Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
506 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 11% | — | Greatdevelopers Certificate | 8/2/2026 | 17/6/2026 | A vulnerability was detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This vulnerability affects unknown code of the file /restructured/csv.php. The manipulation of the argument photo results in os command injection. The attack can be executed remotely. This… | |
| Analizada | Media (5.3) | 0.25% | — | Greatdevelopers Certificate | 8/2/2026 | 17/6/2026 | A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This affects an unknown part of the file /restructured/csv.php. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. This product follows… | |
| Aplazada | Media (4.4) | 0.31% | — | Cookie Consent FOR DevelopersAI | 24/1/2026 | 17/6/2026 | The Cookie consent for developers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple settings fields in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access… | |
| Aplazada | Media (4.3) | 0.30% | — | Wpdeveloper NotificationxAI | 20/1/2026 | 17/6/2026 | The NotificationX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'regenerate' and 'reset' REST API endpoints in all versions up to, and including, 3.1.11. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Alta (7.2) | 0.28% | — | Wpdeveloper NotificationxAI | 20/1/2026 | 17/6/2026 | The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via the 'nx-preview' POST parameter in all versions up to, and including, 3.2.0. This is due to… | |
| Aplazada | Media (5.3) | 0.38% | — | Wpdeveloper Essential Addons FOR ElementorAI | 16/1/2026 | 17/6/2026 | The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 6.5.5 via the 'eael_product_quickview_popup' function. This makes it possible for unauthenticated attackers to retrieve WooCommerce product information for products with draft,… | |
| Aplazada | Media (6.5) | 0.36% | — | Wpdeveloper BetterdocsAI | 9/1/2026 | 17/6/2026 | The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in… | |
| Analizada | Media (6.5) | 0.15% | — | Wpdeveloper Essential Addons FOR Elementor | 30/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows DOM-Based XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.5.3. | |
| Modificada | Alta (7.5) | 0.56% | — | NodemailerRedhat Advanced Cluster Management FOR KubernetesRedhat Ceph StorageRedhat Developer HUB | 18/12/2025 | 7/10/2026 | A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser. | |
| Aplazada | Media (6.4) | 0.30% | — | Wpdeveloper Essential Addons FOR ElementorAI | 17/12/2025 | 17/6/2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in all versions up to, and including, 6.5.3. This is due to insufficient input sanitization and output escaping in the Event Calendar widget's custom… | |
| Aplazada | Media (4.3) | 0.32% | — | Wpdeveloper Essential BlocksAI | 17/12/2025 | 17/6/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capability checks on the get_instagram_access_token_callback, google_map_api_key_save_callback and get_siteinfo functions in all versions up to,… | |
| Analizada | Media (6.5) | 0.57% | — | Uniteddevelopers Document Reader\ | 10/12/2025 | 17/6/2026 | A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a directory traversal. | |
| Analizada | Crítica (10) | 0.91% | — | Microsoft Azure Bastion Developer | 20/11/2025 | 17/6/2026 | Azure Bastion Elevation of Privilege Vulnerability | |
| Aplazada | Alta (7.5) | 0.27% | — | Redhat 3scale Developer PortalAI | 6/11/2025 | 17/6/2026 | A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information. | |
| Aplazada | Alta (8.1) | 0.44% | — | Blanka Theme Developers Blanka - ONE Page Wordpress ThemeAI | 6/11/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File Inclusion.This issue affects Blanka - One Page WordPress Theme: from n/a through < 1.5. | |
| Modificada | Baja (2.7) | 0.23% | — | Wpdeveloper Essential Addons FOR Elementor | 31/10/2025 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a through <= 6.2.4. | |
| Aplazada | Media (6.5) | 0.41% | 💥 PoC | Instantdeveloper Instant Developer FoundationAI | 23/10/2025 | 17/6/2026 | A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected versions of the framework did not properly sanitize user-controlled input before including it in CSV exports. This issue could lead to code execution on the system where the exported CSV… | |
| Aplazada | Media (6.4) | 0.25% | — | Wpdeveloper Essential BlocksAI | 18/10/2025 | 17/6/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.30% | — | Wpdeveloper Essential BlocksAI | 18/10/2025 | 17/6/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.7.1 via the eb_save_ai_generated_image function. This makes it possible for authenticated attackers, with Author-level access and… | |
| Aplazada | Media (6.5) | 0.30% | 💥 PoC | Wpexpertdeveloper WP Private Content PlusAI | 13/10/2025 | 17/6/2026 | The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually… | |
| Aplazada | Crítica (9.3) | 0.53% | — | Google ChromeAIWEB Developer FOR ChromeAI | 8/10/2025 | 17/6/2026 | Web Developer for Chrome v0.4.9 contained malicious code that generated a domain via a DGA and fetched a remote script. The fetched script conditionally loaded follow-on modules that performed extensive ad substitution and malvertising, displayed fake “repair” alerts that redirected users to affiliate programs, and… | |
| Aplazada | Baja (1.9) | 0.27% | — | Changsha Developer Technology Iview EditorAI | 25/9/2025 | 17/6/2026 | A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of the component Markdown Handler. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was… | |
| Aplazada | Media (4.3) | 0.16% | — | Automattic DeveloperAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Automattic Developer allows Cross Site Request Forgery. This issue affects Developer: from n/a through 1.2.6. | |
| Aplazada | Media (6.6) | 0.80% | — | Developer Loggers FOR Simple HistoryAI | 17/9/2025 | 25/9/2026 | The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.5 via the enabled_loggers parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary .php files on… | |
| Aplazada | Media (5.4) | 0.14% | — | Swiftninjapro Developer Tools BlockerAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SwiftNinjaPro Developer Tools Blocker swiftninjapro-inspect-element-console-blocker allows Cross Site Request Forgery.This issue affects Developer Tools Blocker: from n/a through <= 3.2.1. |