Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.36% | — | Nightwolf Penetration Testing PlatformAINightwolf LogbugAI | 27/3/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in the Logbug module of NightWolf Penetration Testing Platform 1.2.2 allows attackers to execute JavaScript through the markdown editor feature. | |
| Analizada | Alta (7.1) | 0.29% | — | Erwinwolff Wordpress Activity-o-meter | 7/3/2025 | 17/6/2026 | The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins. | |
| Modificada | Alta (7.2) | 0.68% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 3/2/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through <= 1.0.8.5. | |
| Modificada | Alta (8.8) | 0.62% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 14/11/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through <= 1.0.8.3. | |
| Aplazada | Crítica (10) | 1.5% | 💥 PoC | Joshua Wolfe THE Novel Design Store DirectoryAI | 11/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upload a Web Shell to a Web Server.This issue affects The Novel Design Store Directory: from n/a through <= 4.3.0. | |
| Analizada | Alta (7.8) | 0.30% | — | Overwolf | 4/9/2024 | 17/6/2026 | A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the… | |
| Analizada | Alta (8.8) | 0.46% | — | Wolfssl | 30/8/2024 | 17/6/2026 | Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the ed25519_key structure. | |
| Modificada | Alta (8.8) | 0.58% | — | Wolfssl | 29/8/2024 | 17/6/2026 | Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the RsaKey structure. | |
| Analizada | Media (5.5) | 0.18% | — | Wolfssl | 29/8/2024 | 17/6/2026 | The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution. In a controlled environment such as Intel SGX, an attacker can gain a per instruction sub-cache-line resolution allowing them to break the cache-line-level protection.… | |
| Analizada | Crítica (10) | 0.56% | — | Wolfssl | 27/8/2024 | 17/6/2026 | In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in a pointer and length to check against, with no requirements that it be NULL terminated. If a caller was attempting to do a name check on… | |
| Analizada | Media (5.1) | 0.47% | — | Wolfssl | 27/8/2024 | 17/6/2026 | A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully parsing the server hello. https://doi.org/10.46586/tches.v2024.i1.457-500 | |
| Analizada | Media (5.9) | 0.42% | — | Wolfssl | 27/8/2024 | 17/6/2026 | An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in signing operations with private ECC keys, such as in server-side TLS connections, the connection is halted if any fault occurs. The success… | |
| Modificada | Media (4.9) | 0.35% | — | Wolfssl | 27/8/2024 | 17/6/2026 | Generating the ECDSA nonce k samples a random number r and then truncates this randomness with a modular reduction mod n where n is the order of the elliptic curve. Meaning k = r mod n. The division used during the reduction estimates a factor q_e by dividing the upper two digits (a digit having e.g. a size of 8 byte)… | |
| Aplazada | Alta (7.5) | 14% | 💥 Exploit | Centralsquare CrywolfAI | 26/8/2024 | 17/6/2026 | A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information. | |
| Modificada | Media (5.4) | 0.36% | — | Wolfiezero Spotify Play Button | 26/6/2024 | 17/6/2026 | The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (4.4) | 0.24% | — | WolfictlAI | 15/5/2024 | 17/6/2026 | wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a local user’s GitHub token to be sent to remote servers other than `github.com`. Most git-dependent functionality in wolfictl relies on its own `git` package, which contains centralized logic for… | |
| Modificada | Media (4.8) | 0.28% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 8/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WOLF allows Stored XSS.This issue affects WOLF: from n/a through 1.0.8.2. | |
| Modificada | Alta (8.8) | 0.22% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager ProfessionalPluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 10/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional, realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.This issue affects WOLF – WordPress Posts Bulk Editor and Manager Professional: from n/a through… | |
| Analizada | Crítica (9.1) | 0.69% | — | Wolfssl | 25/3/2024 | 17/6/2026 | Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via sending a malformed packet with the correct length. | |
| Analizada | Crítica (9.1) | 0.62% | — | Wolfssh | 25/3/2024 | 17/6/2026 | A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first performing user authentication, resulting in unauthorized access. | |
| Modificada | Crítica (9.1) | 0.60% | — | Wolfssl | 20/2/2024 | 17/6/2026 | In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is only intended for debugging). | |
| Analizada | Media (5.3) | 0.51% | — | Wolfssl | 15/2/2024 | 17/6/2026 | wolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key boundaries. As a result, it was possible to combine (D)TLS messages using different keys into one (D)TLS record. The most extreme edge case is that, in (D)TLS 1.3, it was possible that an unencrypted (D)TLS 1.3 record from the… | |
| Modificada | Media (5.9) | 0.54% | — | Wolfssl | 9/2/2024 | 17/6/2026 | wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a timing Bleichenbacher style attack, when built with the following options to configure: --enable-all CFLAGS="-DWOLFSSL_STATIC_RSA" The define “WOLFSSL_STATIC_RSA” enables static RSA cipher suites, which is not recommended,… | |
| Modificada | Media (4.3) | 0.53% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 5/2/2024 | 17/6/2026 | The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing capability check on the wpbe_create_new_term, wpbe_update_tax_term, and wpbe_delete_tax_term functions in all versions up to, and including, 1.0.8.1.… | |
| Modificada | Media (4.3) | 0.31% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 5/2/2024 | 17/6/2026 | The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8.1. This is due to missing or incorrect nonce validation on the wpbe_create_new_term, wpbe_update_tax_term, and wpbe_delete_tax_term functions.… |