Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
155 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.37% | — | Gvectors WpforoAI | 25/10/2025 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() function in all versions up to, and including, 2.4.8 due to missing integer validation on the 'offset' and 'row_count' parameters. The function blindly interpolates 'row_count' into a 'LIMIT… | |
| Aplazada | Media (4.3) | 0.20% | — | Gvectors WpdiscuzAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.33. | |
| Aplazada | Crítica (9.8) | 0.56% | — | NeuvectorAI | 17/9/2025 | 17/6/2026 | A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in `admin` account. If this password is not changed immediately after deployment, any workload with network access within the cluster could use the default credentials to obtain an… | |
| Aplazada | Media (5.3) | 0.25% | — | NeuvectorAI | 17/9/2025 | 17/6/2026 | When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVector security event log. | |
| Aplazada | Media (5.3) | 0.18% | — | NeuvectorAI | 17/9/2025 | 17/6/2026 | NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table attack (offline attack where hashes of known passwords are precomputed). | |
| Aplazada | Media (4.3) | 0.34% | — | Gvectors WpforoAI | 3/9/2025 | 30/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <= 2.4.6. | |
| Aplazada | Media (5.4) | 0.23% | — | Gvectors WpforoAI | 10/7/2025 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary… | |
| Aplazada | Alta (7.2) | 0.24% | — | Wpforo Advanced AttachmentsAIGvectors WpforoAI | 3/6/2025 | 17/6/2026 | The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload names in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and… | |
| Aplazada | Media (5.3) | 0.57% | — | Vector4wang Spring-boot-quickAI | 10/5/2025 | 17/6/2026 | A vulnerability was found in vector4wang spring-boot-quick up to 20250422. It has been rated as critical. This issue affects the function ResponseEntity of the file /spring-boot-quick-master/quick-img2txt/src/main/java/com/quick/controller/Img2TxtController.java of the component quick-img2txt. The manipulation leads… | |
| Aplazada | Alta (7.6) | 0.29% | — | Gvectors Wpforo ForumAI | 4/4/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Tomdever wpForo Forum wpforo allows Privilege Escalation.This issue affects wpForo Forum: from n/a through <= 2.4.2. | |
| Analizada | Media (6.5) | 0.38% | — | Gvectors Wpforo Forum | 28/2/2025 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary… | |
| Modificada | Alta (7.3) | 0.35% | — | Gvectors Wpdiscuz | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.10. | |
| Modificada | Alta (8.8) | 0.41% | — | Gvectors Wpdiscuz | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.3. | |
| Modificada | Media (5.4) | 0.30% | — | Gvectors Wpforo Forum | 9/12/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Code Injection.This issue affects wpForo Forum: from n/a through 2.2.5. | |
| Analizada | Crítica (9.8) | 0.81% | — | Gvectors Wpdiscuz | 25/10/2024 | 17/6/2026 | The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the… | |
| Aplazada | Crítica (9.4) | 0.48% | — | NeuvectorAI | 16/10/2024 | 17/6/2026 | A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE. | |
| Aplazada | Media (6.1) | 0.29% | — | Mediawiki Vector SkinAI | 9/10/2024 | 17/6/2026 | An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-intro-page MalformedTitleException is uncaught if it is not a valid title, leading to incorrect web pages. | |
| Aplazada | Media (6.5) | 0.30% | — | Mediawiki Vector SkinAI | 9/10/2024 | 17/6/2026 | An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because the line param can have markup. | |
| Analizada | Alta (7.5) | 0.45% | — | Gvectors Wpforo Forum | 26/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4. | |
| Analizada | Alta (8.1) | 0.31% | — | Gvectors Wpforo Forum | 18/8/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4. | |
| Analizada | Media (6.1) | 0.60% | — | Gvectors Wpdiscuz | 2/8/2024 | 17/6/2026 | The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it possible for unauthenticated attackers to add HTML such as hyperlinks to comments when rich editing is disabled. | |
| Modificada | Media (5.4) | 0.27% | — | Gvectors Wpforo Forum | 21/6/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Content Spoofing.This issue affects wpForo Forum: from n/a through 2.0.9. | |
| Modificada | Media (5.4) | 0.26% | — | Gvectors Wpdiscuz | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in gVectors Team wpDiscuz allows Stored XSS.This issue affects wpDiscuz: from n/a through 7.6.18. | |
| Analizada | Media (6.1) | 0.28% | — | Gvectors Wpdiscuz | 4/6/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpDiscuz allows Code Injection.This issue affects wpDiscuz: from n/a through 7.6.10. | |
| Modificada | Media (6.5) | 0.46% | — | Gvectors Wpforo Forum | 1/6/2024 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and including, 2.3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… |