Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2775▼ 14 respecto a la semana anterior
Críticas / altas1283▼ 250 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 205 respecto a la semana anterior
14.294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.41% | — | AI Chatbot FOR WoocommerceAI | 2/8/2026 | 26/8/2026 | The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to… | |
| Aplazada | Media (6.1) | 0.36% | — | WP Responsive Thumbnail SliderAI | 1/8/2026 | 12/8/2026 | The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management() function, which echoes $_GET['id']… | |
| Aplazada | Media (6.6) | 1.2% | — | Ayecode GetpaidAI | 1/8/2026 | 12/8/2026 | The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with administrator-level access and above, to… | |
| Aplazada | Media (4.9) | 0.44% | — | Icegram MailerAI | 1/8/2026 | 12/8/2026 | The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and including, 1.0.12. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the Icegram_Mailer_Logs_Table::get_logs()… | |
| Aplazada | Alta (7.2) | 0.42% | — | Pluginops Mailchimp Subscribe FormAI | 1/8/2026 | 12/8/2026 | The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (8.8) | 0.30% | — | AI EngineAI | 1/8/2026 | 12/8/2026 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.4) | 0.36% | — | Brainstormforce SureformsAI | 1/8/2026 | 12/8/2026 | The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.35% | — | Sendpulse Email Marketing NewsletterAI | 1/8/2026 | 12/8/2026 | The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Crítica (9.6) | 0.45% | — | Banzaicloud Vault Secrets WebhookAI | 31/7/2026 | 10/9/2026 | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and… | |
| Aplazada | Media (5.3) | 0.39% | — | MailerpressAI | 31/7/2026 | 12/8/2026 | The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details. | |
| Aplazada | Media (5.3) | 0.39% | — | MailpressAI | 31/7/2026 | 12/8/2026 | The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). The route in the vulnerable range was registered without a permissionCallback,… | |
| Aplazada | Baja (3.7) | 0.28% | — | Cozmoslabs Paid Membership SubscriptionsAI | 31/7/2026 | 26/8/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the uploads directory, allowing unauthenticated users to download the exported member and payment data (including PII) while an export artifact is present. | |
| Aplazada | Media (4.3) | 0.27% | — | Cozmoslabs Paid Membership SubscriptionsAI | 31/7/2026 | 26/8/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated user with Subscriber-level access and above to disclose the payment details of any member by enumerating the payment identifier. | |
| Aplazada | Media (6.5) | 0.27% | — | Mailgun FOR WordpressAI | 31/7/2026 | 26/8/2026 | The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's… | |
| Aplazada | Media (6.5) | 0.40% | — | Check LOG EmailAI | 31/7/2026 | 26/8/2026 | The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with administrator privileges to perform SQL injection attacks. | |
| Pendiente de análisis | Crítica (9.5) | 28% | 💥 Exploit | Rails Action PackAILibvipsAIRubyonrails Active StorageAI | 30/7/2026 | 10/9/2026 | Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured… | |
| Aplazada | Media (6.9) | 0.52% | — | AiohttpAI | 30/7/2026 | 30/7/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This… | |
| Analizada | Media (5.3) | 0.40% | — | IBM Verify Identity AccessIBM Verify Identity Access Container | 30/7/2026 | 12/8/2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error… | |
| Aplazada | Crítica (9.8) | 0.32% | — | Sourcecodester Tailor Management SystemAI | 30/7/2026 | 1/10/2026 | SourceCodester Tailor Management System 1.0 es vulnerable a inyección SQL en customeredit.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Sourcecodester Tailor Management SystemAI | 30/7/2026 | 1/10/2026 | Sistema de Gestión de Sastres SourceCodester 1.0 es vulnerable a inyección SQL en addmeasurement.PHP?id=1. | |
| Pendiente de análisis | Alta (8.8) | 0.80% | — | Samba Active Directory Domain ControllerAI | 30/7/2026 | 30/7/2026 | A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Umai Vision Traffic Analysis SystemAI | 30/7/2026 | 30/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. This issue affects Traffic Analysis System: from 30 before 34. | |
| Aplazada | Media (6.5) | 0.37% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI | 30/7/2026 | 30/7/2026 | The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request. | |
| Analizada | Crítica (9.8) | 0.86% | — | Adobe Campaign | 30/7/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Alta (8.6) | 0.56% | — | Adobe Campaign | 30/7/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require… |