Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

2095 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.37%—Advancedformintegration Advanced Form IntegrationAI1/7/20261/7/2026
The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public…
AplazadaCrítica (9.3)0.40%—Themehunk Advance Product SearchAI26/6/202626/6/2026
Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.
AplazadaAlta (7.1)0.25%—Algolplus Advanced Order Export FOR WoocommerceAI25/6/202625/6/2026
Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.
AplazadaMedia (4.3)0.39%—Advance NAV Menu ManagerAI24/6/202625/6/2026
The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above,…
AplazadaMedia (5.3)0.40%—Advanced Contact Form 7 Compact DBAI24/6/202625/6/2026
The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the cf7cdb_ajax_delete_user() function in versions up to, and including, 1.0.0. The handler is registered against both `wp_ajax_cf7cdb_delete` and…
AplazadaMedia (6.4)0.34%—Addonspress Advanced ImportAI19/6/202622/6/2026
The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the plugin using wp_remote_get() to fetch a user-supplied URL without validating that the URL does not point to internal or private network resources in the…
AplazadaMedia (4.9)0.47%—Algolplus Advanced Order Export FOR WoocommerceAI18/6/202618/6/2026
The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_direction' parameter in all versions up to, and including, 4.0.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaAlta (7.5)0.39%—Monetizemore Advanced ADSAI17/6/202617/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21.
AplazadaCrítica (9.3)0.40%—Advanced ADS TrackingAI17/6/20266/10/2026
Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
ModificadaAlta (8.8)0.43%—Oracle Advanced Outbound Telephony17/6/202617/6/2026
Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound…
ModificadaCrítica (9.1)0.43%—Oracle Advanced Outbound Telephony17/6/202617/6/2026
Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound…
ModificadaAlta (8.8)0.43%—Oracle Advanced Outbound Telephony17/6/202617/6/2026
Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound…
AplazadaCrítica (9.3)0.40%—Advanced 301 AND 302 RedirectAI15/6/202617/6/2026
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
AplazadaMedia (6.5)0.30%—Advancedformintegration Advanced Form IntegrationAI15/6/202617/6/2026
Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.
AplazadaAlta (7.2)0.54%—Advanced Product FieldsAI15/6/202617/6/2026
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
ModificadaAlta (7.7)1.0%—AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+811/6/202611/9/2026
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions…
AplazadaMedia (5.4)0.23%—Berocket Advanced Ajax Product FiltersAI11/6/202629/9/2026
Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced AJAX Product Filters: from n/a through 1.6.3.3.
AnalizadaMedia (4)0.17%—Vmware Spring Advanced Message Queuing Protocol10/6/202623/7/2026
Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15;…
AnalizadaMedia (4.4)0.22%—Vmware Spring Advanced Message Queuing Protocol9/6/20261/10/2026
Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.
Pendiente de análisisAlta (8.6)0.30%—Amazon Aurora PostgresqlAIAmazon Advanced GO WrapperAI5/6/202617/6/2026
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when…
Pendiente de análisisAlta (8.6)0.40%—Amazon Advanced Jdbc WrapperAI5/6/202617/6/2026
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when…
AplazadaAlta (7.5)0.48%—Vasyltech Advanced Access ManagerAI1/6/202622/7/2026
Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue affects Advanced Access Manager: from n/a through 7.1.0.
AplazadaMedia (5.3)0.52%—Advancedcustomfields Advanced Custom FieldsAI31/5/202622/7/2026
The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and…
AplazadaCrítica (9.8)0.87%💥 PoCAcfextended Advanced Custom Fields ExtendedAI28/5/202621/7/2026
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with…
AplazadaMedia (6.5)0.22%—Advancedcustomfields Font Awesome FieldAI27/5/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced Custom Fields: Font Awesome Field allows Stored XSS. This issue affects Advanced Custom Fields: Font Awesome Field: from n/a through 5.0.2.