Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
242 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.48% | — | Mansurahamed Woocommerce Quote Calculator | 28/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocommerce Quote Calculator woo-quote-calculator-order allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through <= 1.1. | |
| Analizada | Media (4.3) | 0.40% | — | Codepeople Calculated Fields Form | 17/10/2024 | 17/6/2026 | The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the… | |
| Analizada | Alta (7.2) | 0.55% | — | Stylemixthemes Cost Calculator Builder | 30/9/2024 | 17/6/2026 | The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin. | |
| Analizada | Media (6.9) | 0.62% | — | Codezips Internal Marks Calculation | 20/9/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (5.3) | 0.42% | — | Stylemixthemes Cost Calculator Builder | 7/9/2024 | 17/6/2026 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.2.1. This is due to the plugin allowing the price field to be manipulated prior to processing via the 'create_cc_order' function, called from the Cost Calculator Builder plugin. This makes… | |
| Modificada | Media (4.8) | 0.32% | — | Kanev CAB Fare Calculator | 5/9/2024 | 17/6/2026 | The Cab fare calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vehicle title setting in versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject… | |
| Analizada | Crítica (9.8) | 2.0% | 💥 Exploit | Stylemixthemes Cost Calculator Builder | 29/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15. | |
| Aplazada | Crítica (9.8) | 0.81% | — | Calculator-boilerplateAI | 18/7/2024 | 17/6/2026 | calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the input field. | |
| Modificada | Media (4.3) | 0.39% | — | Stylemixthemes Cost Calculator Builder | 2/7/2024 | 17/6/2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' functions in all versions up to, and including, 3.2.12. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Modificada | Media (4.8) | 0.44% | — | Stylemixthemes Cost Calculator Builder | 2/7/2024 | 17/6/2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textarea.description’ parameter in all versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level… | |
| Aplazada | Media (5.8) | 0.35% | — | Cost Calculator Builder PROAI | 19/6/2024 | 17/6/2026 | The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 3.1.75. This is due to insufficient limitations on the email recipient and the content in the 'send_pdf' and the 'send_pdf_front' functions which are reachable via AJAX. This makes it… | |
| Analizada | Media (4.3) | 0.31% | — | Codepeople Calculated Fields Form | 3/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople Calculated Fields Form allows Functionality Misuse.This issue affects Calculated Fields Form: from n/a through 1.1.120. | |
| Aplazada | Alta (7.6) | 0.41% | — | CocalcAI | 28/5/2024 | 17/6/2026 | CoCalc is web-based software that enables collaboration in research, teaching, and scientific publishing. In affected versions the markdown parser allows `<script>` tags to be included which execute when published. This issue has been addressed in commit `419862a9c9879c`. Users are advised to upgrade. There are no… | |
| Aplazada | Media (6.4) | 0.28% | — | Cost Calculator Builder PROAI | 17/5/2024 | 17/6/2026 | Cost Calculator Builder Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.1.72, via the send_demo_webhook() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the… | |
| Aplazada | Alta (7.2) | 0.58% | — | Stylemixthemes Cost Calculator BuilderAI | 2/5/2024 | 17/6/2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 3.1.67 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (6.1) | 0.37% | — | AA Cash CalculatorAI | 2/5/2024 | 17/6/2026 | The AA Cash Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘invoice’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (6.5) | 0.32% | — | Lenderd Mortgage Calculators WPAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lenderd Mortgage Calculators WP allows Stored XSS.This issue affects Mortgage Calculators WP: from n/a through 1.56. | |
| Aplazada | Alta (7.1) | 0.18% | — | BMI Adult & KID CalculatorAI | 17/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BMI Adult & Kid Calculator allows Stored XSS.This issue affects BMI Adult & Kid Calculator: from n/a through 1.2.1. | |
| Modificada | Media (6.1) | 0.35% | — | Ezplugins EZ Form Calculator | 15/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Schuppenies EZ Form Calculator allows Reflected XSS.This issue affects EZ Form Calculator: from n/a through 2.14.0.3. | |
| Aplazada | Media (5.4) | 0.20% | — | Quick-plugins Loan Repayment Calculator AND Application FormAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in aerin Loan Repayment Calculator and Application Form.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.4. | |
| Modificada | Media (6.1) | 0.42% | — | Codepeople Calculated Fields Form | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Calculated Fields Form allows Reflected XSS.This issue affects Calculated Fields Form: from n/a through 1.2.54. | |
| Modificada | Media (6.1) | 0.58% | — | Codepeople Calculated Fields Form | 13/3/2024 | 17/6/2026 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href parameter in all versions up to, and including, 5.1.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (6.1) | 0.32% | — | Smartcalc Osticky | 15/2/2024 | 17/6/2026 | An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration with osTicket, a popular Support ticket system. The Open Redirect vulnerability allows attackers to control the return parameter in the URL to a… | |
| Modificada | Media (5.4) | 0.35% | — | Calculatorsworld CC BMI Calculator | 10/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Calculators World CC BMI Calculator allows Stored XSS.This issue affects CC BMI Calculator: from n/a through 2.0.1. | |
| Modificada | Media (6.1) | 0.33% | — | Jgadbois Calculatorpro Calculators | 5/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgadbois CalculatorPro Calculators allows Reflected XSS.This issue affects CalculatorPro Calculators: from n/a through 1.1.7. |