Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
293.949 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.19% | — | Hoosoft Magee ShortcodesAI | 7/10/2026 | 7/10/2026 | The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay). | |
| Aplazada | Alta (7.1) | 0.16% | — | Hoosoft Magee ShortcodesAI | 7/10/2026 | 7/10/2026 | The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting. | |
| Aplazada | Baja (2.7) | 0.17% | — | CP Media PlayerAI | 7/10/2026 | 7/10/2026 | The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that… | |
| Aplazada | Alta (7.2) | 0.37% | — | Wow-company WP CoderAI | 7/10/2026 | 7/10/2026 | The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site. | |
| Aplazada | Media (6.8) | 0.23% | — | Wpmart Animated Number CountersAI | 7/10/2026 | 7/10/2026 | The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data… | |
| Aplazada | Media (6.8) | 0.24% | — | Enviragallery Envira GalleryAI | 7/10/2026 | 7/10/2026 | The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them and outputting them in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an… | |
| Aplazada | Media (6.8) | 0.24% | — | Enviragallery Envira GalleryAI | 7/10/2026 | 7/10/2026 | The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page embedding the… | |
| Aplazada | Media (4.3) | 0.13% | — | Yaad Sarig Payment Gateway FOR WCAI | 7/10/2026 | 7/10/2026 | The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting user owns the target order in several of its order payment-processing actions, allowing any authenticated user, including subscribers, to act on and alter orders belonging to other customers. | |
| Aplazada | Media (4.3) | 0.13% | — | Buffercode Frontend DashboardAI | 7/10/2026 | 7/10/2026 | The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the Frontend Dashboard WordPress plugin before 3.0.0's configured profile and post form fields. | |
| Aplazada | Media (6.5) | 0.14% | — | Geliver Akillikargo PazaryeriAI | 7/10/2026 | 7/10/2026 | The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site's carrier integration key while processing requests from unauthenticated users, allowing attackers to retrieve the key… | |
| Aplazada | Media (5.9) | 0.14% | — | Integration FOR Epos NOW AND WoocommerceAI | 7/10/2026 | 7/10/2026 | The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails… | |
| Pendiente de análisis | Alta (8.1) | 0.21% | — | Vmware WorkstationAIVmware FusionAI | 7/10/2026 | 7/10/2026 | VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. Affected versions: - VMware Workstation: 25H2, 26H1… | |
| Pendiente de análisis | Crítica (9.3) | 0.26% | 💥 PoC | Vmware WorkstationAIVmware FusionAI | 7/10/2026 | 7/10/2026 | VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware… | |
| Pendiente de análisis | Media (5) | 0.23% | — | Pulp RPMAI | 7/10/2026 | 7/10/2026 | A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and write that tree's repository metadata and packages there, as the… | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | Pulpproject Pulp AnsibleAI | 7/10/2026 | 7/10/2026 | A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access… | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | Pulp ContainerAI | 7/10/2026 | 7/10/2026 | A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token… | |
| Aplazada | Alta (7.2) | 0.37% | — | KirkiAI | 7/10/2026 | 7/10/2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via registration metadata in all versions up to, and including, 6.3.1 This is due to insufficient escaping in `ExceptionalElements::image_element()`, which concatenates a user-meta value… | |
| Pendiente de análisis | Crítica (9.3) | 0.37% | — | Flexnet PublisherAI | 7/10/2026 | 7/10/2026 | A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials. | |
| Aplazada | Crítica (9.3) | 0.32% | — | Asus Router FirmwareAI | 7/10/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker to read DOM information, modify router settings, and cause a denial-of-service condition when an authenticated user visits a crafted URL.Refer to the ' Security Update for ASUS Router… | |
| Aplazada | Alta (7.7) | 0.13% | — | Asus Rt-be57AI | 7/10/2026 | 7/10/2026 | A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT pairing token generation of the ASUS RT-BE57 router allows an unauthenticated nearby user to derive the pairing token and read or modify router settings via observed values from an administrator-initiated IFTTT pairing session.Refer to the '… | |
| Aplazada | Crítica (9.3) | 0.19% | — | Asus Router FirmwareAI | 7/10/2026 | 7/10/2026 | A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload that exceeds the expected buffer size.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information. | |
| Aplazada | Alta (8.4) | 0.21% | — | Asus Router FirmwareAI | 7/10/2026 | 7/10/2026 | Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for… | |
| Pendiente de análisis | Alta (8.1) | 0.28% | — | Candlepinproject CandlepinAI | 7/10/2026 | 7/10/2026 | A flaw was found in Candlepin. The central authorization filter incorrectly grants access when any one of multiple @Verify-annotated parameters is accessible, instead of requiring access to every verified entity. A low-privilege authenticated attacker who can access the first referenced object can bypass authorization… | |
| Aplazada | Crítica (9.2) | 0.65% | — | Asustor ADMAI | 7/10/2026 | 7/10/2026 | An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to… | |
| Pendiente de análisis | Alta (8.7) | 0.29% | — | Octopus ServerAI | 7/10/2026 | 7/10/2026 | In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to… |