Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
189 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.55% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the attach_rule function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify cache rules. | |
| Modificada | Media (4.3) | 1.0% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete plugin log files. | |
| Modificada | Media (4.3) | 0.55% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the ajax_deactivate function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to disable caching. | |
| Modificada | Media (4.3) | 0.55% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the ucss_connect function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to connect a new… | |
| Modificada | Media (4.3) | 0.55% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the queue_posts function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to modify the plugin's… | |
| Modificada | Media (4.3) | 0.55% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_page_cache function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete the plugin's cache. | |
| Modificada | Media (6.5) | 0.68% | — | Kraken.io Image Optimizer | 1/2/2023 | 17/6/2026 | The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset image optimizations. | |
| Modificada | Media (6.5) | 0.33% | — | Imageseo Optimize Images ALT Text (alt Tag) & Names FOR SEO Using AI | 23/1/2023 | 17/6/2026 | The Optimize images ALT Text & names for SEO using AI WordPress plugin before 2.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack. | |
| Modificada | Crítica (9.1) | 29% | — | Images Optimize AND Upload CF7 Project Images Optimize AND Upload CF7 | 16/1/2023 | 17/6/2026 | The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX action available to unauthenticated users, which could allow them to delete arbitrary files on the server via path traversal attack. | |
| Modificada | Media (4.8) | 0.47% | — | Sirv Image Optimizer, Resizer AND CDN | 2/1/2023 | 17/6/2026 | The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.3) | 1.5% | 💥 Exploit | Optimizingmatters Autooptimize | 2/1/2023 | 17/6/2026 | The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs. | |
| Modificada | Media (4.3) | 0.51% | — | Resmush.it Image Optimizer | 14/11/2022 | 17/6/2026 | The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them. | |
| Modificada | Media (6.5) | 0.34% | — | Resmush.it Image Optimizer | 14/11/2022 | 17/6/2026 | The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF checks for any of its AJAX actions, allowing an attackers to trick logged in users to perform various actions on their behalf on the site. | |
| Modificada | Media (4.8) | 0.44% | — | Abpressoptimizer AB Press Optimizer | 17/10/2022 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology AB Press Optimizer plugin <= 1.1.1 on WordPress. | |
| Modificada | Media (4.8) | 0.63% | — | Resmush.it Image Optimizer | 10/10/2022 | 17/6/2026 | The reSmush.it WordPress plugin before 0.4.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when unfiltered_html is disallowed. | |
| Modificada | Alta (8.8) | 0.36% | — | Kraken.io Image Optimizer | 23/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kraken.io Image Optimizer plugin <= 2.6.5 at WordPress. | |
| Modificada | Media (4.3) | 0.34% | — | Wordpress Ping Optimizer Project Wordpress Ping Optimizer | 19/9/2022 | 17/6/2026 | The WordPress Ping Optimizer WordPress plugin before 2.35.1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (4.8) | 0.64% | — | Autoptimize | 16/9/2022 | 17/6/2026 | The Autoptimize WordPress plugin before 3.1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.67% | — | Link Optimizer Lite Project Link Optimizer Lite | 6/9/2022 | 17/6/2026 | The Link Optimizer Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 1.4.5. This is due to missing nonce validation on the admin_page function found in the ~/admin.php file. This makes it possible for unauthenticated attackers to modify the… | |
| Modificada | Crítica (9.8) | 2.9% | — | Siteground Security Optimizer | 19/4/2022 | 17/6/2026 | The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA for pending accounts. Upon successful… | |
| Modificada | Media (4.9) | 1.0% | — | FFW Optimize MY Google Fonts | 3/1/2022 | 17/6/2026 | The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (7.4) | 0.49% | — | Siemens Sinumerik Analyse Mycondition FirmwareSiemens Sinumerik Analyze Myperformance FirmwareSiemens Sinumerik Integrate Client FirmwareSiemens Sinumerik Integrate FOR Production Firmware+6 | 13/7/2021 | 17/6/2026 | A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 <… | |
| Modificada | Media (4.8) | 0.62% | — | Autoptimize | 21/6/2021 | 17/6/2026 | The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute when a victim visits… | |
| Modificada | Alta (8.1) | 1.2% | — | Autoptimize | 21/6/2021 | 17/6/2026 | The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not yet… |