Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.6) | 0.31% | — | Themesbrand Chatvia | 16/1/2025 | 17/6/2026 | Insecure Permissions vulnerability in themesebrand Chatvia v.5.3.2 allows a remote attacker to escalate privileges via the User profile name and image upload functions. | |
| Analizada | Media (4.6) | 0.45% | — | Themesbrand Chatvia | 16/1/2025 | 17/6/2026 | An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload image function. | |
| Aplazada | Alta (7.1) | 0.26% | — | Grandslambert Featured Page WidgetAI | 13/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GrandSlambert Featured Page Widget featured-page-widget allows Reflected XSS.This issue affects Featured Page Widget: from n/a through <= 2.2. | |
| Aplazada | Media (5.3) | 0.33% | — | Imw3 MY WP BrandAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in imw3 My Wp Brand my-wp-brand.This issue affects My Wp Brand: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.5) | 0.43% | — | Perl Crypt Random SourceAI | 29/12/2024 | 17/6/2026 | The Crypt::Random::Source package before 0.13 for Perl has a fallback to the built-in rand() function, which is not a secure source of random bits. | |
| Aplazada | Media (6.5) | 0.23% | — | Yaycommerce BrandAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yaycommerce Brand brand allows Stored XSS.This issue affects Brand: from n/a through <= 1.1.6. | |
| Aplazada | Alta (7.1) | 0.21% | — | Brandt-net Display Future PostsAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in brandt-net Display Future Posts display-future-posts allows Stored XSS.This issue affects Display Future Posts: from n/a through <= 0.2.3. | |
| Aplazada | Media (5.3) | 0.50% | — | Berocket Brands FOR WoocommerceAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brands for WooCommerce: from n/a through <= 3.8.2.2. | |
| Aplazada | Media (4.3) | 1.1% | 💥 PoC | Liquidpoll Advanced Polls FOR Creators AND BrandsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a through 3.3.68. | |
| Aplazada | Alta (8.8) | 0.51% | — | DebrandingAI | 12/12/2024 | 17/6/2026 | The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the debranding_save() function in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Media (5.3) | 0.43% | — | Acato Branded Social ImagesAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Acato Branded Social Images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Branded Social Images: from n/a through 1.1.0. | |
| Aplazada | Media (6.5) | 0.30% | — | Buffercode Random BannerAI | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Random Banner random-banner allows Stored XSS.This issue affects Random Banner: from n/a through <= 4.2.12. | |
| Aplazada | Media (6.1) | 0.55% | — | Wpmudev BrandaAI | 21/11/2024 | 17/6/2026 | The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.19. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (8.8) | 0.50% | — | Deco.agency DE BrandingAI | 20/11/2024 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escalation.This issue affects de:branding: from n/a through <= 1.0.2. | |
| Aplazada | Media (6.5) | 0.36% | — | Jakeatthrive Brand MY FooterAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jakeatthrive Brand my Footer brand-my-footer allows DOM-Based XSS.This issue affects Brand my Footer: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.21% | — | Random Featured Post Plugin Random Featured PostAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in scottmydollarplancom Random Featured Post random-featured-post-plugin allows Stored XSS.This issue affects Random Featured Post: from n/a through <= 1.1.3. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Phoenixheart Ajax Random PostsAI | 16/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Phoenixheart AJAX Random Posts ajax-random-posts allows Object Injection.This issue affects AJAX Random Posts: from n/a through <= 0.3.3. | |
| Modificada | Media (5.4) | 0.26% | — | Brandevolutionco Themeshark Templates & Widgets FOR Elementor | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeshark ThemeShark Templates & Widgets for Elementor themeshark-elementor allows Stored XSS.This issue affects ThemeShark Templates & Widgets for Elementor: from n/a through <= 1.1.7. | |
| Aplazada | Alta (7.5) | 0.57% | — | Luvion Grand Elite 3 ConnectAI | 7/11/2024 | 17/6/2026 | An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Clients can authenticate themselves to the device using a username and password. These credentials can be obtained through an unauthenticated web request, e.g., for a JavaScript file. Also, the disclosed information includes the SSID and WPA2… | |
| Modificada | Alta (8.8) | 0.44% | — | Brandonwhite Author Discussion | 20/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brandon White Author Discussion author-discussion allows Blind SQL Injection.This issue affects Author Discussion: from n/a through <= 0.2.2. | |
| Modificada | Crítica (9.8) | 0.52% | — | Brandonclark Sitebuilder Dynamic Components | 20/10/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in sphoid SiteBuilder Dynamic Components sitebuilder-dynamic-components allows Object Injection.This issue affects SiteBuilder Dynamic Components: from n/a through <= 1.0. | |
| Analizada | Media (5.4) | 0.31% | — | Tahoe Debrandify | 18/10/2024 | 17/6/2026 | The Debrandify · Remove or Replace WordPress Branding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… | |
| Analizada | Media (5.4) | 0.30% | — | Gurieveugen&vitaliyshebela Branding | 18/10/2024 | 17/6/2026 | The Branding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web… | |
| Aplazada | Alta (7.5) | 0.56% | — | Hung Trang SI SB Random Posts WidgetAI | 16/10/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hung Trang Si SB Random Posts Widget sb-random-posts-widget allows PHP Local File Inclusion.This issue affects SB Random Posts Widget: from n/a through <= 1.0. | |
| Modificada | Alta (7.8) | 0.46% | — | Randygaul Cute PNG | 1/10/2024 | 17/6/2026 | cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h. |