Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

189 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.32%—Giuliopanda Bulk Images Optimizer18/10/202417/6/2026
The Bulk images optimizer: Resize, optimize, convert to webp, rename … plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_configuration' function in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.6)0.45%—Shortpixel Image OptimizerAI17/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Blind SQL Injection.This issue affects ShortPixel Image Optimizer: from n/a through <= 5.6.3.
AnalizadaCrítica (9.8)0.85%—Siteground Speed Optimizer16/10/202417/6/2026
The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0.12 due to incorrect use of an access control attribute on the switch_php function called via the /switch-php REST API route. This allows…
ModificadaMedia (5.3)0.37%—Wpchill Optimize Images ALT Text (alt Tag) & Names FOR SEO Using AI24/7/202417/6/2026
The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.1.1. This is due the plugin utilizing cocur and not preventing direct access to the generate-default.php file. This makes it possible for unauthenticated…
ModificadaAlta (8.8)0.32%—JCH Optimize Project JCH Optimize9/6/202417/6/2026
Broken Access Control vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.0.0.
AplazadaAlta (7.8)0.24%—Scikit-optimize SkopsAI4/6/202417/6/2026
Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded.
AplazadaMedia (4.3)0.45%—Qodeinteractive OptimizeAI16/5/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.2.0.
AplazadaAlta (8.8)1.9%—Image-optimizerAI5/5/202417/6/2026
image-optimizer before 1.7.3 allows PHAR deserialization, e.g., the phar:// protocol in arguments to file_exists().
AplazadaMedia (5.3)0.52%—Siteground Speed OptimizerAI17/4/202412/8/2026
Missing Authorization vulnerability in SiteGround Speed Optimizer.This issue affects Speed Optimizer: from n/a through 7.4.6.
AplazadaMedia (4.3)0.25%—Nosilver4u Ewww Image OptimizerAI10/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in nosilver4u EWWW Image Optimizer ewww-image-optimizer.This issue affects EWWW Image Optimizer: from n/a through <= 7.2.3.
AnalizadaMedia (4.3)0.22%—Wordpress Ping Optimizer Project Wordpress Ping Optimizer10/4/202417/6/2026
The WordPress Ping Optimizer WordPress plugin through 2.35.1.3.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as clearing logs.
AplazadaAlta (7.2)0.37%—Rapidload Power-up FOR AutoptimizeAI7/4/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize.This issue affects RapidLoad Power-Up for Autoptimize: from n/a through 2.2.11.
AplazadaMedia (4.3)0.20%—LWS OptimizeAI31/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Optimize.This issue affects LWS Optimize: from n/a through 1.9.1.
ModificadaMedia (4.3)0.20%—Marketingoptimizer Marketing Optimizer29/2/202417/6/2026
The Marketing Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20200925. This is due to missing or incorrect nonce validation via the admin/main-settings-page.php file. This makes it possible for unauthenticated attackers to update the plugin's settings…
ModificadaAlta (8.8)0.21%—Yevhenkotelnytskyi JS & CSS Script Optimizer8/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Yevhen Kotelnytskyi JS & CSS Script Optimizer.This issue affects JS & CSS Script Optimizer: from n/a through 0.3.3.
ModificadaMedia (6.1)0.46%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Teller field.
ModificadaAlta (7.5)0.36%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature.
ModificadaAlta (7.5)0.58%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field.
ModificadaMedia (6.1)0.46%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode field of a container.
ModificadaMedia (5.3)0.38%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field.
ModificadaAlta (7.5)0.58%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field.
ModificadaMedia (4.3)0.47%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing the journal to be displayed, despite the option being disabled.
ModificadaMedia (6.1)0.46%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log.
ModificadaMedia (4.8)0.44%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the User ID field when creating a new system user.
ModificadaMedia (5.5)0.17%—Sesami Cash Point & Transport Optimizer29/12/202317/6/2026
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack.
Orbitaley — Vulnerabilidades