Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 0.40% | — | Grafana Oncall | 5/6/2024 | 17/6/2026 | Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces that are tailored specifically for engineers. Grafana OnCall, from version 1.1.37 before 1.5.2 are vulnerable to a Server Side Request Forgery (SSRF) vulnerability in the… | |
| Analizada | Baja (3.5) | 0.33% | — | Buttonizer Call / Chat / Contact Button | 23/5/2024 | 17/6/2026 | The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Alta (7.5) | 0.42% | — | Transsion VideocallenhancerAI | 21/5/2024 | 17/6/2026 | The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to the risk of private file leakage. | |
| Aplazada | Baja (2.8) | 0.14% | — | Motorola Phone CallsAI | 3/5/2024 | 17/6/2026 | An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and calling data. | |
| Aplazada | Baja (2.8) | 0.14% | — | Motorola Phone CallsAI | 3/5/2024 | 17/6/2026 | An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information. | |
| Analizada | Media (4.3) | 0.67% | — | Callnowbutton Call NOW Button | 26/4/2024 | 17/6/2026 | The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (8.5) | 0.60% | — | Plechevandrey Wp-recallAI | 24/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5. | |
| Aplazada | Crítica (9.3) | 5.8% | 💥 Exploit | Plechevandrey Wp-recallAI | 24/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5. | |
| Aplazada | Media (4.3) | 0.36% | — | Plechevandrey Wp-recallAI | 18/4/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5. | |
| Modificada | Alta (8.8) | 0.20% | — | Extendthemes Calliope | 26/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Calliope.This issue affects Calliope: from n/a through 1.0.33. | |
| Modificada | Alta (7.5) | 0.66% | 💥 PoC | Xenomtechnologies Phone Dialer-voice Call Dialer | 27/12/2023 | 17/6/2026 | An issue in Xenom Technologies (sinous) Phone Dialer-voice Call Dialer v.1.2.5 allows an attacker to bypass intended access restrictions via interaction with com.funprime.calldialer.ui.activities.OutgoingActivity. | |
| Modificada | Media (4.8) | 0.39% | — | Codez Quick Call Button | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codez Quick Call Button plugin <= 1.2.9 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Dangngocbinh Easy Call NOW BY Thikshare | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dang Ngoc Binh Easy Call Now by ThikShare plugin <= 1.1.0 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Lokalyze Call ME NOW | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LOKALYZE CALL ME NOW plugin <= 3.0 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Callrail Phone Call Tracking | 27/10/2023 | 17/6/2026 | The CallRail Phone Call Tracking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callrail_form' shortcode in versions up to, and including, 0.5.2 due to insufficient input sanitization and output escaping on the 'form_id' user supplied attribute. This makes it possible for authenticated… | |
| Modificada | Media (4.8) | 0.44% | — | Davidsword Mobile Call NOW & MAP Buttons | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Davidsword Mobile Call Now & Map Buttons plugin <= 1.5.0 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Alantien Call NOW Icon Animate | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alan Tien Call Now Icon Animate plugin <= 0.1.0 versions. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Callback Widget | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | Phpjabbers Callback Widget | 28/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0. | |
| Modificada | Media (4.8) | 0.37% | — | Pradeepsinghweb Dynamically Register Sidebars | 17/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= 1.0.1 versions. | |
| Modificada | Media (6.1) | 0.44% | — | Phpjabbers Callback Widget | 10/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Callback Widget v1.0. | |
| Modificada | Media (6.1) | 0.44% | — | Phpjabbers Callback Widget | 10/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the value-text-o_sms_email_request_message parameters of index.php in PHPJabbers Callback Widget v1.0. | |
| Modificada | Media (5.4) | 0.42% | — | Phpjabbers Callback Widget | 10/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the value-enum-o_bf_include_timezone parameter of index.php in PHPJabbers Callback Widget v1.0. | |
| Modificada | Crítica (9.8) | 1.1% | — | Renjikai Linuxasmcallgraph | 4/8/2023 | 17/6/2026 | LinuxASMCallGraph is software for drawing the call graph of the programming code. Linux ASMCallGraph before commit 20dba06bd1a3cf260612d4f21547c25002121cd5 allows attackers to cause a remote code execution on the server side via uploading a crafted ZIP file due to incorrect filtering rules of uploaded file. The… | |
| Modificada | Media (6.8) | 0.57% | — | Avaya Call Management System | 18/7/2023 | 17/6/2026 | A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used to open the file by a spreadsheet software… |