Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
180 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.4% | — | Mainwp Child Reports | 18/10/2021 | 17/6/2026 | The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue | |
| Modificada | Media (5.7) | 0.42% | — | Catchplugins Catch Scroll Progress BARCatchplugins Catch Sticky MenuCatchplugins Catch Themes Demo ImportCatchplugins Catch Under Construction+6 | 18/10/2021 | 17/6/2026 | Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before… | |
| Modificada | Alta (8.8) | 0.77% | — | Orbisius Child Theme Creator | 16/11/2020 | 17/6/2026 | The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file. | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Media (5.4) | 1.0% | — | Wpchill Modula Image Gallery | 20/2/2020 | 17/6/2026 | A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users. | |
| Modificada | Media (6.1) | 1.9% | — | Wpchill Strong Testimonials | 3/2/2020 | 17/6/2026 | Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens. | |
| Modificada | Media (6.5) | 1.4% | — | Orbisius Child Theme Creator | 7/10/2019 | 17/6/2026 | The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification via the wp-admin/admin-ajax.php?action=orbisius_ctc_theme_editor_ajax&sub_cmd=save_file theme_1, theme_1_file, or theme_1_file_contents parameter. | |
| Modificada | Crítica (9.8) | 3.4% | — | Wpserveur WPS Child Theme Generator | 30/8/2019 | 17/6/2026 | The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal. | |
| Modificada | Crítica (9.8) | 2.6% | 💥 Exploit | Chillcreations Ccnewsletter | 17/2/2018 | 17/6/2026 | SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011-5099. | |
| Modificada | Alta (8.8) | 3.6% | 💥 Exploit | Haudenschilt Family Connections CMS | 11/1/2018 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add news via an add action to familynews.php or (2) add a prayer via an add action to prayers.php. | |
| Modificada | Media (4.3) | 0.95% | — | IBM Rational Lifecycle Integration Adapter FOR Windchill | 12/12/2014 | 17/6/2026 | Session fixation vulnerability in IBM Rational Lifecycle Integration Adapter for Windchill 1.x before 1.0.1 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Fotoschilenas Recetas DE Tragos | 21/10/2014 | 17/6/2026 | The Recetas de Tragos (aka com.wRecetasdeTragos) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Chillingo Flying FOX | 21/10/2014 | 17/6/2026 | The Flying Fox (aka com.chillingo.slyfoxfree.android.aja) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Childrens Help FOR DOC | 20/10/2014 | 17/6/2026 | The Help For Doc (aka com.childrens.physician.relations) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Mobileappcity Childcare | 19/10/2014 | 17/6/2026 | The Childcare (aka com.app_macchildcare.layout) application 1.399 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Fotoschilenas Pregnancy Tips | 16/10/2014 | 17/6/2026 | The Pregnancy Tips (aka com.rareartifact.tipsforpregnant71C80129) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Akronchildrens Care4kids | 16/10/2014 | 17/6/2026 | The Care4Kids (aka com.codetherapy.care4kids) application 1.03 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Fotoschilenas Akne Ernahrung | 15/10/2014 | 17/6/2026 | The Akne Ernahrung (aka com.rareartifact.akneernahrung72010074) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 37% | 💥 Exploit | Haudenschilt Family Connections CMS | 30/8/2012 | 16/6/2026 | dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the argv[1] parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Chillcreations MOD Ccnewsletter | 14/8/2012 | 16/6/2026 | SQL injection vulnerability in helper/popup.php in the ccNewsletter (mod_ccnewsletter) component 1.0.7 through 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Chillycms | 8/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the username field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Chillycms | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Chillcreations COM Ccinvoices | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewInv action to index.php. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Haudenschilt Family Connections CMS | 16/9/2010 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the current_user_id parameter to (1) familynews.php and (2) settings.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Ryan Haudenschilt Family Connections | 22/4/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to addressbook.php, (2) id parameter to recipes.php, (3) year parameter to register.php, (4) poll_id parameter to home.php, and (5) email parameter… |