Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
393 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.44% | — | Dot-propertiesAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the function lib.parse of dot-properties v1.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Aplazada | Alta (7.5) | 0.44% | — | Dot-qsAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the lib.parse function of dot-qs v0.2.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Aplazada | Baja (1) | 0.18% | — | Google ZXAIDotenvAI | 3/2/2025 | 17/6/2026 | zx is a tool for writing better scripts. An attacker with control over environment variable values can inject unintended environment variables into `process.env`. This can lead to arbitrary command execution or unexpected behavior in applications that rely on environment variables for security-sensitive operations.… | |
| Aplazada | Media (4.3) | 0.34% | — | Dotstore Hide Shipping Method FOR WoocommerceAI | 3/2/2025 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Hide Shipping Method For WooCommerce hide-shipping-method-for-woocommerce.This issue affects Hide Shipping Method For WooCommerce: from n/a through <= 1.5.1. | |
| Analizada | Alta (7.8) | 0.14% | — | Jetbrains DottraceJetbrains ETW Host ServiceJetbrains ResharperJetbrains Rider | 28/1/2025 | 17/6/2026 | In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible | |
| Aplazada | Media (4.3) | 0.24% | — | Dotstore Product Size Charts Plugin FOR WoocommerceAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Product Size Charts Plugin for WooCommerce woo-advanced-product-size-chart.This issue affects Product Size Charts Plugin for WooCommerce: from n/a through <= 2.4.5. | |
| Aplazada | Media (4.3) | 0.33% | — | Surdotly Sur.lyAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in surdotly Sur.ly surly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sur.ly: from n/a through <= 3.0.3. | |
| Aplazada | Media (6.5) | 0.21% | — | Piotnetdotcom Piotnet Addons FOR ElementorAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Addons For Elementor piotnet-addons-for-elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through <= 2.4.31. | |
| Analizada | Media (4.7) | 0.46% | — | Dotnetfoundation Piranha CMS | 20/12/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by creating a page via the /manager/pages and then adding a markdown content with the XSS payload. | |
| Analizada | Media (4.7) | 0.51% | — | Dotnetfoundation Piranha CMS | 20/12/2024 | 17/6/2026 | A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media. This PDF can contain malicious JavaScript code, which is executed when a victim user opens or interacts with the PDF in their web browser, leading to a XSS vulnerability. | |
| Aplazada | Alta (7.1) | 0.46% | — | Dotstore Advance Menu ManagerAI | 18/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Advance Menu Manager advance-menu-manager.This issue affects Advance Menu Manager: from n/a through <= 3.1.1. | |
| Aplazada | Media (6.3) | 0.46% | — | Dotonpaper Pinpoint Booking SystemAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.5.7. | |
| Analizada | Media (5.4) | 0.29% | — | Dotcamp Ultimate Blocks | 13/12/2024 | 17/6/2026 | The Ultimate Blocks WordPress plugin before 3.2.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (4.3) | 0.39% | — | Dotstore Minimum AND Maximum Quantity FOR WoocommerceAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Minimum and Maximum Quantity for WooCommerce min-and-max-quantity-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Minimum and Maximum Quantity for WooCommerce: from n/a through <= 2.0.0. | |
| Aplazada | Alta (8.5) | 0.52% | — | Dotonpaper Pinpoint Booking SystemAI | 6/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Blind SQL Injection.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.5.1. | |
| Aplazada | Crítica (10) | 0.51% | — | Dotthattask DO That TaskAI | 14/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in DoThatTask Do That Task do-that-task allows Upload a Web Shell to a Web Server.This issue affects Do That Task: from n/a through <= 1.5.5. | |
| Analizada | Crítica (9.8) | 2.0% | 💥 PoC | Mihula ProdotnetzipDotnetzip.semverd Project Dotnetzip.semverd | 13/11/2024 | 17/6/2026 | Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Modificada | Media (6.1) | 0.29% | — | Dotsquares Google MAP Locations | 20/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DotsquaresLtd Google Map Locations google-map-locations allows Reflected XSS.This issue affects Google Map Locations: from n/a through <= 1.0. | |
| Aplazada | Media (5.4) | 0.18% | — | Dotonpaper Pinpoint Booking SystemAI | 17/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Stored XSS.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.5.7. | |
| Analizada | Media (5.4) | 0.38% | — | Dotcamp Ultimate Blocks | 30/9/2024 | 17/6/2026 | The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.70% | 💥 Exploit | Dotsquares Contact Form 7 Math Captcha | 26/9/2024 | 17/6/2026 | The Contact Form 7 Math Captcha WordPress plugin through 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users. | |
| Analizada | Media (6.5) | 0.29% | — | Dotcamp WP Table Builder | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Table Builder WP Table Builder – WordPress Table Plugin allows Stored XSS.This issue affects WP Table Builder – WordPress Table Plugin: from n/a through 1.4.15. | |
| Analizada | Media (4.6) | 0.32% | — | Dotcamp Ultimate Blocks | 29/7/2024 | 17/6/2026 | The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (7.5) | 0.69% | — | Txtdot | 26/7/2024 | 17/6/2026 | txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting in version 1.4.0 and prior to version 1.6.1, a Server-Side Request Forgery (SSRF) vulnerability in the `/proxy` route of txtdot allows remote attackers to use the server as a proxy to send HTTP GET… | |
| Modificada | Alta (7.5) | 0.69% | — | Txtdot | 26/7/2024 | 17/6/2026 | txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Prior to version 1.7.0, a Server-Side Request Forgery (SSRF) vulnerability in the `/get` route of txtdot allows remote attackers to use the server as a proxy to send HTTP GET requests to arbitrary targets and… |