Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1971 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Wordpress Social Login AND RegisterAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
AplazadaMedia (6.4)0.35%—Gutenverse Ultimate Wordpress FSE Blocks Addons EcosystemAI26/8/202626/8/2026
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.1)0.23%—Blogvault Backup AND StagingAIMalcare Wordpress Security PluginAITHE WP Remote WP RemoteAI26/8/202626/8/2026
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service,…
AplazadaBaja (1.9)1.1%—Sworddut Mcp-ffmpeg-helperAI24/8/202626/8/2026
A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of the argument format results in os command injection. Attacking locally is a requirement. The exploit is now public…
AplazadaMedia (6.4)0.33%—Ibericode Mailchimp FOR WordpressAI22/8/202624/8/2026
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') in all versions up to, and including, 4.12.0 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.9)1.1%💥 ExploitPasswordpusherAI22/8/202623/9/2026
PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil, and Ruby evaluates nil == nil as true, so the check passes and the…
AplazadaCrítica (9.8)0.79%—Mailgun FOR WordpressAI22/8/202625/8/2026
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through…
AplazadaMedia (4.2)0.12%—Litextension Wordpress PluginAI21/8/202626/8/2026
The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a crafted link (CSRF).
AnalizadaAlta (7.5)0.97%—Microsoft 365Microsoft OfficeMicrosoft Office 2021Microsoft Office 2024+120/8/20264/9/2026
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Pendiente de análisisMedia (6.9)0.14%—ARM HDD PasswordAI19/8/202631/8/2026
On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.
AplazadaAlta (8.8)0.20%—Devitems Hashbar Wordpress Notification BARAI18/8/202620/8/2026
Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.
AplazadaAlta (7.1)0.25%—Wordpress Social Login AND RegisterAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
Pendiente de análisisAlta (8.8)1.9%💥 PoCWordpressAI17/8/20263/9/2026
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has…
AplazadaBaja (1.3)0.39%—Orange View Limited Dualsafe Password Manager AND Digital Vault ExtensionAI17/8/202620/8/2026
A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level…
AplazadaAlta (7.1)0.26%—Snstheme Samex Clean Minimal Shop Woocommerce Wordpress ThemeAISnstheme M ANH Fashion Woocommerce Wordpress ThemeAI13/8/202614/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress…
Pendiente de análisisAlta (8.8)1.4%—Zohocorp Manageengine Password Manager PROAIZohocorp Pam360AI13/8/202631/8/2026
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Pendiente de análisisAlta (8.8)3.1%—Zohocorp Manageengine Password Manager PROAIZohocorp Manageengine Pam360AI13/8/202631/8/2026
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.
AplazadaMedia (5.3)0.47%—Prevent Direct Access Protect Wordpress FilesAI13/8/202614/8/2026
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without…
AplazadaAlta (8.1)0.75%—Ventraconnect Social Login Passwordless LoginAI12/8/202612/8/2026
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me…
AnalizadaMedia (5.5)0.54%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+211/8/202612/8/2026
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+211/8/202614/8/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.43%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+211/8/202614/8/2026
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.5)0.43%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+211/8/202614/8/2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.5)0.43%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+211/8/202614/8/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.5)0.43%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+111/8/202614/8/2026
Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Orbitaley — Vulnerabilidades