Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.43% | — | WP Service Payment Form With Authorize NETAI | 12/12/2024 | 17/6/2026 | The WP Service Payment Form With Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Alta (7.3) | 0.58% | — | Wpkube Authors ListAI | 4/12/2024 | 17/6/2026 | The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJAX action in all versions up to, and including, 2.0.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes… | |
| Aplazada | Crítica (9.8) | 1.6% | 💥 Exploit | Adapt Learning Adapt Authoring ToolAI | 25/11/2024 | 17/6/2026 | A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature. The vulnerability occurs due to insufficient validation of user input, which is used as a query in Mongoose's find()… | |
| Aplazada | Media (4.3) | 0.33% | — | Adapt Learning Adapt Authoring ToolAI | 25/11/2024 | 17/6/2026 | Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles to obtain email addresses via the "Get users" feature. The vulnerability occurs due to a flaw in permission verification logic, where the wildcard character in permitted URLs grants unintended… | |
| Aplazada | Alta (7.1) | 0.21% | — | Microkid Custom Author URLAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in microkid Custom Author URL author-slug allows Stored XSS.This issue affects Custom Author URL: from n/a through <= 2.0.1. | |
| Aplazada | Media (6.5) | 0.24% | — | Martythornley Photographer ConnectionsAI | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MartyThornley Photographer Connections photographer-connections allows Stored XSS.This issue affects Photographer Connections: from n/a through <= 1.3.1. | |
| Analizada | Alta (8) | 0.69% | — | Jenkins Authorize Project | 13/11/2024 | 17/6/2026 | Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (8.8) | 0.44% | — | Brandonwhite Author Discussion | 20/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brandon White Author Discussion author-discussion allows Blind SQL Injection.This issue affects Author Discussion: from n/a through <= 0.2.2. | |
| Modificada | Media (6.1) | 0.29% | — | Arifnezami Better Author BIO | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arifnezami Better Author Bio better-author-bio allows Reflected XSS.This issue affects Better Author Bio: from n/a through <= 2.7.10.11. | |
| Aplazada | Alta (8.8) | 0.51% | — | Publishpress AuthorsAI | 17/10/2024 | 17/6/2026 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct Object Reference to Privilege Escalation/Account Takeover in all versions up to, and including, 4.7.1 via the action_edited_author() due to missing validation on the… | |
| Aplazada | Alta (7.2) | 0.51% | — | Afthemes WP Post AuthorAI | 12/10/2024 | 17/6/2026 | The WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the linked_user_id parameter in all versions up to, and including, 3.8.1 due… | |
| Aplazada | Media (6.5) | 0.26% | — | Paul Bearne Author Avatars List BlockAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Stored XSS.This issue affects Author Avatars List/Block: from n/a through <= 2.1.21. | |
| Modificada | Alta (7.5) | 0.56% | — | Opendaylight Authentication, Authorization AND Accounting | 15/9/2024 | 17/6/2026 | An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information. | |
| Analizada | Alta (7.2) | 0.44% | — | Abinitio Authorization GatewayAbinitio Metadata HUB | 8/8/2024 | 17/6/2026 | An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code via crafted modification of server configuration. | |
| Modificada | Media (5.4) | 0.26% | — | Afthemes WP Post Author | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AF themes WP Post Author allows Stored XSS.This issue affects WP Post Author: from n/a through 3.6.7. | |
| Modificada | Media (5.4) | 0.36% | — | Mekshq Meks Smart Author Widget | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Meks Meks Smart Author Widget allows Stored XSS.This issue affects Meks Smart Author Widget: from n/a through 1.1.4. | |
| Aplazada | Media (5.3) | 0.21% | — | Authorize NET Payment Gateway FOR WoocommerceAI | 4/6/2024 | 17/6/2026 | The Authorize.net Payment Gateway For WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 8.0. This is due to the plugin not properly verifying the authenticity of the request that updates a orders payment status. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (6.1) | 0.40% | — | Oxygen XML WEB AuthorAIOxygen Content FusionAI | 14/5/2024 | 17/6/2026 | Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Cross-Site Scripting (XSS) for malicious URLs. | |
| Modificada | Media (4.3) | 0.36% | — | Afthemes WP Post Author | 6/5/2024 | 17/6/2026 | Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4. | |
| Modificada | Media (4.3) | 0.36% | — | Afthemes WP Post Author | 6/5/2024 | 17/6/2026 | Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4. | |
| Aplazada | Alta (7.1) | 0.19% | — | Nick Powers Social Author BIOAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nick Powers Social Author Bio allows Stored XSS.This issue affects Social Author Bio: from n/a through 2.4. | |
| Aplazada | Media (6.1) | 0.53% | — | Vmware Authorization ServerAI | 20/3/2024 | 17/6/2026 | Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorization Code Grant. An application is not… | |
| Modificada | Media (5.4) | 0.51% | — | Shooflysolutions (simply) Guest Author Name | 5/2/2024 | 17/6/2026 | The (Simply) Guest Author Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's post meta in all versions up to, and including, 4.34 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (7.5) | 0.65% | — | Amitzy Molongui Authorship | 5/2/2024 | 17/6/2026 | The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.4 via the 'ma_debu' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including post author emails… | |
| Modificada | Alta (8.8) | 0.44% | — | Andersthorborg Advanced Custom Fields\ | 29/12/2023 | 17/6/2026 | Missing Authorization vulnerability in Anders Thorborg.This issue affects Anders Thorborg: from n/a through 1.4.12. |