Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory Wishlist FOR WoocommerceAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Stored XSS.This issue affects Wishlist for WooCommerce: from n/a through <= 3.2.2. | |
| Analizada | Media (6.8) | 0.52% | — | Dfactory Responsive Lightbox | 15/5/2025 | 17/6/2026 | The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory Custom Checkout Fields FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Custom Checkout Fields for WooCommerce custom-checkout-fields-for-woocommerce allows Stored XSS.This issue affects Custom Checkout Fields for WooCommerce: from n/a through <= 1.8.3. | |
| Analizada | Alta (7.8) | 0.29% | — | Hiyouga Llama-factory | 1/5/2025 | 17/6/2026 | LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script performs insecure deserialization using `torch.load()` on user-supplied `.bin` files from an input directory. An attacker can… | |
| Aplazada | Alta (7.1) | 0.29% | — | Wpfactory Product Excel Import Export Bulk Edit FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Excel Import Export & Bulk Edit for WooCommerce webd-woocommerce-product-excel-importer-bulk-edit allows Reflected XSS.This issue affects Product Excel Import Export & Bulk Edit for WooCommerce: from… | |
| Aplazada | Alta (7.1) | 0.31% | — | Wpfactory Msrp RRP Pricing FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory MSRP (RRP) Pricing for WooCommerce msrp-for-woocommerce allows Reflected XSS.This issue affects MSRP (RRP) Pricing for WooCommerce: from n/a through <= 1.8.1. | |
| Aplazada | Crítica (9.6) | 0.33% | 💥 PoC | Wpfactory Custom CSS JS PHPAI | 16/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP custom-css allows Remote Code Inclusion.This issue affects Custom CSS, JS & PHP: from n/a through <= 2.4.1. | |
| Aplazada | Media (6.5) | 0.27% | — | Wpfactory Additional Custom Product TabsAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Product Tabs for WooCommerce product-tabs-for-woocommerce allows Stored XSS.This issue affects Additional Custom Product Tabs for WooCommerce: from n/a through <= 1.7.0. | |
| Analizada | Media (6.7) | 0.17% | — | Dell Latitude 3140 2in1 FirmwareDell Latitude 3320 FirmwareDell Latitude 3330 FirmwareDell Latitude 3340 Firmware+257 | 9/4/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. | |
| Aplazada | Crítica (9.3) | 0.54% | — | Wpfactory Advanced Woocommerce Product Sales ReportingAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows SQL Injection.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <= 4.1.1. | |
| Aplazada | Media (5.3) | 0.45% | — | Wpfactory AdvertsAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in WPFactory Adverts adverts-click-tracker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Adverts: from n/a through <= 1.4. | |
| Analizada | Alta (8.1) | 0.39% | — | Two-factor Authentication Project Two-factor Authentication | 31/3/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory Quantity Dynamic Pricing & Bulk Discounts FOR WoocommerceAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Quantity Dynamic Pricing & Bulk Discounts for WooCommerce wholesale-pricing-woocommerce allows Stored XSS.This issue affects Quantity Dynamic Pricing & Bulk Discounts for WooCommerce: from n/a through <=… | |
| Aplazada | Media (5.3) | 0.42% | — | Webfactoryltd Advanced Google RecaptchaAI | 28/3/2025 | 17/6/2026 | The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to generic SQL Injection via the ‘sSearch’ parameter in all versions up to, and including, 1.29 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.26% | — | Wpfactory EAN FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in WPFactory EAN for WooCommerce ean-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EAN for WooCommerce: from n/a through <= 5.3.5. | |
| Aplazada | Media (4.7) | 0.46% | — | Wpfactory Scheduled Automatic Order Status Controller FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPFactory Scheduled & Automatic Order Status Controller for WooCommerce order-status-rules-for-woocommerce allows Phishing.This issue affects Scheduled & Automatic Order Status Controller for WooCommerce: from n/a through <= 3.7.1. | |
| Aplazada | Alta (7.1) | 0.18% | — | Shawfactor LH OGP Meta TagsAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in shawfactor LH OGP Meta lh-ogp-meta-tags allows Stored XSS.This issue affects LH OGP Meta: from n/a through <= 1.73. | |
| Modificada | Media (6.5) | 0.18% | — | Wpfactory Wishlist FOR Woocommerce | 8/3/2025 | 17/6/2026 | The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.7. This is due to missing or incorrect nonce validation on the 'save_to_multiple_wishlist' function. This makes it possible for unauthenticated attackers… | |
| Analizada | Media (5.3) | 0.34% | — | Webfactoryltd Advanced Google Recaptcha | 25/2/2025 | 17/6/2026 | The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.27 . This makes it possible for unauthenticated attackers to bypass the Built-in Math Captcha Verification. | |
| Analizada | Alta (8.2) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M16 R2 Firmware+388 | 19/2/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Media (6.5) | 0.45% | — | Wpfactory Customer Email Verification FOR Woocommerce | 15/2/2025 | 17/6/2026 | The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via Shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including emails as well… | |
| Analizada | Alta (7.5) | 0.48% | — | Wpfactory Customer Email Verification FOR Woocommerce | 12/2/2025 | 17/6/2026 | The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode that will generate a confirmation link with a placeholder email. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (7) | 0.38% | — | Rockwellautomation Factorytalk Assetcentre | 30/1/2025 | 17/6/2026 | A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user. | |
| Analizada | Alta (7.3) | 0.33% | — | Rockwellautomation Factorytalk Assetcentre | 30/1/2025 | 17/6/2026 | A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages. | |
| Analizada | Crítica (9.3) | 0.37% | — | Rockwellautomation Factorytalk Assetcentre | 30/1/2025 | 17/6/2026 | An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application. |