Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
370 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.23% | — | Codexpert CodesignerAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codexpert, Inc CoDesigner woolementor allows Stored XSS.This issue affects CoDesigner: from n/a through <= 4.29. | |
| Modificada | Alta (8.8) | 0.39% | — | Wpexperts Post Smtp | 13/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= 2.9.11. | |
| Analizada | Media (5.4) | 0.31% | — | Wpexperts WP Multi Store Locator | 4/1/2025 | 17/6/2026 | The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web… | |
| Aplazada | Media (5.4) | 0.33% | — | Wpexperts NEW User ApproveAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through <= 2.6.2. | |
| Aplazada | Crítica (9.8) | 0.75% | — | Codexpert INC Coschool LMSAI | 13/12/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Codexpert, Inc CoSchool LMS coschool allows Authentication Bypass.This issue affects CoSchool LMS: from n/a through <= 1.4.3. | |
| Aplazada | Media (5.3) | 0.53% | — | Wpexpertsio Apiexperts Square FOR WoocommerceAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Wpexpertsio APIExperts Square for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects APIExperts Square for WooCommerce: from n/a through 4.4.1. | |
| Aplazada | Media (5.3) | 0.45% | — | Wpexpertdeveloper WP Private Content PlusAI | 6/12/2024 | 17/6/2026 | The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.1 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles… | |
| Aplazada | Alta (7.5) | 0.64% | — | Fastapiexpert Python-multipartAI | 2/12/2024 | 17/6/2026 | python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks (CR \r or LF \n) in front of the first boundary and any tailing bytes after the last boundary. This happens one byte at a time and emits a log event each time, which may cause excessive logging for… | |
| Aplazada | Media (6.5) | 0.24% | — | Sohelwpexpert WP Responsive VideoAI | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sohelwpexpert WP Responsive Video my-wp-responsive-video allows DOM-Based XSS.This issue affects WP Responsive Video: from n/a through <= 1.0. | |
| Modificada | Alta (7.2) | 0.46% | — | Wpexperts Post Smtp | 18/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal Post SMTP post-smtp allows Blind SQL Injection.This issue affects Post SMTP: from n/a through <= 2.9.9. | |
| Aplazada | Media (6.5) | 0.25% | — | Wp-experts.in WP Easy RecipeAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-EXPERTS.IN WP EASY RECIPE wp-easy-recipe allows Stored XSS.This issue affects WP EASY RECIPE: from n/a through <= 1.6. | |
| Aplazada | Alta (7.2) | 0.58% | — | Changingtec IdexpertAI | 1/11/2024 | 17/6/2026 | IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and execute OS commands on the server. | |
| Aplazada | Media (6.1) | 0.31% | — | Changingtec IdexpertAI | 1/11/2024 | 17/6/2026 | IDExpert from CHANGING Information Technology does not properly validate a parameter for a specific functionality, allowing unauthenticated remote attackers to inject JavsScript code and perform Reflected Cross-site scripting attacks. | |
| Analizada | Alta (7.3) | 0.56% | — | Aftabhusain Enable Shortcodes Inside Widgets,comments AND Experts | 30/10/2024 | 17/6/2026 | The The Enable Shortcodes inside Widgets,Comments and Experts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes… | |
| Analizada | Media (5.4) | 0.26% | — | Sohelwpexpert Awesome Buttons | 25/10/2024 | 17/6/2026 | The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.2) | 0.46% | — | Schneider-electric Data Center ExpertAI | 11/10/2024 | 17/6/2026 | CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary bash scripts that are executed as root. | |
| Aplazada | Alta (8.5) | 0.42% | — | Wpexperts Square FOR GivewpAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal WPExperts Square For GiveWP wpexperts-square-for-give allows SQL Injection.This issue affects WPExperts Square For GiveWP: from n/a through <= 1.3. | |
| Analizada | Alta (7.8) | 0.21% | — | Schneider-electric Vijeo DesignerSchneider-electric Vijeo Designer Embedded IN Ecostruxure Machine Expert | 11/9/2024 | 17/6/2026 | CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries. | |
| Modificada | Media (5.3) | 0.26% | — | Wpexperts Mycred | 26/8/2024 | 17/6/2026 | Missing Authorization vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2. | |
| Modificada | Media (4.8) | 0.33% | — | Wpexperts WP Secure Maintenance | 12/7/2024 | 17/6/2026 | The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.34% | — | Wpexpertplugins Post Meta Data Manager | 2/7/2024 | 17/6/2026 | The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (6.3) | 0.36% | — | Softexpert Excellence SuiteAI | 26/6/2024 | 17/6/2026 | File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/efms_exec_html/file_upload_parser.php endpoint. | |
| Modificada | Media (6.5) | 0.39% | — | Wpexperts License Manager FOR Woocommerce | 21/6/2024 | 17/6/2026 | The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLicenseKey() and showAllLicenseKeys() functions in all versions up to, and including, 3.0.6. This makes it possible for authenticated attackers, with admin dashboard access… | |
| Modificada | Media (4.8) | 0.40% | — | Expert Invoice Project Expert Invoice | 18/6/2024 | 17/6/2026 | The Expert Invoice WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 0.68% | — | Codexpert Codesigner | 13/6/2024 | 17/6/2026 | The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.1 via deserialization of untrusted input from the recently_viewed_products cookie. This makes it possible for… |