Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
191 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.18% | — | Oracle Complex Maintenance Repair AND Overhaul | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance,… | |
| Analizada | Media (6.1) | 0.38% | — | Oracle Complex Maintenance Repair AND Overhaul | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance,… | |
| Modificada | Media (6.1) | 0.33% | — | Oracle Complex Maintenance Repair AND Overhaul | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance,… | |
| Analizada | Media (6.1) | 0.38% | — | Oracle Complex Maintenance Repair AND Overhaul | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance,… | |
| Analizada | Media (6.1) | 0.38% | — | Oracle Complex Maintenance Repair AND Overhaul | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance,… | |
| Aplazada | Media (4.3) | 0.21% | — | Seedprod Coming Soon Page Under Construction Maintenance ModeAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through 6.15.20. | |
| Aplazada | Media (5.3) | 0.43% | — | CGC Maintenance ModeAI | 4/4/2024 | 17/6/2026 | The CGC Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2 via the REST API. This makes it possible for unauthenticated attackers to view protected posts via REST API even when maintenance mode is enabled. | |
| Aplazada | Media (5.5) | 0.35% | — | Niteothemes CMP Coming Soon MaintenanceAI | 28/3/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in NiteoThemes CMP – Coming Soon & Maintenance.This issue affects CMP – Coming Soon & Maintenance: from n/a through 4.1.10. | |
| Aplazada | Media (5.3) | 0.43% | — | Easy Maintenance ModeAI | 20/3/2024 | 17/6/2026 | The Easy Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the REST API. This makes it possible for authenticated attackers to obtain post and page content via REST API thus bypassign the protection provided by the plugin. | |
| Modificada | Media (5.3) | 0.53% | — | Colorlib Coming Soon & Maintenance Mode | 20/3/2024 | 17/6/2026 | The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.99 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page contents via REST API thus bypassing maintenance mode protection provided… | |
| Aplazada | Media (5.3) | 0.59% | — | Dazzler Coming Soon Under Construction Maintenance ModeAI | 20/3/2024 | 17/6/2026 | The Coming Soon, Under Construction & Maintenance Mode By Dazzler plugin for WordPress is vulnerable to maintenance mode bypass in all versions up to, and including, 2.1.2. This is due to the plugin relying on the REQUEST_URI to determine if the page being accesses is an admin area. This makes it possible for… | |
| Modificada | Media (5.3) | 0.53% | — | Themegrill Maintenance Page | 13/3/2024 | 17/6/2026 | The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 1.0.8 via the REST API. This makes it possible for unauthenticated attackers to view post titles and content when the site is in maintenance mode. | |
| Modificada | Media (4.3) | 0.45% | — | Themegrill Maintenance Page | 13/3/2024 | 17/6/2026 | The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the subscribe_download function hooked via AJAX action in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with subscriber access or higher, to… | |
| Aplazada | Baja (3.8) | 0.14% | — | Livedata Maintenance ServerAI | 5/3/2024 | 17/6/2026 | Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server. The issue… | |
| Modificada | Media (5.3) | 0.53% | — | Helderk Maintenance Mode | 5/3/2024 | 17/6/2026 | The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page content via API thus bypassing the content protection provided by the plugin. | |
| Modificada | Media (5.3) | 0.46% | — | Awplife Coming Soon Maintenance Mode | 29/2/2024 | 17/6/2026 | The Coming Soon Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page content thus bypassing the protection provided by the plugin. | |
| Modificada | Media (5.3) | 0.46% | — | Restezconnectes WP Maintenance | 29/2/2024 | 17/6/2026 | The WP Maintenance plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.1.6 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's maintenance mode obtain post and page content via REST API. | |
| Modificada | Media (5.3) | 0.47% | — | Acurax Under Construction / Maintenance Mode | 28/2/2024 | 17/6/2026 | The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6 via the REST API. This makes it possible for unauthenticated attackers to obtain the contents of posts and pages when maintenance mode is active thus… | |
| Modificada | Media (5.3) | 0.46% | — | Wpshopmart Coming Soon Page & Maintenance Mode | 28/2/2024 | 17/6/2026 | The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an improperly implemented URL check in the wpsm_coming_soon_redirect function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to view a site with… | |
| Modificada | Media (6.5) | 0.49% | — | Acurax Under Construction / Maintenance Mode | 28/2/2024 | 17/6/2026 | The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.6 via the 'acx_csma_subscribe_ajax' function. This can allow authenticated attackers to extract sensitive data such as names and email addresses of subscribed… | |
| Modificada | Media (5.3) | 0.68% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 5/2/2024 | 17/6/2026 | The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenance… | |
| Modificada | Media (6.1) | 0.17% | — | Oracle Complex Maintenance, Repair, AND Overhaul | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: LOV). Supported versions that are affected are 11.5, 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance,… | |
| Modificada | Media (4.8) | 0.39% | — | Wpexperts Rocket Maintenance Mode & Coming Soon Page | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpexpertsio Rocket Maintenance Mode & Coming Soon Page allows Stored XSS.This issue affects Rocket Maintenance Mode & Coming Soon Page: from n/a through 4.3. | |
| Modificada | Media (6.1) | 0.41% | — | Acurax Under Construction / Maintenance Mode | 16/11/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Acurax Under Construction / Maintenance Mode from Acurax plugin <= 2.6 versions. | |
| Modificada | Crítica (9.8) | 0.68% | — | Weblizar Responsive Coming Soon & Maintenance Mode | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar Coming Soon Page – Responsive Coming Soon & Maintenance Mode allows SQL Injection.This issue affects Coming Soon Page – Responsive Coming Soon & Maintenance Mode: from n/a through 1.5.9. |