Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.56% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products. | |
| Modificada | Media (4.3) | 0.32% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_visibility function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted… | |
| Modificada | Media (4.3) | 0.32% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_swap function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they can… | |
| Modificada | Media (4.3) | 0.31% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_apply_default_combination function. This makes it possible for unauthenticated attackers to manipulate products via a forged… | |
| Modificada | Media (4.3) | 0.31% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the create_profile function. This makes it possible for unauthenticated attackers to create profiles via a forged request granted they can trick a site… | |
| Modificada | Alta (8.8) | 0.36% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 20/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_save_options function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they… | |
| Modificada | Media (4.3) | 0.53% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 18/10/2023 | 17/6/2026 | The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products. | |
| Modificada | Media (4.8) | 0.28% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 17/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7.1 versions. | |
| Modificada | Media (6.1) | 0.21% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 18/8/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.6 versions. | |
| Modificada | Media (6.1) | 0.35% | — | Bund BKG Professional Ntripcaster | 28/6/2023 | 17/6/2026 | Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44 | |
| Modificada | Alta (8.8) | 0.26% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Manager Professional | 22/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcs_current_currency shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Modificada | Media (4.3) | 0.41% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to… | |
| Modificada | Media (4.3) | 0.43% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above,… | |
| Modificada | Alta (8.8) | 0.30% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions. | |
| Modificada | Alta (7.2) | 1.3% | — | Pluginus Husky - Products Filter Professional FOR Woocommerce | 6/2/2023 | 17/6/2026 | The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present. | |
| Modificada | Media (5.4) | 0.50% | — | Pluginus FOX - Currency Switcher Professional FOR Woocommerce | 16/1/2023 | 17/6/2026 | The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Media (5.9) | 0.68% | — | Dahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 FirmwareDahuasecurity Dhi-dss4004-s2 FirmwareDahuasecurity DSS Express+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the… | |
| Modificada | Baja (3.7) | 0.64% | — | Dahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 FirmwareDahuasecurity Dhi-dss4004-s2 FirmwareDahuasecurity DSS Express+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could get the traceroute results. | |
| Modificada | Media (5.3) | 0.72% | — | Dahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 FirmwareDahuasecurity Dhi-dss4004-s2 FirmwareDahuasecurity DSS Express+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices in range of IPs from remote DSS Server. | |
| Modificada | Alta (7.5) | 0.66% | — | Dahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 FirmwareDahuasecurity Dhi-dss4004-s2 FirmwareDahuasecurity DSS Express+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated restart of remote DSS Server. | |
| Modificada | Baja (3.7) | 0.43% | — | Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could enable or disable the SSHD service. | |
| Modificada | Alta (7.5) | 0.55% | — | Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal resources by concatenating links (URL) that conform to specific rules. | |
| Modificada | Baja (2.7) | 0.70% | — | Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of sensitive information leakage. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can obtain the debugging information. | |
| Modificada | Alta (7.2) | 0.72% | — | Dahuasecurity DSS ExpressDahuasecurity DSS ProfessionalDahuasecurity Dhi-dss7016d-s2 FirmwareDahuasecurity Dhi-dss7016dr-s2 Firmware+1 | 27/12/2022 | 17/6/2026 | Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can upload arbitrary files. |