Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

1971 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.30%—Wp-feedstats Wordpress PluginAI22/7/202622/7/2026
The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.
AplazadaAlta (7.5)0.49%—Crypt PasswordAI20/7/202620/7/2026
Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the underlying hash.
AplazadaCrítica (9.8)0.55%—Crypt-passwordAI20/7/202620/7/2026
Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
AplazadaMedia (5.4)0.14%💥 PoCWp-feedstats Wordpress PluginAI20/7/202620/7/2026
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's…
AnalizadaCrítica (9.8)10%⚠ Explotación activa💥 ExploitWordpress17/7/202622/7/2026
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
AnalizadaMedia (5.9)5.9%⚠ Explotación activa💥 ExploitWordpress17/7/202629/7/2026
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
AplazadaAlta (8.1)0.38%—Shibboleth Wordpress PluginAI15/7/202615/7/2026
The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an…
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+314/7/202616/7/2026
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+314/7/202616/7/2026
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+314/7/202616/7/2026
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+214/7/202615/7/2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+414/7/202616/7/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+414/7/202616/7/2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+414/7/202616/7/2026
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+314/7/202616/7/2026
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+414/7/202616/7/2026
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+314/7/202616/7/2026
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+314/7/202616/7/2026
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+314/7/202616/7/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AplazadaCrítica (9.6)0.25%—Word Count AND Social SharesAI14/7/202614/7/2026
The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files on the server, which can lead to a full site takeover (e.g.…
AplazadaAlta (8.7)0.41%—PasswordpusherAI13/7/202615/7/2026
PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and per-push lockout mechanisms. Attackers who know a push token can systematically guess passphrases at 120 attempts per minute without triggering any push-level defense,…
AplazadaAlta (7.2)0.27%—Wpswings PDF Generator FOR WordpressAI13/7/202613/7/2026
Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.This issue affects PDF Generator for WordPress: from n/a through <= 1.6.2.
AplazadaMedia (6.3)0.33%—PasswordpusherAI8/7/202614/7/2026
PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the…
AplazadaAlta (7.5)0.48%—Notifications FOR Forms AND Wordpress ActionsAI6/7/20266/7/2026
The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and execute arbitrary local PHP files on the server.
AplazadaAlta (7.1)0.25%—Wordpress Plugins WP DebuggingAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.