Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.19% | — | SAP Business ONE Integration FrameworkAI | 10/6/2025 | 17/6/2026 | The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and availability. | |
| Aplazada | Media (5.3) | 0.32% | — | Viralloops Viral Loops WP IntegrationAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Viral Loops WP Integration: from n/a through <= 3.8.1. | |
| Aplazada | Media (4.3) | 0.28% | — | Viralloops Viral Loops WP IntegrationAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Viral Loops WP Integration: from n/a through <= 3.8.1. | |
| Aplazada | Media (5.3) | 0.31% | — | Integration FOR Salesforce AND Contact Form 7 Wpforms Elementor Formidable Ninja FormsAI | 30/5/2025 | 17/6/2026 | The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used… | |
| Aplazada | Alta (8.1) | 0.64% | — | Miniorange Discord IntegrationAI | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange miniOrange Discord Integration miniorange-discord-integration allows PHP Local File Inclusion.This issue affects miniOrange Discord Integration: from n/a through <= 2.2.2. | |
| Modificada | Alta (8.8) | 0.18% | — | Videowhisper Live Streaming Integration | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Cross Site Request Forgery.This issue affects Broadcast Live Video: from n/a through <= 6.2.4. | |
| Aplazada | Alta (7.1) | 0.15% | — | Affiliates Manager Google Recaptcha IntegrationAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in affmngr Affiliates Manager Google reCAPTCHA Integration affiliates-manager-google-recaptcha-integration allows Stored XSS.This issue affects Affiliates Manager Google reCAPTCHA Integration: from n/a through <= 1.0.6. | |
| Aplazada | Media (4.7) | 0.32% | — | Formsintegrations Integrations OF Zoho CRM With Elementor FormAI | 7/5/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in formsintegrations Integrations of Zoho CRM with Elementor form integrations-of-zoho-crm-with-elementor-form allows Phishing.This issue affects Integrations of Zoho CRM with Elementor form: from n/a through <= 1.0.8. | |
| Aplazada | Media (4.7) | 0.32% | — | Crmperks Integration FOR Woocommerce AND SalesforceAI | 7/5/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and Salesforce woo-salesforce-plugin-crm-perks allows Phishing.This issue affects Integration for WooCommerce and Salesforce: from n/a through <= 1.7.5. | |
| Aplazada | Media (4.9) | 0.42% | — | Hitachivantara Pentaho Business Analytics ServerAIHitachivantara Pentaho Data IntegrationAI | 16/4/2025 | 17/6/2026 | Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is read, it is fed back into the application that is… | |
| Aplazada | Media (6.8) | 0.49% | — | Hitachivantara Pentaho Data Integration AND AnalyticsAI | 16/4/2025 | 17/6/2026 | Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35) Description Hitachi Vantara Pentaho Data… | |
| Aplazada | Media (6.8) | 0.43% | — | Hitachivantara Pentaho Data IntegrationAI | 16/4/2025 | 17/6/2026 | Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. (CWE-35) Description Hitachi Vantara Pentaho Data… | |
| Aplazada | Crítica (9.1) | 0.94% | — | Hitachivantara Pentaho Data Integration AND AnalyticsAI | 16/4/2025 | 17/6/2026 | Overview The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99) Description Hitachi Vantara Pentaho Data Integration & Analytics versions before… | |
| Aplazada | Media (4.3) | 0.21% | — | Crmperks Integration FOR Woocommerce AND QuickbooksAI | 16/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for WooCommerce and QuickBooks wp-woocommerce-quickbooks allows Cross Site Request Forgery.This issue affects Integration for WooCommerce and QuickBooks: from n/a through <= 1.3.1. | |
| Aplazada | Media (5.9) | 0.40% | — | Aribhour Linet ERP Woocommerce IntegrationAI | 10/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aribhour Linet ERP-Woocommerce Integration linet-erp-woocommerce-integration allows Path Traversal.This issue affects Linet ERP-Woocommerce Integration: from n/a through <= 3.5.12. | |
| Aplazada | Alta (7.1) | 0.19% | — | Axew3 WP W3all Phpbb IntegrationAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB wp-w3all-phpbb-integration allows Reflected XSS.This issue affects WP w3all phpBB: from n/a through <= 2.9.9. | |
| Analizada | Media (5.5) | 0.29% | — | Nipotan Line Integration FOR Amon2 | 5/4/2025 | 17/6/2026 | Amon2::Auth::Site::LINE uses the String::Random module to generate nonce values. String::Random defaults to Perl's built-in predictable random number generator, the rand() function, which is not cryptographically secure | |
| Aplazada | Media (4.3) | 0.15% | — | Axew3 WP W3all Phpbb IntegrationAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB wp-w3all-phpbb-integration allows Cross Site Request Forgery.This issue affects WP w3all phpBB: from n/a through <= 2.9.8. | |
| Aplazada | Media (5.4) | 0.49% | — | Shivam Mani Tripathi Privy CRM IntegrationAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Shivam Mani Tripathi Privyr CRM Integration privy-crm-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Privyr CRM Integration: from n/a through <= 1.0.2. | |
| Aplazada | Media (6.5) | 0.27% | — | Wporbit Perfect Font Awesome IntegrationAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPOrbit Support Perfect Font Awesome Integration perfect-font-awesome-integration allows Stored XSS.This issue affects Perfect Font Awesome Integration: from n/a through <= 2.3. | |
| Aplazada | Media (5.3) | 0.50% | — | Viralloops Viral Loops WP IntegrationAI | 1/4/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Retrieve Embedded Sensitive Data.This issue affects Viral Loops WP Integration: from n/a through <= 3.4.0. | |
| Aplazada | Media (5.9) | 0.37% | — | Astoundify WP Modal Popup With Cookie IntegrationAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify WP Modal Popup with Cookie Integration wp-modal-popup-with-cookie-integration allows Stored XSS.This issue affects WP Modal Popup with Cookie Integration: from n/a through <= 2.4. | |
| Aplazada | Media (4.7) | 0.42% | — | Bitapps BIT IntegrationsAI | 27/3/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bit Apps Bit Integrations bit-integrations allows Phishing.This issue affects Bit Integrations: from n/a through <= 2.4.10. | |
| Aplazada | Media (4.3) | 0.21% | — | Crmperks Integration FOR Google Sheets AND Contact Form 7AI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms integration-for-contact-form-7-and-google-sheets allows Cross Site Request Forgery.This issue affects Integration for Google Sheets and Contact Form 7, WPForms, Elementor,… | |
| Analizada | Baja (3.5) | 0.26% | — | Advancedformintegration Advanced Form Integration | 25/3/2025 | 17/6/2026 | The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). |