Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.28% | — | Snipeitapp Snipe-itAI | 3/2/2026 | 17/6/2026 | Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags to execute arbitrary JavaScript when the accessory is viewed by other users. | |
| Aplazada | Media (5.1) | 0.43% | — | SnippcommandAI | 16/1/2026 | 17/6/2026 | SnipCommand 0.1.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into command snippets. Attackers can execute arbitrary code by embedding malicious JavaScript that triggers remote command execution through file or title inputs. | |
| Aplazada | Media (4.3) | 0.12% | — | Postsnippets Post SnippetsAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Post Snippets post-snippets allows Cross Site Request Forgery.This issue affects Post Snippets: from n/a through <= 4.0.11. | |
| Modificada | Media (5.4) | 0.19% | — | Snipeitapp Snipe-it | 1/12/2025 | 5/7/2026 | Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session. | |
| Modificada | Media (5.4) | 0.17% | — | Snipeitapp Snipe-it | 1/12/2025 | 5/7/2026 | Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation. | |
| Modificada | Media (6.1) | 0.24% | 💥 PoC | Snipeitapp Snipe-it | 20/11/2025 | 17/6/2026 | Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application returns a progress_message value that is rendered as raw HTML in the admin interface. An attacker can intercept and modify the POST… | |
| Aplazada | Alta (8) | 0.36% | — | Codesnippets Code SnippetsAI | 19/11/2025 | 17/6/2026 | The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` variable… | |
| Modificada | Crítica (9.9) | 0.64% | — | Snipeitapp Snipe-it | 5/11/2025 | 17/6/2026 | Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system commands. | |
| Aplazada | Media (4.3) | 0.21% | — | F1logic Insert PHP Code SnippetAI | 31/10/2025 | 17/6/2026 | Missing Authorization vulnerability in f1logic Insert PHP Code Snippet insert-php-code-snippet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Insert PHP Code Snippet: from n/a through <= 1.4.3. | |
| Aplazada | Alta (7.1) | 0.25% | — | Fidelo Software Gmbh Fidelo SnippetAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fidelo Software GmbH Fidelo Snippet thebing-snippet allows Reflected XSS.This issue affects Fidelo Snippet: from n/a through <= 1.12. | |
| Aplazada | Media (4.9) | 0.36% | — | Rich Snippet Site ReportAI | 15/10/2025 | 17/6/2026 | The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last' parameter in all versions up to, and including, 2.0.0105 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Analizada | Alta (8.1) | 0.37% | — | Snipeitapp Snipe-it | 19/9/2025 | 17/6/2026 | Snipe-IT before 8.1.18 allows unsafe deserialization. | |
| Analizada | Media (5.4) | 0.26% | 💥 PoC | Snipeitapp Snipe-it | 19/9/2025 | 17/6/2026 | Snipe-IT before 8.1.18 allows XSS. | |
| Aplazada | Media (4.3) | 0.13% | — | Pluginsandsnippets Simple Page Access RestrictionAI | 27/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Plugins and Snippets Simple Page Access Restriction simple-page-access-restriction allows Cross Site Request Forgery.This issue affects Simple Page Access Restriction: from n/a through <= 1.0.32. | |
| Aplazada | Crítica (9.6) | 0.19% | — | Shahjahan Jewel Fluent SnippetsAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets easy-code-manager allows Cross Site Request Forgery.This issue affects FluentSnippets: from n/a through <= 10.50. | |
| Analizada | Media (6.5) | 0.22% | — | Pluginsandsnippets Simple Page Access Restriction | 30/5/2025 | 17/6/2026 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and capability checks in the settings save handler in the settings.php script. This makes it possible for unauthenticated attackers… | |
| Analizada | Baja (3.3) | 1.3% | 💥 Exploit | Snipeitapp Snipe-it | 2/5/2025 | 17/6/2026 | Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information. | |
| Aplazada | Media (6.5) | 0.22% | — | Webberzone SnippetzAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay WebberZone Snippetz add-to-all allows Stored XSS.This issue affects WebberZone Snippetz: from n/a through <= 2.1.1. | |
| Aplazada | Media (4.3) | 0.21% | — | Smackcoders INC Google SEO Pressor SnippetAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Smackcoders Inc., Google SEO Pressor Snippet google-seo-author-snippets allows Cross Site Request Forgery.This issue affects Google SEO Pressor Snippet: from n/a through <= 2.0. | |
| Aplazada | Media (4.3) | 0.28% | — | Smackcoders INC Google SEO Pressor SnippetAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Smackcoders Inc., Google SEO Pressor Snippet google-seo-author-snippets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google SEO Pressor Snippet: from n/a through <= 2.0. | |
| Analizada | Media (6.3) | 0.29% | — | Jtsternberg Code Snippets CPT | 8/3/2025 | 17/6/2026 | The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.15% | — | Alexvtn Content Snippet ManagerAI | 16/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in alexvtn Content Snippet Manager content-snippet-manager allows Stored XSS.This issue affects Content Snippet Manager: from n/a through <= 1.1.5. | |
| Aplazada | Alta (7.1) | 0.17% | — | RIK Schennink SnippyAI | 22/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rik Schennink Snippy snippy allows Reflected XSS.This issue affects Snippy: from n/a through <= 1.4.1. | |
| Aplazada | Alta (7.6) | 0.62% | — | Alphabpo Easy Code SnippetsAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpha BPO Easy Code Snippets easy-code-snippets allows SQL Injection.This issue affects Easy Code Snippets: from n/a through <= 1.0.2. | |
| Aplazada | Media (4.3) | 0.41% | — | Ekaterir Cache Sniper FOR NginxAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in ekaterir Cache Sniper for Nginx snipe-nginx-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cache Sniper for Nginx: from n/a through <= 1.0.4.2. |