Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.91% | — | Ali2woo Aliexpress Dropshipping With Alinext | 19/6/2024 | 17/6/2026 | The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_save_image function in all versions up to, and including, 3.3.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Analizada | Alta (8.8) | 1.2% | — | Dropbox Desktop | 13/6/2024 | 17/6/2026 | Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Modificada | Media (5.3) | 0.31% | — | Opmc Woocommerce Dropshipping | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in OPMC WooCommerce Dropshipping.This issue affects WooCommerce Dropshipping: from n/a through 5.0.4. | |
| Aplazada | Crítica (9.8) | 14% | 💥 Exploit | Country State City Dropdown CF7AI | 22/5/2024 | 17/6/2026 | The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.76% | — | Sharkdropship DropshippingAI | 14/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Woo product importer Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a through 2.1.1. | |
| Aplazada | Media (4.3) | 0.37% | — | Eprolo DropshippingAI | 8/5/2024 | 17/6/2026 | Missing Authorization vulnerability in EPROLO EPROLO Dropshipping.This issue affects EPROLO Dropshipping: from n/a through 1.7.1. | |
| Aplazada | Media (6.5) | 0.25% | — | RaindropsAI | 8/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nobita allows Stored XSS.This issue affects raindrops: from n/a through 1.600. | |
| Modificada | Alta (7.5) | 0.71% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 2/5/2024 | 17/6/2026 | The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory. This makes it possible for unauthenticated attackers to extract sensitive… | |
| Aplazada | Media (4.3) | 0.45% | — | Country State City Dropdown CF7AI | 2/5/2024 | 17/6/2026 | The Country State City Dropdown CF7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tc_csca_patch_settings function in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with subscriber access and above, to add… | |
| Aplazada | Media (5.9) | 0.34% | — | Jeroen Peters Navigation Menu AS Dropdown WidgetAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Navigation menu as Dropdown Widget navigation-menu-as-dropdown-widget.This issue affects Navigation menu as Dropdown Widget: from n/a through <= 1.3.4. | |
| Aplazada | Media (5.3) | 0.40% | — | Sharkdropship FOR Aliexpress Dropshipping AND AffiliateAI | 2/4/2024 | 17/6/2026 | The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wads_removeProductFromShop() function in all versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to delete… | |
| Modificada | Media (5.4) | 0.19% | — | Backie Wp-eggdrop | 29/3/2024 | 17/6/2026 | The WP-Eggdrop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing or incorrect nonce validation on the wpegg_updateOptions() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged… | |
| Modificada | Media (4.8) | 0.32% | — | Backie Wp-eggdrop | 29/3/2024 | 17/6/2026 | The WP-Eggdrop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Media (6.5) | 0.31% | — | Alordiel Dropdown Multisite SelectorAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alordiel Dropdown Multisite selector allows Stored XSS.This issue affects Dropdown Multisite selector: from n/a through 0.9.2. | |
| Modificada | Crítica (9.8) | 0.66% | — | Dropbox Samly | 11/2/2024 | 17/6/2026 | In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry. | |
| Modificada | Crítica (9.8) | 0.60% | — | Codedropz Drag AND Drop Multiple File Upload FOR Woocommerce | 21/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8. | |
| Modificada | Crítica (9.8) | 0.94% | — | Zendrop | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Zendrop Zendrop – Global Dropshipping.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0. | |
| Modificada | Alta (8.8) | 0.64% | — | Amadercode Dropshipping & Affiliation With Amazon | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in AmaderCode Lab Dropshipping & Affiliation with Amazon.This issue affects Dropshipping & Affiliation with Amazon: from n/a through 2.1.2. | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Crítica (9.8) | 1.8% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 22/11/2023 | 17/6/2026 | The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files… | |
| Modificada | Media (5.4) | 0.54% | — | Stevenhenty Drop Shadow Boxes | 22/11/2023 | 17/6/2026 | The Drop Shadow Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dropshadowbox' shortcode in versions up to, and including, 1.7.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Crítica (9.8) | 0.69% | — | Zendrop | 3/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – Global Dropshipping zendrop-dropshipping-and-fulfillment allows SQL Injection.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0. | |
| Modificada | Alta (7.8) | 0.29% | — | Inkdrop | 30/10/2023 | 17/6/2026 | Inkdrop prior to v5.6.0 allows a local attacker to conduct a code injection attack by having a legitimate user open a specially crafted markdown file. | |
| Modificada | Crítica (9.8) | 1.1% | — | Hynotech Dropbox Folder Share | 20/10/2023 | 17/6/2026 | The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to… | |
| Modificada | Media (5.4) | 0.45% | — | Codedropz Drag AND Drop Multiple File Uploader | 16/10/2023 | 17/6/2026 | The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts. |