Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 14/8/2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 14/8/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 14/8/2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 14/8/2026 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 14/8/2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 14/8/2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 14/8/2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 13/8/2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 11/8/2026 | 13/8/2026 | Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.43% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 11/8/2026 | 14/8/2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 11/8/2026 | 14/8/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Pendiente de análisis | Media (6.6) | 0.33% | — | Glibc WordexpAI | 10/8/2026 | 3/9/2026 | When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was… | |
| Pendiente de análisis | Alta (8.9) | 0.89% | 💥 Exploit | WordpressAI | 7/8/2026 | 3/9/2026 | WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social… | |
| Aplazada | Alta (7.5) | 0.44% | — | Wpexperts Password ProtectedAI | 7/8/2026 | 26/8/2026 | The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content… | |
| Aplazada | Alta (7.1) | 0.25% | — | Facebook FOR WordpressAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wordpress File UploadAI | 6/8/2026 | 12/8/2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. | |
| Aplazada | Alta (8.1) | 1.2% | — | Keywordrush Content EGGAI | 5/8/2026 | 12/8/2026 | The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11.3.0. This is due to insufficient validation of the 'img_file' field within the cegg_data post metadata: the value passes only through… | |
| Aplazada | Media (6.5) | 0.27% | — | Mailgun FOR WordpressAI | 31/7/2026 | 26/8/2026 | The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's… | |
| Aplazada | Alta (7.5) | 0.41% | — | Wp-feedstats Wordpress PluginAI | 31/7/2026 | 26/8/2026 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes. | |
| Analizada | Alta (7.4) | 0.13% | — | Devolutions Password Manager | 29/7/2026 | 21/8/2026 | Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate. | |
| Aplazada | Alta (8.8) | 0.51% | — | WP Password PolicyAI | 28/7/2026 | 29/7/2026 | The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally calls `WP_User::set_role()` with the… | |
| Pendiente de análisis | Alta (8.6) | 0.25% | — | Wordpress Coding StandardsAI | 28/7/2026 | 9/9/2026 | WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as… | |
| Aplazada | Alta (7.2) | 1.2% | — | Wordplus Better MessagesAI | 28/7/2026 | 28/7/2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.22% | — | Wordpress Social Login AND RegisterAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | |
| Aplazada | Alta (7.6) | 0.48% | — | Office Word MCP ServerAI | 23/7/2026 | 23/7/2026 | Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read arbitrary .docx files or create and overwrite .docx files outside the intended working directory. Attackers can supply absolute paths or ../… |