Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

212 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.47%—Pluginsandsnippets Simple Page Access RestrictionAI18/12/202417/6/2026
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level…
AplazadaMedia (4.3)0.38%—Yeken Snippet ShortcodesAI12/12/202417/6/2026
The Snippet Shortcodes plugin for WordPress is vulnerable to unauthorized Shortcode Deletion due to missing authorization in all versions up to, and including, 4.1.6. Note that a nonce is used as authentication here, but the value is leaked. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaMedia (6.1)0.29%—Easy Code SnippetsAI7/12/202417/6/2026
The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaMedia (6.5)0.37%—PAT Obrien CodesnipsAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pat O’Brien codeSnips codesnips allows Stored XSS.This issue affects codeSnips: from n/a through <= 1.2.
AnalizadaAlta (8)0.44%—Snipeitapp Snipe-it12/11/202417/6/2026
An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. When an administrator later accesses the People Management page, exports the data as a CSV file, and opens it, the injected payload will be executed, allowing…
ModificadaAlta (8.7)0.41%—Snipeitapp Snipe-it12/11/202417/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-IT system.
AnalizadaMedia (6.6)0.99%—Snipeitapp Snipe-it11/10/202417/6/2026
Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.
ModificadaMedia (6.5)0.25%—Xyzscripts Insert PHP Code Snippet15/8/202417/6/2026
The Insert PHP Code Snippet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6. This is due to missing or incorrect nonce validation in the /admin/snippets.php file. This makes it possible for unauthenticated attackers to activate/deactivate and delete code…
ModificadaMedia (4.3)0.20%—Yeken Snippet Shortcodes3/7/202417/6/2026
The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.1.4. This is due to missing or incorrect nonce validation when adding or editing shortcodes. This makes it possible for unauthenticated attackers to modify shortcodes via a forged request…
AplazadaCrítica (9.9)2.8%💥 PoCWoody Code Snippets Insert Header Footer CodeAI15/6/202417/6/2026
The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restricting the usage of the functionality to high level authorized users. This makes it…
AnalizadaAlta (8.1)0.41%—Snipeitapp Snipe-it14/6/202417/6/2026
Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.
ModificadaMedia (4.8)0.27%—Cm-wp Woody Code Snippets8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Creative Motion, Will Bontrager Software, LLC Woody ad snippets allows Stored XSS.This issue affects Woody ad snippets: from n/a through 2.4.10.
AplazadaAlta (7.1)0.28%—WP Hive Events Rich Snippets FOR GoogleAI17/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Hive Events Rich Snippets for Google allows Exploitation of Trusted Credentials.This issue affects Events Rich Snippets for Google: from n/a through 1.8.
AnalizadaCrítica (9.9)0.98%—Mainwp Code Snippets Extension17/5/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue affects MainWP Code Snippets Extension: from n/a through 4.0.2.
AplazadaCrítica (9.8)0.95%—Zenario Twig SnippetAITribalsystems ZenarioAI4/5/202417/6/2026
Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.
ModificadaMedia (4.8)0.34%—F1logic Insert PHP Code Snippet29/2/202417/6/2026
The Insert PHP Code Snippet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user's name when accessing the insert-php-code-snippet-manage page in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
ModificadaMedia (5.3)0.48%—Pluginsandsnippets Simple Page Access Restriction8/2/202417/6/2026
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content.
ModificadaAlta (8.8)0.30%—Code Snippets18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Code Snippets Pro Code Snippets.This issue affects Code Snippets: from n/a through 3.5.0.
ModificadaMedia (4.3)0.39%—Cm-wp Woody Code Snippets20/10/202317/6/2026
The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.9. This is due to missing or incorrect nonce validation on the runActions() function. This makes it possible for unauthenticated attackers to activate and deactivate snippets via a forged…
ModificadaAlta (8.8)0.27%—Snipeitapp Snipe-it11/10/202317/6/2026
Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.
ModificadaMedia (5.4)0.61%—Snipeitapp Snipe-it6/10/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.
ModificadaMedia (4.8)0.40%—Postsnippets Post Snippets8/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Postsnippets Post Snippets plugin <= 4.0.2 versions.
ModificadaBaja (3.3)2.0%💥 PoCMicrosoft Snip & SketchMicrosoft Snipping Tool13/6/202317/6/2026
Windows Snipping Tool Information Disclosure Vulnerability
ModificadaMedia (4.8)0.37%—Itemprop WP FOR Serp/seo Rich Snippets Project Itemprop WP FOR Serp/seo Rich Snippets12/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Rolands Umbrovskis itemprop WP for SERP/SEO Rich snippets plugin <= 3.5.201706131 versions.
ModificadaMedia (6.1)0.67%—Snippet BOX Project Snippet BOX11/4/202317/6/2026
Snippet-box 1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote attackers can render arbitrary web script or HTML from the "Snippet code" form field.
Orbitaley — Vulnerabilidades