Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 31% | 💥 Exploit | Awesomemotive Duplicator | 26/12/2023 | 17/6/2026 | The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the… | |
| Modificada | Alta (8.8) | 0.26% | — | Getbutterfly Block FOR Font Awesome | 17/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu Block for Font Awesome.This issue affects Block for Font Awesome: from n/a through 1.4.0. | |
| Modificada | Alta (8.8) | 0.25% | — | Getawesomesupport Awesome Support | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4. | |
| Modificada | Alta (8.1) | 0.66% | — | Getawesomesupport Awesome Support | 6/11/2023 | 17/6/2026 | The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server. | |
| Modificada | Media (6.1) | 0.40% | — | Getawesomesupport Awesome Support | 6/11/2023 | 17/6/2026 | The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (4.3) | 0.40% | — | Getawesomesupport Awesome Support | 6/11/2023 | 17/6/2026 | The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission. | |
| Modificada | Media (6.1) | 0.33% | — | Arrowplugins THE Awesome Feed | 26/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins The Awesome Feed – Custom Feed plugin <= 2.2.5 versions. | |
| Modificada | Media (5.4) | 0.65% | — | WP Font Awesome Project WP Font Awesome | 25/10/2023 | 17/6/2026 | The WP Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping on 'icon' user supplied attribute. This makes it possible for authenticated attackers with contributor-level and above… | |
| Modificada | Alta (8.8) | 0.27% | — | Awesometogi Product Category Tree | 25/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AWESOME TOGI Product Category Tree plugin <= 2.5 versions. | |
| Modificada | Media (6.1) | 0.33% | — | Awesometogi Product-category-tree | 18/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AWESOME TOGI Product Category Tree plugin <= 2.5 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Profosbox AGP Font Awesome Collection | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alexey Golubnichenko AGP Font Awesome Collection plugin <= 3.2.4 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Arrowplugins THE Awesome Feed | 2/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Arrow Plugins The Awesome Feed – Custom Feed plugin <= 2.2.5 versions. | |
| Modificada | Media (5.4) | 0.41% | — | Fontawesome Font Awesome Integration | 28/9/2023 | 17/6/2026 | The Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fawesome' shortcode in versions up to, and including, 5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Modificada | Media (5.4) | 0.41% | — | Webguysaz Font Awesome More Icons | 28/9/2023 | 17/6/2026 | The Font Awesome More Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' shortcode in versions up to, and including, 3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Modificada | Media (5.4) | 0.49% | — | Awesome Weather Widget Project Awesome Weather Widget | 14/9/2023 | 17/6/2026 | The Awesome Weather Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'awesome-weather' shortcode in versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (5.4) | 0.51% | — | Newnine Font Awesome 4 Menus | 2/9/2023 | 17/6/2026 | The Font Awesome 4 Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fa' and 'fa-stack' shortcodes in versions up to, and including, 4.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (6.1) | 0.38% | — | Profosbox AGP Font Awesome Collection | 10/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Alexey Golubnichenko AGP Font Awesome Collection plugin <= 3.2.4 versions. | |
| Modificada | Media (6.1) | 0.65% | — | Awesomemotive WP Mail Logging | 12/7/2023 | 17/6/2026 | The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.1) | 0.38% | — | Awesomemotive Duplicator | 28/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions. | |
| Modificada | Crítica (9.8) | 3.1% | 💥 Exploit | Awesomemotive Easy Digital Downloads | 2/5/2023 | 17/6/2026 | Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1. | |
| Modificada | Media (6.5) | 0.75% | — | Awesome Libmemcached | 7/3/2023 | 17/6/2026 | libmemcached-awesome is an open source C/C++ client library and tools for the memcached server. `libmemcached` could return data for a previously requested key, if that previous request timed out due to a low `POLL_TIMEOUT`. This issue has been addressed in version 1.1.4. Users are advised to upgrade. There are… | |
| Modificada | Media (5.4) | 0.53% | — | Smg-webdesign Shortcode FOR Font Awesome | 21/2/2023 | 17/6/2026 | The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.47% | — | WP Font Awesome Project WP Font Awesome | 21/2/2023 | 17/6/2026 | The WP Font Awesome WordPress plugin before 1.7.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.1) | 0.89% | — | Neo4j Awesome Procedures ON Cyper | 16/2/2023 | 17/6/2026 | APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml procedure of APOC core plugin prior to version 5.5.0 and 4.4.0.14 (4.4 branch) in Neo4j graph database. XML External Entity (XXE) injection occurs when the XML parser allows… | |
| Modificada | Media (5.4) | 0.76% | — | Better Font Awesome Project Better Font Awesome | 13/2/2023 | 17/6/2026 | The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. |