Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

205 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.60%—Jenkins Cloudbees Docker Hub/registry Notification15/11/202217/6/2026
A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.
ModificadaAlta (8.7)0.72%—Amazon Opensearch Notifications11/11/202217/6/2026
OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Custom web-hook etc channels. A potential SSRF issue in OpenSearch Notifications Plugin starting in 2.0.0 and prior to 2.2.1 could allow an existing privileged user to…
ModificadaCrítica (9.8)0.90%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification27/10/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=.
ModificadaMedia (4.3)0.68%—Fluxcd Flux2Fluxcd Helm-controllerFluxcd Image-automation-controllerFluxcd Image-reflector-controller+322/10/202217/6/2026
Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or…
ModificadaAlta (7.2)1.0%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification16/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=.
ModificadaAlta (7.2)1.0%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification16/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=.
ModificadaAlta (7.2)1.0%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification16/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=.
ModificadaAlta (7.2)0.88%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification8/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/modstudent/index.php?view=edit&id=.
ModificadaAlta (7.2)0.88%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification8/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/autonumber/index.php?view=edit&id=.
ModificadaAlta (7.2)0.88%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification8/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/user/index.php?view=edit&id=.
ModificadaAlta (8)0.91%—Ultimatesmsnotifications Ultimate SMS Notifications FOR Woocommerce6/9/202217/6/2026
The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First…
ModificadaMedia (6.1)0.54%—8degreethemes Notification BAR23/8/202217/6/2026
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in 8 Degree Themes otification Bar for WordPress plugin <= 1.1.8 at WordPress.
ModificadaMedia (4.3)0.51%—Jenkins Build Notifications30/6/202217/6/2026
Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
ModificadaMedia (4.3)0.59%—Jenkins Build Notifications30/6/202217/6/2026
Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
ModificadaMedia (4.3)0.55%—Jenkins Jianliao Notification23/6/202217/6/2026
A missing permission check in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers with Overall/Read permission to send HTTP POST requests to an attacker-specified URL.
ModificadaMedia (6.5)0.49%—Jenkins Jianliao Notification23/6/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests to an attacker-specified URL.
ModificadaCrítica (9.8)34%💥 ExploitWpdeveloper Notificationx7/3/202217/6/2026
The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaMedia (6.5)0.44%—Google Exposure Notification Verification Server9/12/202117/6/2026
An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater.
ModificadaAlta (8.8)0.67%—Delitestudio Push Notifications FOR Wordpress24/11/202117/6/2026
Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page.
ModificadaMedia (4.8)0.93%—Bracketspace Notification1/11/202117/6/2026
The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/classes/Utils/Settings.php file which made it possible for attackers with administrative user access to inject arbitrary web scripts, in…
ModificadaMedia (6.1)0.90%—Feedify WEB Push Notifications10/9/202117/6/2026
The Feedify – Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter found in the ~/includes/base.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.8.
ModificadaMedia (5.4)0.62%—Wpfront Notification BAR6/9/202117/6/2026
The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (6.1)0.83%—Cozyvision SMS Alert Order Notifications6/9/202117/6/2026
The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.
ModificadaMedia (4.8)0.69%—Wpfront Notification BAR16/8/202117/6/2026
The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue
Orbitaley — Vulnerabilidades