Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
250 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.29% | — | Kylephillips Nested Pages | 4/7/2024 | 17/6/2026 | The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing or incorrect nonce validation on the 'settingsPage' function and missing santization of the 'tab' parameter. This makes it possible for unauthenticated attackers to call… | |
| Modificada | Media (5.3) | 0.37% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 21/6/2024 | 17/6/2026 | The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to… | |
| Modificada | Alta (7.3) | 0.25% | — | Ipages Flipbook Project Ipages Flipbook | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Avirtum iPages Flipbook.This issue affects iPages Flipbook: from n/a through 1.5.1. | |
| Modificada | Alta (8.8) | 0.36% | — | Themekraft Buddypress Woocommerce MY Account Integration. Create Woocommerce Member Pages | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.19. | |
| Aplazada | Alta (7.2) | 0.31% | — | Social Link PagesAI | 4/6/2024 | 17/6/2026 | The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_link_pages() function in all versions up to, and including, 1.6.9. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (4.3) | 0.56% | — | Different Menu IN Different PagesAI | 2/5/2024 | 17/6/2026 | The Different Menu in Different Pages – Control Menu Visibility (All in One) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax() function in all versions up to, and including, 2.3.2. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Media (4.3) | 0.21% | — | Wpwax Legal PagesAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1.4.2. | |
| Modificada | Alta (7.5) | 0.53% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 10/4/2024 | 12/8/2026 | Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5. | |
| Aplazada | Media (5.4) | 0.21% | — | Landingi Landing PagesAI | 29/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Landingi Landingi Landing Pages.This issue affects Landingi Landing Pages: from n/a through 3.1.1. | |
| Modificada | Alta (8) | 0.21% | — | Wpwax Legal Pages | 15/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF), Incorrect Authorization vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1.3.7. | |
| Analizada | Media (4.3) | 0.30% | — | Najeebmedia Comments Extra Fields FOR Post, Pages AND CPT | 13/3/2024 | 11/8/2026 | The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0. This is due to missing or incorrect nonce validation on several ajax actions. This makes it possible for unauthenticated attackers to invoke those actions via a… | |
| Analizada | Media (4.3) | 0.53% | — | Najeebmedia Comments Extra Fields FOR Post, Pages AND CPT | 13/3/2024 | 11/8/2026 | The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0. This is due to missing or incorrect capability checks on several ajax actions. This makes it possible for authenticated attackers, with subscriber access or higher, to… | |
| Modificada | Media (6.5) | 0.65% | — | Ampforwp Accelerated Mobile Pages | 29/2/2024 | 17/6/2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'amppb_remove_saved_layout_data' function in all versions up to, and including, 1.0.93.1. This makes it possible for authenticated attackers, with contributor access and… | |
| Analizada | Media (6.1) | 0.43% | — | Jstrieb URL Pages | 26/2/2024 | 17/6/2026 | A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages before commit 035b647 allows attackers to execute arbitrary Javascript via sending a crafted URL. | |
| Modificada | Media (6.1) | 0.33% | — | Geekcodelab ALL 404 Pages Redirect TO Homepage | 12/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Geek Code Lab All 404 Pages Redirect to Homepage allows Stored XSS.This issue affects All 404 Pages Redirect to Homepage: from n/a through 1.9. | |
| Modificada | Media (6.1) | 0.44% | — | Ampforwp Accelerated Mobile Pages | 23/1/2024 | 17/6/2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqus_name' parameter in all versions up to, and including, 1.0.92.1 due to insufficient input sanitization and output escaping on the executed JS file. This makes it possible for unauthenticated… | |
| Modificada | Alta (8.8) | 0.70% | — | IBM Openpages With Watson | 19/1/2024 | 17/6/2026 | IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By authenticating as an OpenPages user and using non-public APIs, an attacker could exploit this vulnerability to bypass security and gain unauthorized administrative access… | |
| Modificada | Alta (8.1) | 0.53% | — | IBM Openpages With Watson | 19/1/2024 | 17/6/2026 | IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in a OpenPages environment using Native authentication. If OpenPages is using Native authentication an attacker with access to the OpenPages database could through a series of specially crafted steps could exploit this weakness and gain… | |
| Modificada | Alta (8.8) | 0.23% | — | Infolific ADD ANY Extension TO Pages | 28/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Add Any Extension to Pages.This issue affects Add Any Extension to Pages: from n/a through 1.4. | |
| Modificada | Media (4.9) | 0.54% | — | Ipages Flipbook Project Ipages Flipbook | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum iPages Flipbook For WordPress.This issue affects iPages Flipbook For WordPress: from n/a through 1.4.8. | |
| Modificada | Media (6.1) | 0.48% | — | Magazine3 Core WEB Vitals & Pagespeed Booster | 19/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magazine3 Core Web Vitals & PageSpeed Booster.This issue affects Core Web Vitals & PageSpeed Booster: from n/a through 1.0.12. | |
| Modificada | Media (4.8) | 0.39% | — | Kylephillips Nested Pages | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS.This issue affects Nested Pages: from n/a through 3.2.6. | |
| Modificada | Alta (8.8) | 0.25% | — | Wpwax Legal Pages | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpWax Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator plugin <= 1.3.8 versions. | |
| Modificada | Media (4.8) | 0.45% | — | Wpeka Wplegalpages | 20/10/2023 | 17/6/2026 | The WPLegalPages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wplegalpage' shortcode in versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with author-level and above… | |
| Modificada | Alta (8.8) | 0.23% | — | Keap Landing Pages | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Keap Keap Landing Pages plugin <= 1.4.2 versions. |