Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
512 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.29% | — | Templatesnext ToolkitAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marsian TemplatesNext ToolKit templatesnext-toolkit allows Stored XSS.This issue affects TemplatesNext ToolKit: from n/a through <= 3.2.9. | |
| Aplazada | Media (5.4) | 0.17% | — | Uncannyowl Uncanny Toolkit PRO FOR LearndashAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Cross Site Request Forgery.This issue affects Uncanny Toolkit Pro for LearnDash: from n/a before 4.1.4.1. | |
| Aplazada | Crítica (9.1) | 1.3% | 💥 PoC | Ludwig YOU WpmastertoolkitAI | 2/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Upload a Web Shell to a Web Server.This issue affects WPMasterToolKit: from n/a through <= 1.13.1. | |
| Aplazada | Media (4.9) | 0.54% | — | Ludwig YOU WpmastertoolkitAI | 2/1/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Path Traversal.This issue affects WPMasterToolKit: from n/a through <= 1.13.1. | |
| Aplazada | Crítica (9.8) | 0.68% | — | Inspry Agency ToolkitAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in inspry Agency Toolkit agency-toolkit allows Privilege Escalation.This issue affects Agency Toolkit: from n/a through <= 1.0.23. | |
| Aplazada | Alta (7.5) | 0.47% | — | Tobias Keller Wp-nerd ToolkitAI | 16/12/2024 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tobias Keller WP-NERD Toolkit wp-nerd-toolkit.This issue affects WP-NERD Toolkit: from n/a through <= 1.1. | |
| Analizada | Media (5.1) | 0.21% | — | Percona Toolkit | 15/12/2024 | 17/6/2026 | Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption Brute Forcing.This issue affects percona-toolkit: 3.6.0. | |
| Aplazada | Media (5.4) | 0.57% | — | Madfishdigital Bulk Noindex AND Nofollow ToolkitAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 1.5. | |
| Aplazada | Media (6.5) | 0.60% | — | Uncannyowl Uncanny Toolkit FOR LearndashAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.6.4.3. | |
| Aplazada | Media (6.1) | 0.45% | — | Servit Affiliate-toolkitAI | 21/11/2024 | 17/6/2026 | The affiliate-toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 3.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they… | |
| Aplazada | Media (6.5) | 0.35% | — | Id-sk Idsk-toolkitAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IDSK team ID-SK Toolkit idsk-toolkit allows Stored XSS.This issue affects ID-SK Toolkit: from n/a through <= 1.7.2. | |
| Analizada | Media (5.2) | 0.16% | — | Intel Oneapi Base ToolkitIntel System Bring-up ToolkitIntel Vtune Profiler | 13/11/2024 | 17/6/2026 | Improper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Analizada | Media (5.4) | 0.17% | — | Intel Oneapi Base ToolkitIntel System Bring-up ToolkitIntel Vtune Profiler | 13/11/2024 | 17/6/2026 | Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.4) | 0.17% | — | Intel Integrated Performance PrimitivesIntel Oneapi Base Toolkit | 13/11/2024 | 17/6/2026 | Uncontrolled search path for some Intel(R) IPP software for Windows before version 2021.12.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.17% | — | Intel Rendering ToolkitAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) Rendering Toolkit software before version 2024.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.4) | 0.25% | — | Sksdev Toolkit | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKSDEV SKSDEV Toolkit sksdev-toolkit allows Stored XSS.This issue affects SKSDEV Toolkit: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | Ben.moody Content-syndication-toolkit-readerAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ben.moody Content Syndication Toolkit Reader content-syndication-toolkit-reader allows Reflected XSS.This issue affects Content Syndication Toolkit Reader: from n/a through <= 1.5. | |
| Aplazada | Alta (7.1) | 0.27% | — | Michael Visser Jigoshop Store ToolkitAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Visser Jigoshop – Store Toolkit jigoshop-store-toolkit allows Reflected XSS.This issue affects Jigoshop – Store Toolkit: from n/a through <= 1.4.0. | |
| Analizada | Media (4.1) | 0.37% | — | Nvidia Container ToolkitNvidia GPU Operator | 5/11/2024 | 17/6/2026 | NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to… | |
| Aplazada | Media (5.4) | 0.39% | — | Uncannyowl Uncanny Toolkit PRO FOR LearndashAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Toolkit Pro for LearnDash: from n/a through 4.1.4.0 | |
| Aplazada | Crítica (9.8) | 0.51% | — | Deryck User-toolkitAI | 30/10/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck User Toolkit user-toolkit allows Authentication Bypass.This issue affects User Toolkit: from n/a through <= 1.2.3. | |
| Aplazada | Media (6.4) | 0.34% | — | Affiliate-toolkit Affiliate ToolkitAI | 29/10/2024 | 17/6/2026 | The affiliate-toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atkp_product shortcode in all versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.33% | — | Id-sk ToolkitAI | 26/10/2024 | 17/6/2026 | The ID-SK Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary… | |
| Aplazada | Alta (8.8) | 1.1% | 💥 PoC | User ToolkitAI | 26/10/2024 | 17/6/2026 | The User Toolkit plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.3. This is due to an improper capability check in the 'switchUser' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user… | |
| Aplazada | Alta (7.1) | 0.34% | — | Oath-toolkitAI | 9/10/2024 | 17/6/2026 | pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink. |