Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

299 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)0.40%—Grafana Oncall5/6/202417/6/2026
Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces that are tailored specifically for engineers. Grafana OnCall, from version 1.1.37 before 1.5.2 are vulnerable to a Server Side Request Forgery (SSRF) vulnerability in the…
AnalizadaBaja (3.5)0.33%—Buttonizer Call / Chat / Contact Button23/5/202417/6/2026
The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AplazadaAlta (7.5)0.42%—Transsion VideocallenhancerAI21/5/202417/6/2026
The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to the risk of private file leakage.
AplazadaBaja (2.8)0.14%—Motorola Phone CallsAI3/5/202417/6/2026
An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and calling data.
AplazadaBaja (2.8)0.14%—Motorola Phone CallsAI3/5/202417/6/2026
An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information.
AnalizadaMedia (4.3)0.67%—Callnowbutton Call NOW Button26/4/202417/6/2026
The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaAlta (8.5)0.60%—Plechevandrey Wp-recallAI24/4/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.
AplazadaCrítica (9.3)5.8%💥 ExploitPlechevandrey Wp-recallAI24/4/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.
AplazadaMedia (4.3)0.36%—Plechevandrey Wp-recallAI18/4/202417/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.
ModificadaAlta (8.8)0.20%—Extendthemes Calliope26/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Calliope.This issue affects Calliope: from n/a through 1.0.33.
ModificadaAlta (7.5)0.66%💥 PoCXenomtechnologies Phone Dialer-voice Call Dialer27/12/202317/6/2026
An issue in Xenom Technologies (sinous) Phone Dialer-voice Call Dialer v.1.2.5 allows an attacker to bypass intended access restrictions via interaction with com.funprime.calldialer.ui.activities.OutgoingActivity.
ModificadaMedia (4.8)0.39%—Codez Quick Call Button22/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codez Quick Call Button plugin <= 1.2.9 versions.
ModificadaAlta (8.8)0.26%—Dangngocbinh Easy Call NOW BY Thikshare22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dang Ngoc Binh Easy Call Now by ThikShare plugin <= 1.1.0 versions.
ModificadaAlta (8.8)0.31%—Lokalyze Call ME NOW9/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in LOKALYZE CALL ME NOW plugin <= 3.0 versions.
ModificadaMedia (5.4)0.44%—Callrail Phone Call Tracking27/10/202317/6/2026
The CallRail Phone Call Tracking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callrail_form' shortcode in versions up to, and including, 0.5.2 due to insufficient input sanitization and output escaping on the 'form_id' user supplied attribute. This makes it possible for authenticated…
ModificadaMedia (4.8)0.44%—Davidsword Mobile Call NOW & MAP Buttons30/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Davidsword Mobile Call Now & Map Buttons plugin <= 1.5.0 versions.
ModificadaMedia (4.8)0.37%—Alantien Call NOW Icon Animate30/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alan Tien Call Now Icon Animate plugin <= 0.1.0 versions.
ModificadaCrítica (9.8)0.89%—Phpjabbers Callback Widget28/8/202317/6/2026
User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaMedia (6.1)1.3%💥 ExploitPhpjabbers Callback Widget28/8/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.
ModificadaMedia (4.8)0.37%—Pradeepsinghweb Dynamically Register Sidebars17/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= 1.0.1 versions.
ModificadaMedia (6.1)0.44%—Phpjabbers Callback Widget10/8/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Callback Widget v1.0.
ModificadaMedia (6.1)0.44%—Phpjabbers Callback Widget10/8/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the value-text-o_sms_email_request_message parameters of index.php in PHPJabbers Callback Widget v1.0.
ModificadaMedia (5.4)0.42%—Phpjabbers Callback Widget10/8/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the value-enum-o_bf_include_timezone parameter of index.php in PHPJabbers Callback Widget v1.0.
ModificadaCrítica (9.8)1.1%—Renjikai Linuxasmcallgraph4/8/202317/6/2026
LinuxASMCallGraph is software for drawing the call graph of the programming code. Linux ASMCallGraph before commit 20dba06bd1a3cf260612d4f21547c25002121cd5 allows attackers to cause a remote code execution on the server side via uploading a crafted ZIP file due to incorrect filtering rules of uploaded file. The…
ModificadaMedia (6.8)0.57%—Avaya Call Management System18/7/202317/6/2026
A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used to open the file by a spreadsheet software…
Orbitaley — Vulnerabilidades