Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.30% | — | Wp-feedstats Wordpress PluginAI | 22/7/2026 | 22/7/2026 | The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment. | |
| Aplazada | Alta (7.5) | 0.49% | — | Crypt PasswordAI | 20/7/2026 | 20/7/2026 | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the underlying hash. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Crypt-passwordAI | 20/7/2026 | 20/7/2026 | Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography. | |
| Aplazada | Media (5.4) | 0.14% | 💥 PoC | Wp-feedstats Wordpress PluginAI | 20/7/2026 | 20/7/2026 | The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's… | |
| Analizada | Crítica (9.8) | 10% | ⚠ Explotación activa💥 Exploit | Wordpress | 17/7/2026 | 22/7/2026 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. | |
| Analizada | Media (5.9) | 5.9% | ⚠ Explotación activa💥 Exploit | Wordpress | 17/7/2026 | 29/7/2026 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. | |
| Aplazada | Alta (8.1) | 0.38% | — | Shibboleth Wordpress PluginAI | 15/7/2026 | 15/7/2026 | The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an… | |
| Analizada | Media (5.5) | 0.60% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 14/7/2026 | 16/7/2026 | Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 14/7/2026 | 16/7/2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 14/7/2026 | 16/7/2026 | Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+2 | 14/7/2026 | 15/7/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+4 | 14/7/2026 | 16/7/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+4 | 14/7/2026 | 16/7/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.60% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+4 | 14/7/2026 | 16/7/2026 | Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 14/7/2026 | 16/7/2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.60% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+4 | 14/7/2026 | 16/7/2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 14/7/2026 | 16/7/2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 14/7/2026 | 16/7/2026 | Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 14/7/2026 | 16/7/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Aplazada | Crítica (9.6) | 0.25% | — | Word Count AND Social SharesAI | 14/7/2026 | 14/7/2026 | The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files on the server, which can lead to a full site takeover (e.g.… | |
| Aplazada | Alta (8.7) | 0.41% | — | PasswordpusherAI | 13/7/2026 | 15/7/2026 | PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and per-push lockout mechanisms. Attackers who know a push token can systematically guess passphrases at 120 attempts per minute without triggering any push-level defense,… | |
| Aplazada | Alta (7.2) | 0.27% | — | Wpswings PDF Generator FOR WordpressAI | 13/7/2026 | 13/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.This issue affects PDF Generator for WordPress: from n/a through <= 1.6.2. | |
| Aplazada | Media (6.3) | 0.33% | — | PasswordpusherAI | 8/7/2026 | 14/7/2026 | PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the… | |
| Aplazada | Alta (7.5) | 0.48% | — | Notifications FOR Forms AND Wordpress ActionsAI | 6/7/2026 | 6/7/2026 | The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and execute arbitrary local PHP files on the server. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Plugins WP DebuggingAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions. |