Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

182 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.47%—Woocoomerce Aweber Newsletter SubscriptionAI2/5/202417/6/2026
Missing Authorization vulnerability in Kestrel WooCommerce AWeber Newsletter Subscription.This issue affects WooCommerce AWeber Newsletter Subscription: from n/a through 4.0.2.
AplazadaMedia (4.3)0.20%—Cozmoslabs Paid Member SubscriptionsAI24/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Paid Member Subscriptions.This issue affects Paid Member Subscriptions: from n/a through 2.11.0.
AnalizadaAlta (8.8)0.71%—Oretnom23 Simple Subscription Website24/4/202417/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Simple Subscription Website 1.0. Affected is an unknown function of the file view_application.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to…
AnalizadaCrítica (9.1)0.61%—Oretnom23 Simple Subscription Website28/3/202417/6/2026
A vulnerability was found in SourceCodester Simple Subscription Website 1.0 and classified as critical. This issue affects some unknown processing of the file manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public…
AnalizadaAlta (8.8)0.68%—Oretnom23 Simple Subscription Website28/3/202417/6/2026
A vulnerability classified as critical was found in SourceCodester Simple Subscription Website 1.0. Affected by this vulnerability is an unknown functionality of the file manage_plan.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to…
AnalizadaAlta (8.8)0.68%—Oretnom23 Simple Subscription Website28/3/202417/6/2026
A vulnerability classified as critical has been found in SourceCodester Simple Subscription Website 1.0. Affected is an unknown function of the file Actions.php. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…
ModificadaMedia (6.1)0.33%—I13websolution Email Subscription Popup17/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution Email Subscription Popup allows Stored XSS.This issue affects Email Subscription Popup: from n/a through 1.2.20.
ModificadaAlta (8.8)0.23%—Cozmoslabs Paid Membership Subscriptions15/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Paid Member Subscriptions.This issue affects Paid Member Subscriptions: from n/a through 2.10.4.
ModificadaMedia (4.3)0.53%—Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions29/2/202417/6/2026
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the creating_pricing_table_page function in all versions up to, and including, 2.11.1. This makes it possible…
ModificadaMedia (5.3)0.52%—Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions29/2/202417/6/2026
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pms_stripe_connect_handle_authorization_return function in all versions up to, and including, 2.11.1.…
ModificadaMedia (6.1)0.44%—I13websolution Email Subscription Popup8/1/202417/6/2026
The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (7.5)0.57%—Automattic Woocommerce Subscriptions20/12/202317/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a through 5.1.2.
ModificadaMedia (6.1)0.37%—I13websolution Email Subscription Popup6/12/202317/6/2026
The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP_REFERER header in all versions up to, and including, 1.2.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
ModificadaAlta (7.8)0.24%—Redhat Subscription-managerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+1623/8/202317/6/2026
A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a…
ModificadaMedia (6.1)0.41%—I13websolution Email Subscription Popup14/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <= 1.2.16 versions.
ModificadaMedia (4.8)0.37%—Tipsandtricks-hq Category Specific RSS Feed Subscription12/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.2 versions.
ModificadaAlta (8.8)0.27%—Tipsandtricks-hq Category Specific RSS Feed Subscription3/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.1 versions.
ModificadaAlta (8.8)0.25%—Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible5/4/202317/6/2026
The WCFM Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying knowledge bases, modifying…
ModificadaAlta (8.8)0.64%—Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible5/4/202317/6/2026
The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 due to missing capability checks on various AJAX actions. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to perform a…
ModificadaAlta (7.2)0.71%—Paymattic Simple Payment Donations & Subscriptions5/9/202217/6/2026
The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks against admins
ModificadaMedia (6.1)0.61%—Subscription-manager Project Subscription-manager15/6/202217/6/2026
Subscription-Manager v1.0 /main.js has a cross-site scripting (XSS) vulnerability in the machineDetail parameter.
ModificadaCrítica (9.8)1.6%—Oretnom23 Simple Subscription Website21/3/202217/6/2026
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.
ModificadaCrítica (9.8)8.5%💥 ExploitWclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible21/12/202117/6/2026
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections
ModificadaAlta (8.8)1.3%—Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible8/11/202117/6/2026
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using…
ModificadaMedia (6.1)1.4%💥 PoCOretnom23 Simple Subscription Website3/11/202117/6/2026
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter in plan_application.
Orbitaley — Vulnerabilidades