Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.26% | — | Website Chat Button Kommo IntegrationAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Kommo Website Chat Button: Kommo integration website-chat-button-kommo-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Website Chat Button: Kommo integration: from n/a through <= 1.3.1. | |
| Analizada | Alta (8.8) | 0.34% | — | IBM Webmethods Integration | 22/9/2025 | 17/6/2026 | IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to the improper validation of format string strings passed as an argument from an external source. | |
| Analizada | Media (5.4) | 0.19% | — | IBM Webmethods Integration | 22/9/2025 | 17/6/2026 | IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Aplazada | Media (6.4) | 0.24% | — | Streamweasels Kick IntegrationAI | 6/9/2025 | 17/6/2026 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChannel’ parameter in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (4.3) | 0.14% | — | Michalzagdan Trustmate IO Integration FOR WoocommerceAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in michalzagdan TrustMate.io – WooCommerce integration trustmate-io-integration-for-woocommerce allows Cross Site Request Forgery.This issue affects TrustMate.io – WooCommerce integration: from n/a through <= 1.16.0. | |
| Aplazada | Alta (8.1) | 0.71% | — | Wordpress Helpdesk IntegrationAI | 5/9/2025 | 25/9/2026 | The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.8.10 via the portal_type parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP… | |
| Aplazada | Media (6.5) | 0.21% | — | Bxslider IntegrationAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Mimoun-Prat bxSlider integration for WordPress bxslider-integration allows Stored XSS.This issue affects bxSlider integration for WordPress: from n/a through <= 1.7.2. | |
| Aplazada | Media (5.9) | 0.23% | — | Contact Form 7AICrmperks Integration FOR Contact Form 7 AND Constant ContactAIConstantcontact Constant ContactAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Integration for Contact Form 7 and Constant Contact cf7-constant-contact allows Stored XSS.This issue affects Integration for Contact Form 7 and Constant Contact: from n/a through <= 1.1.7. | |
| Aplazada | Media (5.9) | 0.23% | — | Astoundify WP Modal Popup With Cookie IntegrationAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify WP Modal Popup with Cookie Integration wp-modal-popup-with-cookie-integration allows Reflected XSS.This issue affects WP Modal Popup with Cookie Integration: from n/a through <= 2.4. | |
| Aplazada | Media (6.5) | 0.21% | — | Wetail Woocommerce Fortnox IntegrationAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wetail WooCommerce Fortnox Integration woocommerce-fortnox-integration allows Stored XSS.This issue affects WooCommerce Fortnox Integration: from n/a through <= 4.5.6. | |
| Analizada | Crítica (9.4) | 52% | 💥 Exploit | Nestjs Devtools-integration | 2/8/2025 | 17/6/2026 | Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP server with an API endpoint that uses an… | |
| Aplazada | Media (6.4) | 0.23% | — | Streamweasels Youtube IntegrationAI | 29/7/2025 | 17/6/2026 | The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.4) | 0.21% | — | Streamweasels Kick IntegrationAI | 29/7/2025 | 17/6/2026 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.23% | — | Streamweasels Twitch IntegrationAI | 29/7/2025 | 17/6/2026 | The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 0.60% | — | Dataverse IntegrationAI | 24/7/2025 | 17/6/2026 | The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within its reset_password_link REST endpoint in versions 2.77 through 2.81. The endpoint’s handler accepts a client-supplied id, email, or login, looks up that user, and calls… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Integration FOR Google Sheets AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 19/7/2025 | 17/6/2026 | The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.1 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.8) | 1.0% | — | Pipedrive IntegrationAI | 19/7/2025 | 17/6/2026 | The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.3 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (8.6) | 0.29% | — | Digitware System Integration Corporation Cross-browser Document Creation ComponentAI | 14/7/2025 | 17/6/2026 | The cross-browser document creation component produced by Digitware System Integration Corporation has a Remote Code Execution vulnerability. If a user visits a malicious website while the component is active, remote attackers can cause the system to download and execute arbitrary programs. | |
| Analizada | Media (6.7) | 0.23% | — | IBM Integration BUS | 7/7/2025 | 17/6/2026 | IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory. | |
| Analizada | Alta (8.8) | 0.28% | — | Dell Openmanage Network Integration | 30/6/2025 | 17/6/2026 | Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerability in the RADIUS protocol. An attacker with local network access could potentially exploit this vulnerability to forge a valid protocol accept message in response to a failed authentication… | |
| Aplazada | Media (5.4) | 0.30% | — | Wetail Woocommerce Fortnox IntegrationAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Wetail WooCommerce Fortnox Integration woocommerce-fortnox-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Fortnox Integration: from n/a through <= 4.5.5. | |
| Analizada | Alta (8.8) | 0.65% | — | IBM Webmethods Integration | 18/6/2025 | 17/6/2026 | IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. | |
| Analizada | Alta (7.2) | 0.49% | — | IBM Webmethods Integration | 18/6/2025 | 17/6/2026 | IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Contact Form 7AIZoho CRMAICrmperks Integration FOR Contact Form 7 AND Zoho CRM BiginAI | 17/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin cf7-zoho allows Object Injection.This issue affects Integration for Contact Form 7 and Zoho CRM, Bigin: from n/a through <= 1.3.0. | |
| Aplazada | Media (6.4) | 0.27% | — | Streamweasels Kick IntegrationAI | 14/6/2025 | 17/6/2026 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… |