Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.76%—Pluginus Husky - Products Filter Professional FOR Woocommerce29/3/202417/6/2026
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.5.2 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary…
ModificadaMedia (6.1)0.37%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional28/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR allows Reflected XSS.This issue affects BEAR: from n/a through 1.1.4.2.
ModificadaMedia (6.5)0.38%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional23/3/202417/6/2026
Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.
ModificadaAlta (8.8)0.23%—Pluginus Husky - Products Filter Professional FOR Woocommerce15/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 HUSKY – Products Filter for WooCommerce (formerly WOOF).This issue affects HUSKY – Products Filter for WooCommerce (formerly WOOF): from n/a through 1.3.4.3.
ModificadaMedia (5.4)0.34%—Pluginus Husky - Products Filter Professional FOR Woocommerce15/3/202417/6/2026
The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'woof' shortcode in all versions up to, and including, 1.3.5.1 due to insufficient input sanitization and output escaping on user supplied attributes such as 'swoof_slug'. This…
ModificadaAlta (8.8)0.56%—Pluginus Husky - Products Filter Professional FOR Woocommerce15/3/202417/6/2026
The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to SQL Injection via the 'name' parameter in the woof shortcode in all versions up to, and including, 1.3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
ModificadaMedia (4.3)0.43%—Hikvision Hikcentral Professional2/3/202417/6/2026
Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values.
ModificadaAlta (7.5)0.57%—Hikvision Hikcentral Professional2/3/202417/6/2026
Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should not have access to.
ModificadaAlta (8.8)0.21%—Blackbam Tinymce AND Tinymce Advanced Professsional Formats AND Styles21/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in David Stockl TinyMCE and TinyMCE Advanced Professsional Formats and Styles.This issue affects TinyMCE and TinyMCE Advanced Professsional Formats and Styles: from n/a through 1.1.2.
ModificadaAlta (7.1)0.27%—Siemens Openpcs 7Siemens Simatic BatchSiemens Simatic PCS 7Siemens Simatic Route Control+213/2/202417/6/2026
A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC Route Control V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 4),…
ModificadaAlta (7.1)0.27%—Siemens Openpcs 7Siemens Simatic BatchSiemens Simatic PCS 7Siemens Simatic Route Control+213/2/202417/6/2026
A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC Route Control V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 4),…
ModificadaMedia (4.8)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional8/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net allows Stored XSS.This issue affects BEAR – Bulk Editor and Products Manager Professional for WooCommerce by…
ModificadaMedia (4.3)0.53%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional5/2/202417/6/2026
The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing capability check on the wpbe_create_new_term, wpbe_update_tax_term, and wpbe_delete_tax_term functions in all versions up to, and including, 1.0.8.1.…
ModificadaMedia (4.3)0.31%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional5/2/202417/6/2026
The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8.1. This is due to missing or incorrect nonce validation on the wpbe_create_new_term, wpbe_update_tax_term, and wpbe_delete_tax_term functions.…
ModificadaMedia (6.1)0.33%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional31/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional allows Reflected XSS.This issue affects WOLF – WordPress Posts Bulk Editor and Manager Professional: from n/a through 1.0.8.
ModificadaAlta (8.8)1.3%—Pluginus FOX - Currency Switcher Professional FOR Woocommerce16/1/202417/6/2026
The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.
ModificadaMedia (5.4)0.41%—Pluginus FOX - Currency Switcher Professional FOR Woocommerce11/1/202417/6/2026
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
ModificadaCrítica (9.8)0.59%—Pluginus Husky - Products Filter Professional FOR Woocommerce20/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in realmag777 HUSKY – Products Filter for WooCommerce Professional.This issue affects HUSKY – Products Filter for WooCommerce Professional: from n/a through 1.3.4.2.
ModificadaAlta (8.8)0.25%—Pluginus FOX - Currency Switcher Professional FOR Woocommerce17/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 FOX – Currency Switcher Professional for WooCommerce.This issue affects FOX – Currency Switcher Professional for WooCommerce: from n/a through 1.4.1.4.
ModificadaMedia (5.4)0.63%—Michaelschwarz Ajax.net Professional5/12/202317/6/2026
Ajax.NET Professional (AjaxPro) is an AJAX framework for Microsoft ASP.NET which will create proxy JavaScript classes that are used on client-side to invoke methods on the web server. Affected versions of this package are vulnerable cross site scripting attacks. Releases before version 21.12.22.1 are affected. Users…
ModificadaAlta (8.8)0.27%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional25/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7.1 versions.
ModificadaMedia (4.3)0.56%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_swap function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
ModificadaMedia (4.3)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulk_delete_products function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they can…
ModificadaMedia (4.3)0.31%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobe_bulkoperations_delete function. This makes it possible for authenticated attackers, with subscriber access or higher, to delete products.
ModificadaMedia (4.3)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_delete function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they can…