Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
189 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.31% | — | Sesami Cash Point & Transport Optimizer | 25/12/2023 | 17/6/2026 | An issue was discovered in SESAMI planfocus CPTO (Cash Point & Transport Optimizer) 6.3.8.6 718. There is XSS via the Name field when modifying a client. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Ewww Image Optimizer | 30/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a through 7.2.0. | |
| Modificada | Alta (8.8) | 0.31% | — | Passionatebrains ADD Expires Headers & Optimized Minify | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Passionate Brains Add Expires Headers & Optimized Minify plugin <= 2.7 versions. | |
| Modificada | Media (4.8) | 0.42% | — | Optimizely CMS | 14/11/2023 | 17/6/2026 | Optimizely CMS UI before v12.16.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Admin panel. | |
| Modificada | Alta (8.8) | 0.26% | — | Cagewebdev Optimize Database After Deleting Revisions | 4/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CAGE Web Design | Rolf van Gelder Optimize Database after Deleting Revisions plugin <= 5.1 versions. | |
| Modificada | Media (6.1) | 0.85% | 💥 Exploit | 10web Image Optimizer | 16/8/2023 | 17/6/2026 | The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a… | |
| Modificada | Crítica (9.8) | 0.62% | — | Ai-dev Aioptimizedcombinations | 3/8/2023 | 17/6/2026 | ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php. | |
| Modificada | Media (4.3) | 0.38% | — | Ewww Image Optimizer | 12/7/2023 | 17/6/2026 | The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a… | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Srbtranslatin Project SrbtranslatinUpdraftplus Wp-optimize | 10/7/2023 | 17/6/2026 | The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability. | |
| Modificada | Media (6.5) | 0.64% | — | Rapidload Power-up FOR Autoptimize | 22/6/2023 | 17/6/2026 | Auth. (subscriber+) SQL Injection (SQLi) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize plugin <= 1.6.35 versions. | |
| Modificada | Baja (2.7) | 0.66% | — | 10web Image Optimizer | 30/5/2023 | 17/6/2026 | The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root. | |
| Modificada | Media (4.8) | 0.47% | — | Autoptimize | 30/5/2023 | 17/6/2026 | The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export, allowing high privileged users (such as an administrator) to inject arbitrary javascript into the admin panel, even when the unfiltered_html capability is disabled, such as in a multisite setup. | |
| Modificada | Media (4.8) | 0.37% | — | JCH Optimize Project JCH Optimize | 6/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Samuel Marshall JCH Optimize plugin <= 3.2.2 versions. | |
| Modificada | Alta (7.5) | 0.84% | — | Apng Optimizer Project Apng Optimizer | 17/4/2023 | 17/6/2026 | APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png. | |
| Modificada | Alta (8.8) | 0.22% | — | Wordpress Ping Optimizer Project Wordpress Ping Optimizer | 27/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pankaj Jha WordPress Ping Optimizer plugin <= 2.35.1.2.3 versions. | |
| Modificada | Media (6.3) | 0.21% | — | Rapidload Power-up FOR Autoptimize | 17/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on its AJAX actions. This makes it possible for unauthenticated attackers to invoke those functions, via forged request… | |
| Modificada | Media (4.3) | 0.23% | — | A2hosting A2 Optimized | 13/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in A2 Hosting A2 Optimized WP plugin <= 3.0.4 versions. | |
| Modificada | Media (4.3) | 0.32% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_page_cache function. This makes it possible for unauthenticated attackers to clear the plugin's cache via a… | |
| Modificada | Media (4.3) | 0.31% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the queue_posts function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a… | |
| Modificada | Media (4.3) | 0.31% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the uucss_update_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache via… | |
| Modificada | Media (4.3) | 0.31% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the attach_rule function. This makes it possible for unauthenticated attackers to modify the plugin's cache via a… | |
| Modificada | Media (4.3) | 0.31% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ucss_connect function. This makes it possible for unauthenticated attackers to connect the site to a new license… | |
| Modificada | Media (4.3) | 0.31% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate function. This makes it possible for unauthenticated attackers to turn off caching via a forged… | |
| Modificada | Media (4.3) | 0.31% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_uucss_logs function. This makes it possible for unauthenticated attackers to clear plugin logs via a forged… | |
| Modificada | Media (4.3) | 0.55% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the uucss_update_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to update caching rules. |