Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Social Login AND RegisterAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions. | |
| Aplazada | Media (6.4) | 0.35% | — | Gutenverse Ultimate Wordpress FSE Blocks Addons EcosystemAI | 26/8/2026 | 26/8/2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.1) | 0.23% | — | Blogvault Backup AND StagingAIMalcare Wordpress Security PluginAITHE WP Remote WP RemoteAI | 26/8/2026 | 26/8/2026 | The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service,… | |
| Aplazada | Baja (1.9) | 1.1% | — | Sworddut Mcp-ffmpeg-helperAI | 24/8/2026 | 26/8/2026 | A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of the argument format results in os command injection. Attacking locally is a requirement. The exploit is now public… | |
| Aplazada | Media (6.4) | 0.33% | — | Ibericode Mailchimp FOR WordpressAI | 22/8/2026 | 24/8/2026 | The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') in all versions up to, and including, 4.12.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.9) | 1.1% | 💥 Exploit | PasswordpusherAI | 22/8/2026 | 23/9/2026 | PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil, and Ruby evaluates nil == nil as true, so the check passes and the… | |
| Aplazada | Crítica (9.8) | 0.79% | — | Mailgun FOR WordpressAI | 22/8/2026 | 25/8/2026 | The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through… | |
| Aplazada | Media (4.2) | 0.12% | — | Litextension Wordpress PluginAI | 21/8/2026 | 26/8/2026 | The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a crafted link (CSRF). | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft 365Microsoft OfficeMicrosoft Office 2021Microsoft Office 2024+1 | 20/8/2026 | 4/9/2026 | Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | |
| Pendiente de análisis | Media (6.9) | 0.14% | — | ARM HDD PasswordAI | 19/8/2026 | 31/8/2026 | On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables. | |
| Aplazada | Alta (8.8) | 0.20% | — | Devitems Hashbar Wordpress Notification BARAI | 18/8/2026 | 20/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Social Login AND RegisterAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. | |
| Pendiente de análisis | Alta (8.8) | 1.9% | 💥 PoC | WordpressAI | 17/8/2026 | 3/9/2026 | WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has… | |
| Aplazada | Baja (1.3) | 0.39% | — | Orange View Limited Dualsafe Password Manager AND Digital Vault ExtensionAI | 17/8/2026 | 20/8/2026 | A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level… | |
| Aplazada | Alta (7.1) | 0.26% | — | Snstheme Samex Clean Minimal Shop Woocommerce Wordpress ThemeAISnstheme M ANH Fashion Woocommerce Wordpress ThemeAI | 13/8/2026 | 14/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress… | |
| Pendiente de análisis | Alta (8.8) | 1.4% | — | Zohocorp Manageengine Password Manager PROAIZohocorp Pam360AI | 13/8/2026 | 31/8/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation. | |
| Pendiente de análisis | Alta (8.8) | 3.1% | — | Zohocorp Manageengine Password Manager PROAIZohocorp Manageengine Pam360AI | 13/8/2026 | 31/8/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection. | |
| Aplazada | Media (5.3) | 0.47% | — | Prevent Direct Access Protect Wordpress FilesAI | 13/8/2026 | 14/8/2026 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without… | |
| Aplazada | Alta (8.1) | 0.75% | — | Ventraconnect Social Login Passwordless LoginAI | 12/8/2026 | 12/8/2026 | The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me… | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 12/8/2026 | Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 14/8/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.43% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 14/8/2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.43% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 14/8/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.43% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 14/8/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.43% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 11/8/2026 | 14/8/2026 | Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |