Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
189 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.32% | — | Giuliopanda Bulk Images Optimizer | 18/10/2024 | 17/6/2026 | The Bulk images optimizer: Resize, optimize, convert to webp, rename … plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_configuration' function in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.6) | 0.45% | — | Shortpixel Image OptimizerAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Blind SQL Injection.This issue affects ShortPixel Image Optimizer: from n/a through <= 5.6.3. | |
| Analizada | Crítica (9.8) | 0.85% | — | Siteground Speed Optimizer | 16/10/2024 | 17/6/2026 | The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0.12 due to incorrect use of an access control attribute on the switch_php function called via the /switch-php REST API route. This allows… | |
| Modificada | Media (5.3) | 0.37% | — | Wpchill Optimize Images ALT Text (alt Tag) & Names FOR SEO Using AI | 24/7/2024 | 17/6/2026 | The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.1.1. This is due the plugin utilizing cocur and not preventing direct access to the generate-default.php file. This makes it possible for unauthenticated… | |
| Modificada | Alta (8.8) | 0.32% | — | JCH Optimize Project JCH Optimize | 9/6/2024 | 17/6/2026 | Broken Access Control vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.0.0. | |
| Aplazada | Alta (7.8) | 0.24% | — | Scikit-optimize SkopsAI | 4/6/2024 | 17/6/2026 | Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded. | |
| Aplazada | Media (4.3) | 0.45% | — | Qodeinteractive OptimizeAI | 16/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.2.0. | |
| Aplazada | Alta (8.8) | 1.9% | — | Image-optimizerAI | 5/5/2024 | 17/6/2026 | image-optimizer before 1.7.3 allows PHAR deserialization, e.g., the phar:// protocol in arguments to file_exists(). | |
| Aplazada | Media (5.3) | 0.52% | — | Siteground Speed OptimizerAI | 17/4/2024 | 12/8/2026 | Missing Authorization vulnerability in SiteGround Speed Optimizer.This issue affects Speed Optimizer: from n/a through 7.4.6. | |
| Aplazada | Media (4.3) | 0.25% | — | Nosilver4u Ewww Image OptimizerAI | 10/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nosilver4u EWWW Image Optimizer ewww-image-optimizer.This issue affects EWWW Image Optimizer: from n/a through <= 7.2.3. | |
| Analizada | Media (4.3) | 0.22% | — | Wordpress Ping Optimizer Project Wordpress Ping Optimizer | 10/4/2024 | 17/6/2026 | The WordPress Ping Optimizer WordPress plugin through 2.35.1.3.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as clearing logs. | |
| Aplazada | Alta (7.2) | 0.37% | — | Rapidload Power-up FOR AutoptimizeAI | 7/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize.This issue affects RapidLoad Power-Up for Autoptimize: from n/a through 2.2.11. | |
| Aplazada | Media (4.3) | 0.20% | — | LWS OptimizeAI | 31/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Optimize.This issue affects LWS Optimize: from n/a through 1.9.1. | |
| Modificada | Media (4.3) | 0.20% | — | Marketingoptimizer Marketing Optimizer | 29/2/2024 | 17/6/2026 | The Marketing Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20200925. This is due to missing or incorrect nonce validation via the admin/main-settings-page.php file. This makes it possible for unauthenticated attackers to update the plugin's settings… | |
| Modificada | Alta (8.8) | 0.21% | — | Yevhenkotelnytskyi JS & CSS Script Optimizer | 8/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Yevhen Kotelnytskyi JS & CSS Script Optimizer.This issue affects JS & CSS Script Optimizer: from n/a through 0.3.3. | |
| Modificada | Media (6.1) | 0.46% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Teller field. | |
| Modificada | Alta (7.5) | 0.36% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature. | |
| Modificada | Alta (7.5) | 0.58% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field. | |
| Modificada | Media (6.1) | 0.46% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode field of a container. | |
| Modificada | Media (5.3) | 0.38% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field. | |
| Modificada | Alta (7.5) | 0.58% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field. | |
| Modificada | Media (4.3) | 0.47% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing the journal to be displayed, despite the option being disabled. | |
| Modificada | Media (6.1) | 0.46% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log. | |
| Modificada | Media (4.8) | 0.44% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the User ID field when creating a new system user. | |
| Modificada | Media (5.5) | 0.17% | — | Sesami Cash Point & Transport Optimizer | 29/12/2023 | 17/6/2026 | An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack. |