Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
205 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | Sayandatta Ultimate Social Comments Email Notification Lazy LoadAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sayan Datta Ultimate Social Comments – Email Notification & Lazy Load allows Stored XSS.This issue affects Ultimate Social Comments – Email Notification & Lazy Load: from n/a through 1.4.8. | |
| Aplazada | Media (5.9) | 0.34% | — | Wpfront Notification BARAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront Notification Bar allows Stored XSS.This issue affects WPFront Notification Bar: from n/a through 3.3.2. | |
| Modificada | Media (4.3) | 0.24% | — | Cozyvision SMS Alert Order Notifications | 13/3/2024 | 17/6/2026 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.9. This is due to missing or incorrect nonce validation on the processBulkAction function. This makes it possible for unauthenticated attackers to delete pages and… | |
| Modificada | Crítica (9.8) | 78% | 💥 Exploit | Wpdeveloper Notificationx | 27/2/2024 | 17/6/2026 | The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Modificada | Media (4.8) | 0.40% | — | Wpfront Notification BAR | 25/1/2024 | 17/6/2026 | The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notification-bar-options[custom_class]’ parameter in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Modificada | Media (5.3) | 0.46% | — | Freeamigos Manage Notification E-mails | 11/1/2024 | 17/6/2026 | The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_famne_export_settings function. This makes it possible for unauthenticated attackers to obtain plugin settings. | |
| Modificada | Media (5.4) | 0.43% | — | Webpushr WEB Push Notifications | 27/11/2023 | 17/6/2026 | The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks. | |
| Modificada | Crítica (9.8) | 0.81% | — | Medart Notification Panel Project Medart Notification Panel | 23/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Medart Health Services Medart Notification Panel allows SQL Injection. This issue affects Medart Notification Panel: through 20231123. NOTE: The vendor was contacted early about this disclosure but did not respond in… | |
| Modificada | Alta (8.8) | 0.32% | — | Webpushr WEB Push Notifications | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability leading to Local File Inclusion (LF) in Webpushr Web Push Notifications Web Push Notifications – Webpushr plugin <= 4.34.0 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Remileclercq Hide Admin Notices - Admin Notification Center Plugin | 9/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rémi Leclercq Hide admin notices – Admin Notification Center plugin <= 2.3.2 versions. | |
| Modificada | Media (4.8) | 0.36% | — | I13websolution Wordpress Publish Post Email Notification | 2/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution WordPress publish post email notification plugin <= 1.0.2.2 versions. | |
| Modificada | Media (6.5) | 0.22% | — | Disable Wordpress Update Notifications AND Auto-update Email Notifications Project Disable Wordpress Update Notifications AND Auto-update Email Notifications | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Prem Tiwari Disable WordPress Update Notifications and auto-update Email Notifications plugin <= 2.3.3 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Comment Reply Notification Project Comment Reply Notification | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Denishua Comment Reply Notification plugin <= 1.4 versions. | |
| Modificada | Media (4.3) | 0.38% | — | Wpdeveloper Notificationx | 1/7/2023 | 17/6/2026 | The NotificationX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on the generate_conversions() function. This makes it possible for unauthenticated attackers to generate conversions via a forged request… | |
| Modificada | Media (6.1) | 0.60% | 💥 PoC | Angular-ui-notification Project Angular-ui-notification | 30/6/2023 | 9/7/2026 | angular-ui-notification v0.1.0, v0.2.0, and v0.3.6 was discovered to contain a cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (6.5) | 0.54% | — | Pivotal Cloud Foundry NFS VolumePivotal Cloud Foundry NotificationsPivotal Cloud Foundry SMB Volume | 16/6/2023 | 17/6/2026 | Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications: All versions prior to 63; SMB-volume release: All versions prior to 3.1.19; cf-nfs-volume release: 5.0.X versions prior to 5.0.27, 7.1.X versions prior to 7.1.19. | |
| Modificada | Media (6.1) | 0.38% | — | Wpoperation Salert - Fake Sales Notification Woocommerce | 12/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPoperation SALERT – Fake Sales Notification WooCommerce plugin <= 1.2.1 versions. | |
| Modificada | Media (5.4) | 0.29% | — | Announcement & Notification Banner - Bulletin | 9/6/2023 | 17/6/2026 | The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce validation on the 'bulletinwp_update_bulletin_status', 'bulletinwp_update_bulletin', 'bulletinwp_update_settings', 'bulletinwp_update_status', 'bulletinwp_export_bulletins', and… | |
| Modificada | Media (4.3) | 0.51% | — | Announcement & Notification Banner - Bulletin | 9/6/2023 | 17/6/2026 | The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'bulletinwp_update_bulletin_status', 'bulletinwp_update_bulletin', 'bulletinwp_update_settings', 'bulletinwp_update_status',… | |
| Modificada | Alta (8.8) | 1.4% | — | Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+6 | 7/6/2023 | 17/6/2026 | Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber. | |
| Modificada | Alta (8.8) | 0.26% | — | Madewithfuel Better Notifications FOR WP | 26/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Made with Fuel Better Notifications for WP plugin <= 1.9.2 versions. | |
| Modificada | Media (6.1) | 0.54% | — | Pushassist Push Notifications | 15/5/2023 | 17/6/2026 | The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (4.3) | 0.25% | — | Hasthemes WC Sales Notification | 27/3/2023 | 17/6/2026 | The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | |
| Modificada | Alta (8.8) | 0.32% | — | Freeamigos Manage Notification E-mails | 28/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in Virgial Berveling's Manage Notification E-mails plugin <= 1.8.2 on WordPress. | |
| Modificada | Media (4.8) | 0.53% | — | Jeeng Push Notifications Project Jeeng Push Notifications | 28/11/2022 | 17/6/2026 | The Jeeng Push Notifications WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) |