Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2095 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.37% | — | Advancedformintegration Advanced Form IntegrationAI | 1/7/2026 | 1/7/2026 | The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Themehunk Advance Product SearchAI | 26/6/2026 | 26/6/2026 | Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Algolplus Advanced Order Export FOR WoocommerceAI | 25/6/2026 | 25/6/2026 | Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. | |
| Aplazada | Media (4.3) | 0.39% | — | Advance NAV Menu ManagerAI | 24/6/2026 | 25/6/2026 | The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Aplazada | Media (5.3) | 0.40% | — | Advanced Contact Form 7 Compact DBAI | 24/6/2026 | 25/6/2026 | The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the cf7cdb_ajax_delete_user() function in versions up to, and including, 1.0.0. The handler is registered against both `wp_ajax_cf7cdb_delete` and… | |
| Aplazada | Media (6.4) | 0.34% | — | Addonspress Advanced ImportAI | 19/6/2026 | 22/6/2026 | The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the plugin using wp_remote_get() to fetch a user-supplied URL without validating that the URL does not point to internal or private network resources in the… | |
| Aplazada | Media (4.9) | 0.47% | — | Algolplus Advanced Order Export FOR WoocommerceAI | 18/6/2026 | 18/6/2026 | The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_direction' parameter in all versions up to, and including, 4.0.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Alta (7.5) | 0.39% | — | Monetizemore Advanced ADSAI | 17/6/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Advanced ADS TrackingAI | 17/6/2026 | 6/10/2026 | Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. | |
| Modificada | Alta (8.8) | 0.43% | — | Oracle Advanced Outbound Telephony | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound… | |
| Modificada | Crítica (9.1) | 0.43% | — | Oracle Advanced Outbound Telephony | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound… | |
| Modificada | Alta (8.8) | 0.43% | — | Oracle Advanced Outbound Telephony | 17/6/2026 | 17/6/2026 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Advanced 301 AND 302 RedirectAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | Advancedformintegration Advanced Form IntegrationAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Advanced Product FieldsAI | 15/6/2026 | 17/6/2026 | Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions. | |
| Modificada | Alta (7.7) | 1.0% | — | AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+8 | 11/6/2026 | 11/9/2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions… | |
| Aplazada | Media (5.4) | 0.23% | — | Berocket Advanced Ajax Product FiltersAI | 11/6/2026 | 29/9/2026 | Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced AJAX Product Filters: from n/a through 1.6.3.3. | |
| Analizada | Media (4) | 0.17% | — | Vmware Spring Advanced Message Queuing Protocol | 10/6/2026 | 23/7/2026 | Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15;… | |
| Analizada | Media (4.4) | 0.22% | — | Vmware Spring Advanced Message Queuing Protocol | 9/6/2026 | 1/10/2026 | Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17. | |
| Pendiente de análisis | Alta (8.6) | 0.30% | — | Amazon Aurora PostgresqlAIAmazon Advanced GO WrapperAI | 5/6/2026 | 17/6/2026 | An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when… | |
| Pendiente de análisis | Alta (8.6) | 0.40% | — | Amazon Advanced Jdbc WrapperAI | 5/6/2026 | 17/6/2026 | An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when… | |
| Aplazada | Alta (7.5) | 0.48% | — | Vasyltech Advanced Access ManagerAI | 1/6/2026 | 22/7/2026 | Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue affects Advanced Access Manager: from n/a through 7.1.0. | |
| Aplazada | Media (5.3) | 0.52% | — | Advancedcustomfields Advanced Custom FieldsAI | 31/5/2026 | 22/7/2026 | The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and… | |
| Aplazada | Crítica (9.8) | 0.87% | 💥 PoC | Acfextended Advanced Custom Fields ExtendedAI | 28/5/2026 | 21/7/2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with… | |
| Aplazada | Media (6.5) | 0.22% | — | Advancedcustomfields Font Awesome FieldAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced Custom Fields: Font Awesome Field allows Stored XSS. This issue affects Advanced Custom Fields: Font Awesome Field: from n/a through 5.0.2. |