Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

634 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.18%—Boldgrid Post AND Page BuilderAI6/1/202617/6/2026
Missing Authorization vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.9.
AplazadaMedia (5.3)0.21%—Wpgrids EasytestAI31/12/202517/6/2026
Missing Authorization vulnerability in WP Grids EasyTest convertpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EasyTest: from n/a through <= 1.0.1.
AplazadaMedia (5.3)0.21%—Boldgrid WeformsAI30/12/20255/10/2026
Missing Authorization vulnerability in BoldGrid weForms weforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weForms: from n/a through <= 1.6.25.
AplazadaAlta (7.1)0.18%—Councilsoft Content Grid SliderAI29/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in councilsoft Content Grid Slider content-grid-slider allows Reflected XSS.This issue affects Content Grid Slider: from n/a through <= 1.5.
AplazadaMedia (6.5)0.16%—Pickplugins Post GridAI24/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23.
AplazadaMedia (6.4)0.23%—Image Photo Gallery Final Tiles GridAI21/12/202517/6/2026
The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom scripts' setting in all versions up to, and including, 3.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level…
AplazadaMedia (5.4)0.29%—Image Photo Gallery Final Tiles GridAI19/12/202517/6/2026
The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.7. This is due to the plugin not properly verifying that a user is authorized to perform actions on gallery management functions. This makes it possible for authenticated…
AplazadaMedia (6.5)0.24%—Pickplugins Post GridAI18/12/202517/6/2026
Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.17.
AplazadaMedia (5.3)0.24%—Pickplugins Post Grid AND Gutenberg BlocksAI18/12/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23.
AplazadaAlta (7.1)0.18%—Boldgrid Sprout ClientsAI18/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows Reflected XSS.This issue affects Sprout Clients: from n/a through <= 3.2.1.
AplazadaCrítica (9.8)0.38%—Boldgrid Client Invoicing BY Sprout InvoicesAI18/12/20255/10/2026
Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.
AplazadaMedia (5.4)0.20%—Merkulove Grider FOR ElementorAI16/12/202517/6/2026
Missing Authorization vulnerability in merkulove Grider for Elementor grider-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grider for Elementor: from n/a through <= 1.0.8.
AplazadaMedia (5.9)0.28%—Filter GridsAI13/12/202517/6/2026
The Filter & Grids plugin for WordPress is vulnerable to SQL Injection via the 'phrase' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to…
AnalizadaMedia (5.3)0.30%—Siemens Gridscale X Prepay9/12/202517/6/2026
A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to capture-replay of authentication tokens. This could allow an authenticated but already locked-out user to establish still valid user sessions.
AnalizadaMedia (6.9)0.46%—Siemens Gridscale X Prepay9/12/202517/6/2026
A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to user enumeration due to distinguishable responses. This could allow an unauthenticated remote attacker to determine if a user is valid or not, enabling a brute force attack with valid users.
AplazadaMedia (4.3)0.22%—Codeamp Custom Layouts Post Product Grids Made EasyAI9/12/20255/10/2026
Missing Authorization vulnerability in Code Amp Custom Layouts – Post + Product grids made easy custom-layouts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Layouts – Post + Product grids made easy: from n/a through <= 1.4.12.
AplazadaCrítica (9)23%💥 PoCBoldgrid W3 Total CacheAI17/11/202517/6/2026
The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.
AplazadaMedia (4.3)0.24%—Image Gallery Photo Grid Video GalleryAI15/11/202517/6/2026
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes it possible for authenticated attackers, with author-level access and above,…
AplazadaAlta (8.5)0.14%—Altair Grid EngineAI11/11/202517/6/2026
A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly validate environment variables when loading shared libraries, allowing path hijacking through malicious library substitution. This could allow a local attacker to execute arbitrary code with…
AplazadaMedia (6.8)0.13%—Altair Grid EngineAI11/11/202517/6/2026
A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly handle error messages and discloses sensitive password hash information when processing user authentication requests. This could allow a local attacker to extract password hashes for privileged…
AplazadaMedia (6.5)0.33%—Pickplugins Post GridAIPickplugins Gutenberg BlocksAI27/10/202517/6/2026
Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.17.
AnalizadaCrítica (9.8)0.38%—Microsoft Azure Event Grid23/10/202517/6/2026
Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.
AplazadaAlta (7.1)0.25%—G5theme Grid PlusAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Grid Plus grid-plus allows Reflected XSS.This issue affects Grid Plus: from n/a through <= 3.3.
AplazadaCrítica (9.8)0.49%—Themesflat TF WOO Product GridAI22/10/20255/10/2026
Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For Elementor tf-woo-product-grid allows Object Injection.This issue affects TF Woo Product Grid Addon For Elementor: from n/a through <= 1.0.1.
AplazadaMedia (6.4)0.24%—Cinza GridAI22/10/202517/6/2026
The Cinza Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cgrid_skin_content' post meta field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
Orbitaley — Vulnerabilidades