Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
205 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.60% | — | Jenkins Cloudbees Docker Hub/registry Notification | 15/11/2022 | 17/6/2026 | A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository. | |
| Modificada | Alta (8.7) | 0.72% | — | Amazon Opensearch Notifications | 11/11/2022 | 17/6/2026 | OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Custom web-hook etc channels. A potential SSRF issue in OpenSearch Notifications Plugin starting in 2.0.0 and prior to 2.2.1 could allow an existing privileged user to… | |
| Modificada | Crítica (9.8) | 0.90% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 27/10/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=. | |
| Modificada | Media (4.3) | 0.68% | — | Fluxcd Flux2Fluxcd Helm-controllerFluxcd Image-automation-controllerFluxcd Image-reflector-controller+3 | 22/10/2022 | 17/6/2026 | Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or… | |
| Modificada | Alta (7.2) | 1.0% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 16/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 1.0% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 16/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=. | |
| Modificada | Alta (7.2) | 1.0% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 16/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 0.88% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 8/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/modstudent/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 0.88% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 8/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/autonumber/index.php?view=edit&id=. | |
| Modificada | Alta (7.2) | 0.88% | — | School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification | 8/9/2022 | 17/6/2026 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/user/index.php?view=edit&id=. | |
| Modificada | Alta (8) | 0.91% | — | Ultimatesmsnotifications Ultimate SMS Notifications FOR Woocommerce | 6/9/2022 | 17/6/2026 | The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First… | |
| Modificada | Media (6.1) | 0.54% | — | 8degreethemes Notification BAR | 23/8/2022 | 17/6/2026 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in 8 Degree Themes otification Bar for WordPress plugin <= 1.1.8 at WordPress. | |
| Modificada | Media (4.3) | 0.51% | — | Jenkins Build Notifications | 30/6/2022 | 17/6/2026 | Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. | |
| Modificada | Media (4.3) | 0.59% | — | Jenkins Build Notifications | 30/6/2022 | 17/6/2026 | Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (4.3) | 0.55% | — | Jenkins Jianliao Notification | 23/6/2022 | 17/6/2026 | A missing permission check in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers with Overall/Read permission to send HTTP POST requests to an attacker-specified URL. | |
| Modificada | Media (6.5) | 0.49% | — | Jenkins Jianliao Notification | 23/6/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests to an attacker-specified URL. | |
| Modificada | Crítica (9.8) | 34% | 💥 Exploit | Wpdeveloper Notificationx | 7/3/2022 | 17/6/2026 | The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (6.5) | 0.44% | — | Google Exposure Notification Verification Server | 9/12/2021 | 17/6/2026 | An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater. | |
| Modificada | Alta (8.8) | 0.67% | — | Delitestudio Push Notifications FOR Wordpress | 24/11/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page. | |
| Modificada | Media (4.8) | 0.93% | — | Bracketspace Notification | 1/11/2021 | 17/6/2026 | The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/classes/Utils/Settings.php file which made it possible for attackers with administrative user access to inject arbitrary web scripts, in… | |
| Modificada | Media (6.1) | 0.90% | — | Feedify WEB Push Notifications | 10/9/2021 | 17/6/2026 | The Feedify – Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter found in the ~/includes/base.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.8. | |
| Modificada | Media (5.4) | 0.62% | — | Wpfront Notification BAR | 6/9/2021 | 17/6/2026 | The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (6.1) | 0.83% | — | Cozyvision SMS Alert Order Notifications | 6/9/2021 | 17/6/2026 | The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page. | |
| Modificada | Media (4.8) | 0.69% | — | Wpfront Notification BAR | 16/8/2021 | 17/6/2026 | The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue |