Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.13% | — | Plugin Updates BlockerAI | 11/9/2025 | 17/6/2026 | The Plugin updates blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the pub_save action handler. This makes it possible for unauthenticated attackers to disable or enable plugin updates via a… | |
| Aplazada | Alta (8.8) | 0.12% | — | Altiris Core Agent UpdaterAI | 11/9/2025 | 30/9/2026 | The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking. | |
| Analizada | Alta (7.8) | 0.42% | — | Microsoft Autoupdate | 9/9/2025 | 17/6/2026 | Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (6.5) | 0.17% | — | Mulscully Todays Date InserterAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mulscully Today's Date Inserter todays-date-inserter allows Stored XSS.This issue affects Today's Date Inserter: from n/a through <= 1.2.1. | |
| Aplazada | Media (6.5) | 0.17% | — | Ablancodev Woocommerce Notify Updated ProductAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ablancodev Woocommerce Notify Updated Product woocommerce-notify-updated-product allows Stored XSS.This issue affects Woocommerce Notify Updated Product: from n/a through <= 1.6. | |
| Aplazada | Media (4.3) | 0.24% | — | Tychesoftwares Order Delivery Date FOR WoocommerceAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery Date for WooCommerce: from n/a through <= 4.1.0. | |
| Aplazada | Media (6.4) | 0.25% | — | Intl Datetime CalendarAI | 16/8/2025 | 17/6/2026 | The Intl DateTime Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos+11 | 29/7/2025 | 21/9/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. | |
| Aplazada | Media (5.5) | 0.27% | — | Codeermeneer Companion Auto UpdateAI | 15/7/2025 | 17/6/2026 | The Companion Auto Update plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘update_delay_days’ parameter in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access,… | |
| Analizada | Media (4.3) | 0.28% | — | Tychesoftwares Order Delivery Date FOR Woocommerce | 11/7/2025 | 17/6/2026 | The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information | |
| Analizada | Alta (8.1) | 0.40% | — | Updategadh Real Estate Management | 18/6/2025 | 17/6/2026 | Real Estate Management 1.0 is vulnerable to Cross Site Scripting (XSS) in /store/index.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64+16 | 12/6/2025 | 18/9/2026 | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input. | |
| Aplazada | Media (6.9) | 0.13% | — | UpdatenaviAIUpdatenaviinstallserviceAI | 12/6/2025 | 17/6/2026 | Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be executed. | |
| Analizada | Alta (7.8) | 0.39% | — | Microsoft Autoupdate | 10/6/2025 | 17/6/2026 | Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (5.9) | 0.34% | — | Abup Cloud Update PlatformAI | 23/5/2025 | 17/6/2026 | Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation by submitting the malicious JWT to a vulnerable method exposed on the cloud platform. If the exploit is successful, the user can escalate privileges to access any device managed by the ABUP Cloud… | |
| Analizada | Alta (8.8) | 0.58% | — | Microsoft Edge Update | 22/5/2025 | 17/6/2026 | Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.1) | 0.26% | — | Tychesoftwares Order Delivery Date FOR Woocommerce | 20/5/2025 | 17/6/2026 | The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Media (4.3) | 0.14% | — | Javier Revilla ValidatecertifyAI | 16/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Javier Revilla ValidateCertify validar-certificados-de-cursos allows Cross Site Request Forgery.This issue affects ValidateCertify: from n/a through <= 1.6.4. | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Ethernet Network Adapter E810 NVM Update UtilityAI | 13/5/2025 | 17/6/2026 | Insecure inherited permissions in the NVM Update Utility for some Intel(R) Ethernet Network Adapter E810 Series before version 4.60 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.3) | 0.28% | — | Patch MY PC Home UpdaterAI | 9/5/2025 | 17/6/2026 | A vulnerability was found in Patch My PC Home Updater up to 5.1.3.0. It has been rated as critical. This issue affects some unknown processing in the library… | |
| Analizada | Crítica (9.8) | 1.4% | — | Tychesoftwares Order Delivery Date PRO FOR Woocommerce | 26/4/2025 | 17/6/2026 | The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update options relevant to the Order Delivery Date WordPress plugin before 12.3.1. This leads to attackers being able to modify the… | |
| Aplazada | Media (5.9) | 0.22% | — | Devignstudiosltd Covid-19 Coronavirus Update Your CustomersAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devignstudiosltd COVID-19 (Coronavirus) Update Your Customers covid-19-alert allows Stored XSS.This issue affects COVID-19 (Coronavirus) Update Your Customers: from n/a through <= 1.5.1. | |
| Aplazada | Media (6.5) | 0.27% | — | Padam Shankhadev Nepali-post-dateAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Padam Shankhadev Nepali Post Date nepali-post-date allows Stored XSS.This issue affects Nepali Post Date: from n/a through <= 5.1.1. | |
| Aplazada | Media (6.5) | 0.27% | — | Addonspress Nepali Date ConverterAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonsPress Nepali Date Converter nepali-date-converter allows Stored XSS.This issue affects Nepali Date Converter: from n/a through <= 2.0.8. | |
| Aplazada | Alta (8.8) | 0.37% | — | Aweos Gmbh Email Notifications FOR UpdatesAI | 15/4/2025 | 17/6/2026 | Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Privilege Escalation.This issue affects Email Notifications for Updates: from n/a through <= 1.1.6. |