Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
–

2459 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.45%—Linuxfoundation Backstage Catalog-modelLinuxfoundation Backstage Core-componentsLinuxfoundation Backstage Plugin-catalog-backend14/2/202317/6/2026
Backstage is an open platform for building developer portals. `@backstage/catalog-model` prior to version 1.2.0, `@backstage/core-components` prior to 0.12.4, and `@backstage/plugin-catalog-backend` prior to 1.7.2 are affected by a cross-site scripting vulnerability. This vulnerability allows a malicious actor with…
ModificadaAlta (8.8)0.26%—Shapedplugin WP Tabs14/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ShapedPlugin WP Tabs – Responsive Tabs Plugin for WordPress plugin <= 2.1.14 versions.
ModificadaMedia (6.1)0.66%—UDX Stateless Media Plugin13/2/202317/6/2026
Se encontró una vulnerabilidad en UDX Stateless Media Plugin 3.1.1 en WordPress. Ha sido declarada problemática. Esta vulnerabilidad afecta a la función setup_wizard_interface del archivo lib/classes/class-settings.php. La manipulación de la configuración de los argumentos conduce a cross-site scripting. El ataque se…
ModificadaMedia (5.4)0.54%—Shapedplugin Location Weather13/2/202317/6/2026
El complemento Location Weather de WordPress anterior a 1.3.4 no valida ni escapa algunas de sus opciones de bloqueo antes de devolverlas a una página/publicación donde está incrustado el bloque, lo que podría permitir a los usuarios con el rol de colaborador y superior realizar un cross-site scripting almacenado.
ModificadaMedia (5.4)0.48%—Pickplugins Product Slider FOR Woocommerce13/2/202317/6/2026
The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting…
ModificadaMedia (5.4)0.48%—Wpplugin Easy Paypal BUY NOW Button13/2/202317/6/2026
The Easy PayPal Buy Now Button WordPress plugin before 1.7.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.4)0.71%—Yarpp YET Another Related Posts Plugin13/2/202317/6/2026
The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (4.3)0.31%—Wickedplugins Wicked Folders8/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted…
ModificadaMedia (4.3)0.31%—Wickedplugins Wicked Folders8/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted…
ModificadaMedia (4.3)0.31%—Wickedplugins Wicked Folders8/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted…
ModificadaMedia (4.3)0.31%—Wickedplugins Wicked Folders8/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted…
ModificadaMedia (4.3)0.58%—Wickedplugins Wicked Folders8/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and…
ModificadaMedia (4.3)0.58%—Wickedplugins Wicked Folders8/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and…
ModificadaMedia (4.3)0.58%—Wickedplugins Wicked Folders8/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and…
ModificadaMedia (4.3)0.58%—Wickedplugins Wicked Folders8/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and…
ModificadaMedia (4.3)0.58%—Wickedplugins Wicked Folders8/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform…
ModificadaMedia (4.3)0.31%—Wickedplugins Wicked Folders8/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function. This makes it possible for unauthenticated attackers to invoke this function via forged request…
ModificadaMedia (4.3)0.58%—Wickedplugins Wicked Folders8/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and…
ModificadaMedia (4.3)0.59%—Wickedplugins Wicked Folders8/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and…
ModificadaMedia (4.3)0.32%—Wickedplugins Wicked Folders7/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request…
ModificadaMedia (4.3)0.32%—Wickedplugins Wicked Folders7/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted…
ModificadaMedia (4.3)0.32%—Wickedplugins Wicked Folders7/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_move_object function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted…
ModificadaMedia (4.3)0.60%—Wickedplugins Wicked Folders7/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and…
ModificadaMedia (4.3)0.60%—Wickedplugins Wicked Folders7/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and…
ModificadaMedia (4.3)0.31%—Wickedplugins Wicked Folders7/2/202317/6/2026
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted…