Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
380 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.65% | — | Pluginus Wordpress Meta Data AND Taxonomies Filter | 24/9/2024 | 17/6/2026 | The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.3.3.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible… | |
| Analizada | Media (5.4) | 0.12% | — | Intel HID Event Filter DriverIntel NUC M15 Laptop KIT Lapbc510 FirmwareIntel NUC M15 Laptop KIT Lapbc710 FirmwareIntel NUC M15 Laptop KIT Laprc510 Firmware+6 | 14/8/2024 | 17/6/2026 | Insecure inherited permissions in some Intel(R) HID Event Filter software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.2) | 0.45% | — | Pluginus Husky - Products Filter Professional FOR Woocommerce | 13/8/2024 | 17/6/2026 | Improper Privilege Management vulnerability in realmag777 HUSKY allows Privilege Escalation.This issue affects HUSKY: from n/a through 1.3.6.1. | |
| Analizada | Media (4.8) | 0.31% | — | Codeamp Search & Filter | 8/8/2024 | 17/6/2026 | The Search & Filter Pro WordPress plugin before 2.5.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.27% | — | Kofimokome Message Filter FOR Contact Form 7 | 1/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.1.1. | |
| Aplazada | Media (6.5) | 0.29% | — | Ymc-22 Filter & GridsAI | 1/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in YMC Filter & Grids allows Stored XSS.This issue affects Filter & Grids: from n/a through 2.9.2. | |
| Aplazada | Media (5.8) | 0.30% | — | Yithemes Yith Woocommerce Ajax Product FilterAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Ajax Product Filter yith-woocommerce-ajax-navigation.This issue affects YITH WooCommerce Ajax Product Filter: from n/a through <= 5.1.0. | |
| Modificada | Crítica (9.8) | 1.1% | — | Ymc-22 Filter & Grids | 18/7/2024 | 17/6/2026 | The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files. | |
| Modificada | Alta (7.5) | 20% | — | Pluginus Husky - Products Filter Professional FOR Woocommerce | 16/7/2024 | 17/6/2026 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ‘woof_author’ parameter in all versions up to, and including, 1.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Modificada | Media (5.4) | 0.32% | — | Plugin-devs Blog, Posts AND Category Filter FOR Elementor | 9/7/2024 | 17/6/2026 | The Blog, Posts and Category Filter for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post and Category Filter widget in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied 'post_types' attribute. This makes it… | |
| Modificada | Alta (7.5) | 0.77% | — | Themify Product Filter | 21/6/2024 | 17/6/2026 | The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to time-based SQL Injection via the ‘conditions’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Modificada | Alta (8.8) | 0.35% | — | Websupporter Filter Custom Fields & Taxonomies Light Project Websupporter Filter Custom Fields & Taxonomies Light | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Websupporter Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05. | |
| Modificada | Alta (8.8) | 0.31% | — | Premmerce Product Filter FOR Woocommerce | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Premmerce Premmerce Product Filter for WooCommerce premmerce-woocommerce-product-filter.This issue affects Premmerce Product Filter for WooCommerce: from n/a through <= 3.7.2. | |
| Analizada | Alta (8.8) | 0.32% | — | Pluginus Wordpress Meta Data AND Taxonomies Filter | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3. | |
| Modificada | Media (6.4) | 0.33% | — | Pluginus Husky - Products Filter Professional FOR Woocommerce | 29/5/2024 | 17/6/2026 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (6.5) | 0.28% | — | Pluginus Wordpress Meta Data AND Taxonomies Filter | 17/5/2024 | 17/6/2026 | Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusion, Functionality Misuse.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.2. | |
| Analizada | Alta (8.8) | 0.70% | — | Pluginus Husky - Products Filter Professional FOR Woocommerce | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in PluginUS HUSKY – Products Filter for WooCommerce (formerly WOOF) allows Using Malicious Files, Code Inclusion.This issue affects HUSKY – Products Filter for… | |
| Aplazada | Media (5.9) | 0.38% | — | Sayful Islam Filterable PortfolioAI | 26/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sayful Islam Filterable Portfolio allows Stored XSS.This issue affects Filterable Portfolio: from n/a through 1.6.4. | |
| Aplazada | Media (5.3) | 0.36% | — | Mark Stockton Quicksand Post Filter Jquery PluginAI | 11/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from n/a through 3.1.1. | |
| Analizada | Media (6.1) | 0.42% | — | Themify Woocommerce Product Filter | 1/4/2024 | 17/6/2026 | Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (4.8) | 0.40% | — | Themify Woocommerce Product Filter | 1/4/2024 | 17/6/2026 | Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Media (4.7) | 0.24% | — | Themify Woocommerce Product Filter | 1/4/2024 | 17/6/2026 | Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs | |
| Aplazada | Alta (7.1) | 0.40% | — | Michael Simpson ADD Shortcodes Actions AND FiltersAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Simpson Add Shortcodes Actions And Filters allows Reflected XSS.This issue affects Add Shortcodes Actions And Filters: from n/a through 2.10. | |
| Aplazada | Alta (8.5) | 0.55% | — | Filter Custom Fields & Taxonomies LightAI | 31/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05. | |
| Modificada | Alta (8.8) | 0.24% | — | Pluginus Husky - Products Filter Professional FOR Woocommerce | 29/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 HUSKY – Products Filter for WooCommerce (formerly WOOF).This issue affects HUSKY – Products Filter for WooCommerce (formerly WOOF): from n/a through 1.3.5.1. |