Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.47% | — | Pluginsandsnippets Simple Page Access RestrictionAI | 18/12/2024 | 17/6/2026 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level… | |
| Aplazada | Media (4.3) | 0.38% | — | Yeken Snippet ShortcodesAI | 12/12/2024 | 17/6/2026 | The Snippet Shortcodes plugin for WordPress is vulnerable to unauthorized Shortcode Deletion due to missing authorization in all versions up to, and including, 4.1.6. Note that a nonce is used as authentication here, but the value is leaked. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (6.1) | 0.29% | — | Easy Code SnippetsAI | 7/12/2024 | 17/6/2026 | The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.5) | 0.37% | — | PAT Obrien CodesnipsAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pat O’Brien codeSnips codesnips allows Stored XSS.This issue affects codeSnips: from n/a through <= 1.2. | |
| Analizada | Alta (8) | 0.44% | — | Snipeitapp Snipe-it | 12/11/2024 | 17/6/2026 | An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV file, and opens it, the injected payload will be executed, allowing… | |
| Modificada | Alta (8.7) | 0.41% | — | Snipeitapp Snipe-it | 12/11/2024 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-IT system. | |
| Analizada | Media (6.6) | 0.99% | — | Snipeitapp Snipe-it | 11/10/2024 | 17/6/2026 | Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values. | |
| Modificada | Media (6.5) | 0.25% | — | Xyzscripts Insert PHP Code Snippet | 15/8/2024 | 17/6/2026 | The Insert PHP Code Snippet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6. This is due to missing or incorrect nonce validation in the /admin/snippets.php file. This makes it possible for unauthenticated attackers to activate/deactivate and delete code… | |
| Modificada | Media (4.3) | 0.20% | — | Yeken Snippet Shortcodes | 3/7/2024 | 17/6/2026 | The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.1.4. This is due to missing or incorrect nonce validation when adding or editing shortcodes. This makes it possible for unauthenticated attackers to modify shortcodes via a forged request… | |
| Aplazada | Crítica (9.9) | 2.8% | 💥 PoC | Woody Code Snippets Insert Header Footer CodeAI | 15/6/2024 | 17/6/2026 | The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restricting the usage of the functionality to high level authorized users. This makes it… | |
| Analizada | Alta (8.1) | 0.41% | — | Snipeitapp Snipe-it | 14/6/2024 | 17/6/2026 | Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1. | |
| Modificada | Media (4.8) | 0.27% | — | Cm-wp Woody Code Snippets | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Creative Motion, Will Bontrager Software, LLC Woody ad snippets allows Stored XSS.This issue affects Woody ad snippets: from n/a through 2.4.10. | |
| Aplazada | Alta (7.1) | 0.28% | — | WP Hive Events Rich Snippets FOR GoogleAI | 17/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Hive Events Rich Snippets for Google allows Exploitation of Trusted Credentials.This issue affects Events Rich Snippets for Google: from n/a through 1.8. | |
| Analizada | Crítica (9.9) | 0.98% | — | Mainwp Code Snippets Extension | 17/5/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue affects MainWP Code Snippets Extension: from n/a through 4.0.2. | |
| Aplazada | Crítica (9.8) | 0.95% | — | Zenario Twig SnippetAITribalsystems ZenarioAI | 4/5/2024 | 17/6/2026 | Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator. | |
| Modificada | Media (4.8) | 0.34% | — | F1logic Insert PHP Code Snippet | 29/2/2024 | 17/6/2026 | The Insert PHP Code Snippet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user's name when accessing the insert-php-code-snippet-manage page in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Media (5.3) | 0.48% | — | Pluginsandsnippets Simple Page Access Restriction | 8/2/2024 | 17/6/2026 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content. | |
| Modificada | Alta (8.8) | 0.30% | — | Code Snippets | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Code Snippets Pro Code Snippets.This issue affects Code Snippets: from n/a through 3.5.0. | |
| Modificada | Media (4.3) | 0.39% | — | Cm-wp Woody Code Snippets | 20/10/2023 | 17/6/2026 | The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.9. This is due to missing or incorrect nonce validation on the runActions() function. This makes it possible for unauthenticated attackers to activate and deactivate snippets via a forged… | |
| Modificada | Alta (8.8) | 0.27% | — | Snipeitapp Snipe-it | 11/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3. | |
| Modificada | Media (5.4) | 0.61% | — | Snipeitapp Snipe-it | 6/10/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2. | |
| Modificada | Media (4.8) | 0.40% | — | Postsnippets Post Snippets | 8/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Postsnippets Post Snippets plugin <= 4.0.2 versions. | |
| Modificada | Baja (3.3) | 2.0% | 💥 PoC | Microsoft Snip & SketchMicrosoft Snipping Tool | 13/6/2023 | 17/6/2026 | Windows Snipping Tool Information Disclosure Vulnerability | |
| Modificada | Media (4.8) | 0.37% | — | Itemprop WP FOR Serp/seo Rich Snippets Project Itemprop WP FOR Serp/seo Rich Snippets | 12/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Rolands Umbrovskis itemprop WP for SERP/SEO Rich snippets plugin <= 3.5.201706131 versions. | |
| Modificada | Media (6.1) | 0.67% | — | Snippet BOX Project Snippet BOX | 11/4/2023 | 17/6/2026 | Snippet-box 1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote attackers can render arbitrary web script or HTML from the "Snippet code" form field. |