Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.56%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
ModificadaMedia (4.3)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_visibility function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted…
ModificadaMedia (4.3)0.32%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_swap function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they can…
ModificadaMedia (4.3)0.31%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_apply_default_combination function. This makes it possible for unauthenticated attackers to manipulate products via a forged…
ModificadaMedia (4.3)0.31%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the create_profile function. This makes it possible for unauthenticated attackers to create profiles via a forged request granted they can trick a site…
ModificadaAlta (8.8)0.36%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional20/10/202317/6/2026
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_save_options function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they…
ModificadaMedia (4.3)0.53%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional18/10/202317/6/2026
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
ModificadaMedia (4.8)0.28%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional17/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7.1 versions.
ModificadaMedia (6.1)0.21%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional18/8/202317/6/2026
Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.6 versions.
ModificadaMedia (6.1)0.35%—Bund BKG Professional Ntripcaster28/6/202317/6/2026
Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44
ModificadaAlta (8.8)0.26%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Manager Professional22/6/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7 versions.
ModificadaMedia (5.4)0.36%—Pluginus Wordpress Currency Switcher Professional9/6/202317/6/2026
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcs_current_currency shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
ModificadaMedia (4.3)0.41%—Pluginus Wordpress Currency Switcher Professional9/6/202317/6/2026
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to…
ModificadaMedia (4.3)0.43%—Pluginus Wordpress Currency Switcher Professional9/6/202317/6/2026
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above,…
ModificadaAlta (8.8)0.30%—Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional28/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions.
ModificadaAlta (7.2)1.3%—Pluginus Husky - Products Filter Professional FOR Woocommerce6/2/202317/6/2026
The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
ModificadaMedia (5.4)0.50%—Pluginus FOX - Currency Switcher Professional FOR Woocommerce16/1/202317/6/2026
The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
ModificadaMedia (5.9)0.68%—Dahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 FirmwareDahuasecurity Dhi-dss4004-s2 FirmwareDahuasecurity DSS Express+127/12/202217/6/2026
Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the…
ModificadaBaja (3.7)0.64%—Dahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 FirmwareDahuasecurity Dhi-dss4004-s2 FirmwareDahuasecurity DSS Express+127/12/202217/6/2026
Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could get the traceroute results.
ModificadaMedia (5.3)0.72%—Dahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 FirmwareDahuasecurity Dhi-dss4004-s2 FirmwareDahuasecurity DSS Express+127/12/202217/6/2026
Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices in range of IPs from remote DSS Server.
ModificadaAlta (7.5)0.66%—Dahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 FirmwareDahuasecurity Dhi-dss4004-s2 FirmwareDahuasecurity DSS Express+127/12/202217/6/2026
Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated restart of remote DSS Server.
ModificadaBaja (3.7)0.43%—Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+127/12/202217/6/2026
Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could enable or disable the SSHD service.
ModificadaAlta (7.5)0.55%—Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+127/12/202217/6/2026
Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal resources by concatenating links (URL) that conform to specific rules.
ModificadaBaja (2.7)0.70%—Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+127/12/202217/6/2026
Some Dahua software products have a vulnerability of sensitive information leakage. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can obtain the debugging information.
ModificadaAlta (7.2)0.72%—Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+127/12/202217/6/2026
Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can upload arbitrary files.
Orbitaley — Vulnerabilidades