 21/10/2020 | 17/6/2026 | SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL. | |
| Modificada | Media (6.1) | 0.94% | — | Tipsandtricks-hq Simple Download Monitor | 21/10/2020 | 17/6/2026 | Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.85% | — | Tipsandtricks-hq Category Specific RSS Feed Subscription | 12/9/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.9% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 14/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues. | |
| Modificada | Crítica (9.8) | 1.9% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 14/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues. |