Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
155 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.47% | — | Gvectors Wpforo Forum | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.2.3. | |
| Modificada | Media (5.4) | 0.34% | — | Gvectors Wpdiscuz | 23/4/2024 | 17/6/2026 | The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an uploaded image in all versions up to, and including, 7.6.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and… | |
| Analizada | Media (5.4) | 0.37% | — | Sterlinghamilton Scalable Vector Graphics (svg) | 18/3/2024 | 17/6/2026 | The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |
| Modificada | Media (4.8) | 0.34% | — | Gvectors Wpdiscuz | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team Comments – wpDiscuz allows Stored XSS.This issue affects Comments – wpDiscuz: from n/a through 7.6.12. | |
| Modificada | Media (4.3) | 0.38% | — | Mintplexlabs Vector Admin | 25/1/2024 | 17/6/2026 | Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email address. | |
| Modificada | Media (6.5) | 0.52% | — | Gvectors Wpdiscuz | 20/12/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a through 7.6.3. | |
| Modificada | Alta (8.8) | 0.27% | — | Gvectors Woodiscuz - Woocommerce Comments | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0. | |
| Modificada | Alta (8.8) | 0.27% | — | Gvectors Wpforo Forum | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a through 2.2.6. | |
| Modificada | Media (5.4) | 0.38% | — | Gvectors Wpforo Forum | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team wpForo Forum allows Stored XSS.This issue affects wpForo Forum: from n/a through 2.2.3. | |
| Modificada | Media (4.3) | 0.48% | — | Jenkins Neuvector Vulnerability Scanner | 29/11/2023 | 17/6/2026 | A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password. | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Neuvector Vulnerability ScannerJenkins JiraJenkins Google Compute EngineJenkins Matlab | 29/11/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password. | |
| Modificada | Alta (8.8) | 0.26% | — | Gvectors Wpdiscuz | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions. | |
| Modificada | Media (6.1) | 0.37% | — | Gvectors Wpdiscuz | 6/11/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions. | |
| Modificada | Media (5.3) | 0.48% | — | Gvectors Wpdiscuz | 20/10/2023 | 17/6/2026 | The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a post. | |
| Modificada | Media (5.3) | 0.48% | — | Gvectors Wpdiscuz | 20/10/2023 | 17/6/2026 | The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a comment. | |
| Modificada | Media (6.1) | 0.84% | 💥 Exploit | Gvectors Wpforo Forum | 24/7/2023 | 17/6/2026 | The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability. | |
| Modificada | Media (4.8) | 0.39% | — | Gvectors Wpview | 19/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Display Custom Fields – wpView plugin <= 1.3.0 versions. | |
| Modificada | Alta (8.8) | 61% | — | Gvectors Wpforo Forum | 9/6/2023 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it… | |
| Modificada | Media (4.8) | 0.37% | — | Gvectors Woodiscuz - Woocommerce Comments | 28/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments woodiscuz-woocommerce-comments allows Stored XSS.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.2.9. | |
| Modificada | Media (5.3) | 0.32% | — | Jenkins Neuvector Vulnerability Scanner | 12/4/2023 | 17/6/2026 | Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server. | |
| Modificada | Alta (7.5) | 0.62% | — | Lfprojects Vector Packet Processor | 28/3/2023 | 17/6/2026 | FP.io VPP (Vector Packet Processor) 22.10, 22.06, 22.02, 21.10, 21.06, 21.01, 20.09, 20.05, 20.01, 19.08, and 19.04 Generates a Predictable IV with CBC Mode. | |
| Modificada | Media (5.5) | 0.24% | — | Pig-vector Project Pig-vector | 21/12/2022 | 17/6/2026 | A vulnerability was found in pig-vector and classified as problematic. Affected by this issue is the function LogisticRegression of the file src/main/java/org/apache/mahout/pig/LogisticRegression.java. The manipulation leads to insecure temporary file. The attack needs to be approached locally. The name of the patch… | |
| Modificada | Alta (8.8) | 0.66% | — | Gvectors Wpdiscuz | 18/11/2022 | 17/6/2026 | Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress. | |
| Modificada | Alta (8.8) | 0.96% | — | Gvectors Wpforo Forum | 17/11/2022 | 17/6/2026 | Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. | |
| Modificada | Alta (8.8) | 0.47% | — | Gvectors Wpforo Forum | 17/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. |