Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.29% | — | Ashish Ajani Contact-form-vcard-generatorAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani Contact Form vCard Generator contact-form-vcard-generator allows Reflected XSS.This issue affects Contact Form vCard Generator: from n/a through <= 2.4. | |
| Analizada | Media (4.8) | 0.27% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'. | |
| Analizada | Crítica (9.8) | 0.50% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4. | |
| Analizada | Crítica (9.8) | 0.50% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1. | |
| Analizada | Crítica (9.8) | 0.77% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Analizada | Media (5.1) | 0.26% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Analizada | Media (5.4) | 0.27% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'. | |
| Analizada | Media (5.9) | 0.25% | — | Oretnom23 Online ID Generator System | 16/4/2025 | 17/6/2026 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1. | |
| Aplazada | Alta (7.5) | 0.38% | — | Dmitry V Barcode Generator FOR WoocommerceAI | 15/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-barcodes-into-product-pages-and-orders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Barcode Generator for WooCommerce: from n/a through <= 2.0.4. | |
| Aplazada | Media (4.3) | 0.29% | — | Wpmessiah AI Image ALT Text Generator FOR WPAI | 10/4/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Messiah Ai Image Alt Text Generator for WP ai-image-alt-text-generator-for-wp allows Retrieve Embedded Sensitive Data.This issue affects Ai Image Alt Text Generator for WP: from n/a through <= 1.1.9. | |
| Aplazada | Media (5.4) | 0.49% | — | Wpmessiah AI Image ALT Text Generator FOR WPAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Messiah Ai Image Alt Text Generator for WP ai-image-alt-text-generator-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ai Image Alt Text Generator for WP: from n/a through <= 1.1.1. | |
| Aplazada | Alta (7.6) | 0.54% | — | Generator-jhipster-entity-auditAIJaversAI | 3/4/2025 | 17/6/2026 | generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page. Prior to 5.9.1, generator-jhipster-entity-audit allows unsafe reflection when having Javers selected as Entity Audit Framework. If an attacker manages to place some malicious classes into the classpath and also has access… | |
| Analizada | Media (6.9) | 0.56% | — | Phpgurukul Time Table Generator System | 3/4/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Time Table Generator System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-class.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Aplazada | Alta (7.1) | 0.29% | — | Ashish Ajani Contact Form Vcard GeneratorAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani Contact Form vCard Generator contact-form-vcard-generator allows Stored XSS.This issue affects Contact Form vCard Generator: from n/a through <= 2.4. | |
| Aplazada | Media (5.4) | 0.27% | — | Dmitry V Barcode Generator FOR WoocommerceAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-barcodes-into-product-pages-and-orders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Barcode Generator for WooCommerce: from n/a through <= 2.0.4. | |
| Aplazada | Media (5.4) | 0.27% | — | Dmitry V UPC EAN Gtin Code GeneratorAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator upc-ean-barcode-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UPC/EAN/GTIN Code Generator: from n/a through <= 2.0.2. | |
| Aplazada | Media (6.5) | 0.27% | — | Redefiningtheweb PDF Generator Addon FOR Elementor Page BuilderAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Page Builder pdf-generator-addon-for-elementor-page-builder allows Stored XSS.This issue affects PDF Generator Addon for Elementor Page Builder: from n/a through <=… | |
| Aplazada | Media (5.4) | 0.45% | — | Oliver Boyers PIN GeneratorAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Oliver Boyers Pin Generator pin-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pin Generator: from n/a through <= 2.0.0. | |
| Aplazada | Alta (7.1) | 0.31% | — | Wpwham SKU Generator FOR WoocommerceAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Wham SKU Generator for WooCommerce sku-for-woocommerce allows Reflected XSS.This issue affects SKU Generator for WooCommerce: from n/a through <= 1.6.2. | |
| Analizada | Media (5.3) | 0.48% | — | Projectworlds Online Time Table Generator | 1/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. This vulnerability affects unknown code of the file /student/updateprofile.php. The manipulation of the argument pic leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.48% | — | Projectworlds Online Time Table Generator | 1/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /admin/updatestudent.php. The manipulation of the argument pic leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.64% | — | Projectworlds Online Time Table Generator | 31/3/2025 | 17/6/2026 | A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_student.php. The manipulation of the argument pic leads to unrestricted upload. The attack may be launched remotely. The exploit has… | |
| Aplazada | Media (4.3) | 0.14% | — | Nopeamedia Print PDF Generator AND PublisherAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in verkkovaraani Print PDF Generator and Publisher nopeamedia allows Cross Site Request Forgery.This issue affects Print PDF Generator and Publisher: from n/a through <= 1.2.0. | |
| Aplazada | Media (4.3) | 0.17% | — | Vollstart Serial Codes Generator AND ValidatorAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Vollstart Serial Codes Generator and Validator with WooCommerce Support serial-codes-generator-and-validator allows Cross Site Request Forgery.This issue affects Serial Codes Generator and Validator with WooCommerce Support: from n/a through <= 2.7.7. | |
| Analizada | Media (5.3) | 0.59% | — | Projectworlds Online Time Table Generator | 23/3/2025 | 17/6/2026 | A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been classified as critical. Affected is an unknown function of the file student/studentdashboard.php. The manipulation of the argument course leads to sql injection. It is possible to launch the attack remotely. The exploit has been… |