Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
403.004 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.29% | — | Salonbookingsystem Salon Booking SystemAI | 6/10/2026 | 6/10/2026 | Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Wpmailster WP MailsterAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions. | |
| Aplazada | Media (6.5) | 0.35% | — | WordpressAI | 6/10/2026 | 6/10/2026 | Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions. | |
| Aplazada | Alta (8.8) | 0.32% | — | WP User ProfilesAI | 6/10/2026 | 6/10/2026 | Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions. | |
| Aplazada | Media (5.3) | 0.32% | — | Zero SpamAI | 6/10/2026 | 6/10/2026 | Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Epiph Form BlockAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions. | |
| Aplazada | Alta (7.2) | 0.32% | — | Codection Import AND Export Users AND CustomersAI | 6/10/2026 | 6/10/2026 | Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions. | |
| Aplazada | Alta (8.1) | 0.26% | — | HaakenAI | 6/10/2026 | 6/10/2026 | Unauthenticated PHP Object Injection in Haaken <= 1.5 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | GivewpAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Thimpress LearnpressAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions. | |
| Aplazada | Alta (7.3) | 0.29% | — | PicuAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in picu <= 3.10.1 versions. | |
| Aplazada | Alta (8.1) | 0.28% | — | GivewpAI | 6/10/2026 | 6/10/2026 | Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions. | |
| Aplazada | Media (6.9) | 0.41% | — | Stylemixthemes MotorsAI | 6/10/2026 | 6/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124. | |
| Aplazada | Alta (7.1) | 0.24% | — | PicuAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | CharitableAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions. | |
| Aplazada | Alta (7.2) | 0.32% | — | Blubrry PowerpressAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions. | |
| Aplazada | Alta (7.5) | 0.30% | — | GroundhoggAI | 6/10/2026 | 6/10/2026 | Unauthenticated Sensitive Data Exposure in Groundhogg <= 4.8.3 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Tomlister Payflex Payment GatewayAI | 6/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1. | |
| Aplazada | Alta (8.5) | 0.22% | — | Wpo365AI | 6/10/2026 | 6/10/2026 | Subscriber Broken Access Control in WPO365 <= 44.1 versions. | |
| Aplazada | Alta (7.5) | 0.30% | — | Xserver MigratorAI | 6/10/2026 | 6/10/2026 | Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions. | |
| Aplazada | Media (5.3) | 0.26% | — | Webfactoryltd Advanced Google RecaptchaAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions. | |
| Aplazada | Crítica (9.3) | 0.37% | — | SchmoozeAI | 6/10/2026 | 6/10/2026 | This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys.… | |
| Aplazada | Media (6.9) | 0.26% | — | Sourcecodester Simple Student Information SystemAI | 6/10/2026 | 6/10/2026 | A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in sql injection. The attack can be initiated remotely. | |
| Pendiente de análisis | Media (5.4) | 0.19% | — | KeycloakAI | 6/10/2026 | 6/10/2026 | A flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities to obtain security tokens. The issue occurs because the flow fails to check the minimum authentication level required by a client… | |
| Aplazada | Media (6.5) | 0.16% | — | Elegro Crypto PaymentAI | 6/10/2026 | 6/10/2026 | The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been… |