Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

454 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.35%—Wpgogo Custom Field TemplateAI9/12/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Hiroaki Miyashita Custom Field Template custom-field-template allows Retrieve Embedded Sensitive Data.This issue affects Custom Field Template: from n/a through <= 2.7.6.
AplazadaCrítica (9.8)68%💥 ExploitAcfextended Advanced Custom Fields ExtendedAI3/12/202517/6/2026
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated…
AplazadaCrítica (10)0.46%—Addify Custom User Registration Fields FOR WoocommerceAI6/11/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Addify Custom User Registration Fields for WooCommerce user-registration-plugin-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Custom User Registration Fields for WooCommerce: from n/a through <= 2.1.2.
AplazadaAlta (8.8)0.70%—Wordpress User Extra FieldsAI31/10/202517/6/2026
The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in all versions up to, and including, 16.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete…
AnalizadaMedia (6.1)0.20%—Json Field Project Json Field30/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal JSON Field allows Cross-Site Scripting (XSS).This issue affects JSON Field: from 0.0.0 before 1.5.
AplazadaMedia (6.7)0.18%—Nvidia BluefieldAINvidia ConnectxAI22/10/202517/6/2026
NVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a malicious actor with high privilege access to execute arbitrary code.
AplazadaAlta (8.8)0.39%—Extendons Woocommerce Registration FieldsAI22/10/202517/6/2026
Incorrect Privilege Assignment vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields allows Privilege Escalation.This issue affects WooCommerce Registration Fields Plugin - Custom Signup Fields: from n/a through <= 3.2.3.
AplazadaAlta (8.8)0.20%—Tusko Trush Advanced Custom Fields CPT Options PagesAI22/10/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-options-pages allows Object Injection.This issue affects Advanced Custom Fields : CPT Options Pages: from n/a through <= 2.0.9.
AplazadaAlta (7.1)0.28%—Extendons Woocommerce Registration Fields PluginAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields allows Reflected XSS.This issue affects WooCommerce Registration Fields Plugin - Custom Signup Fields: from n/a…
AplazadaMedia (6.5)0.17%—Silverplugins217 Dynamic Text Field FOR Contact Form 7AI9/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silverplugins217 Dynamic Text Field For Contact Form 7 dynamic-text-field-for-contact-form-7 allows Stored XSS.This issue affects Dynamic Text Field For Contact Form 7: from n/a through <= 1.0.
AplazadaMedia (4.3)0.14%—Themelocation Custom Woocommerce Checkout Fields EditorAI5/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in themelocation Custom WooCommerce Checkout Fields Editor add-fields-to-checkout-page-woocommerce allows Cross Site Request Forgery.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through <= 1.3.4.
AplazadaAlta (8.7)0.15%—Nvidia BluefieldAI4/9/202517/6/2026
NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.
AplazadaAlta (8.6)0.47%—Buddypress Xprofile Custom Image FieldAI20/8/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field buddypress-xprofile-image-field allows Path Traversal.This issue affects BuddyPress XProfile Custom Image Field: from n/a through <= 3.0.1.
AplazadaMedia (4.6)0.21%—Advancedcustomfields Advanced Custom FieldsAI8/8/202517/6/2026
An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered.
AplazadaCrítica (10)1.8%💥 ExploitAdvancedcustomfields Advanced Custom FieldsAI5/8/202516/6/2026
The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuration directive allow_url_include is enabled (default: Off), an unauthenticated attacker can exploit the acf_abspath POST parameter to include…
AplazadaMedia (4.3)0.26%—Sminozzi Real Estate Property 2024 Create Your OWN Fields AND Search BARAI16/7/202517/6/2026
Missing Authorization vulnerability in sminozzi Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin real-estate-right-now allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin: from n/a…
AnalizadaAlta (8.1)0.34%—Oracle Mobile Field Service15/7/202517/6/2026
Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Multiplatform Sync Errors). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Field Service.…
AnalizadaAlta (7.5)0.46%—Sick Field Analytics12/6/202517/6/2026
The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files.
AnalizadaCrítica (9.8)0.33%—Sick Field Analytics12/6/202517/6/2026
The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, making the application unusable. They can redirect…
AnalizadaCrítica (9.1)0.26%—Sick Field Analytics12/6/202517/6/2026
A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected ways or spoof identities of other users or devices, affecting the confidentiality and integrity of the device.
AnalizadaMedia (6.1)0.31%—Sick Baggage AnalyticsSick Field AnalyticsSick Logistic Diagnostic AnalyticsSick Media Server+212/6/202517/6/2026
The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks).
AnalizadaMedia (6.1)0.33%—Sick Field AnalyticsSick Media Server12/6/202517/6/2026
The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others to take control of their computer while…
AnalizadaMedia (6.1)0.35%—Sick Field Analytics12/6/202517/6/2026
Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker is authorized to create new dashboards…
AnalizadaMedia (5.8)0.34%—Sick Field Analytics12/6/202517/6/2026
The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports.
AnalizadaAlta (7.5)0.44%—Sick Field Analytics12/6/202517/6/2026
The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.
Orbitaley — Vulnerabilidades