Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

3425 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.68%—Trueview Security Camera T18161AI7/7/202610/7/2026
Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.
AplazadaMedia (6.4)0.33%—Reviews Widgets FOR Google Yelp AND TripadvisorAI6/7/20267/7/2026
The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Shortcode::fbrev()…
AplazadaAlta (7.1)0.25%—Wpdeveloper ReviewxAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions.
AplazadaMedia (6.5)0.22%—JetreviewsAI2/7/20262/7/2026
Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.
AplazadaAlta (7.5)0.46%—WP Review Slider PROAI2/7/20262/7/2026
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action in versions up to, and including, 12.7.2. The parameter is read via $_POST['notinstring'] and passed through sanitize_text_field() — which strips HTML and whitespace but…
AplazadaMedia (6.1)0.37%—WP Google Places Review SliderAI1/7/20261/7/2026
The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, and including, 18.1. This is due to insufficient input sanitization and output escaping in admin/partials/googlecrawl_dfs.php, where the $_GET['place'] value is…
AplazadaAlta (8.6)0.39%—H.view IP CameraAI26/6/202629/6/2026
A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations…
AplazadaAlta (8.6)0.63%—H.view IP CameraAI26/6/202629/6/2026
A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate creation command without proper input validation. This may allow for command execution with elevated…
AplazadaMedia (5.3)0.31%—Gravityplugins GravityviewAI26/6/202626/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.
AplazadaAlta (7.5)0.43%—Panorama Viewer 360 Degree Image AND Video ViewerAI26/6/202626/6/2026
Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.
Pendiente de análisisAlta (8.7)0.68%—Zaproxy ZAPAIZaproxy Viewstate Add-onAI26/6/202614/7/2026
Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState HTTP response parameter. The…
AplazadaMedia (6.5)0.37%—Geminilabs Site ReviewsAI26/6/202626/6/2026
Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.
AplazadaAlta (7.1)0.25%—Cusrev Customer Reviews FOR WoocommerceAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.
AplazadaAlta (7.5)0.60%—Faststone Image ViewerAI26/6/202626/6/2026
An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.
AplazadaMedia (6.5)0.46%—Faststone Image ViewerAI26/6/202626/6/2026
A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the current process via supplying a crafted JPEG 2000 (JP2) file.
AplazadaAlta (7.5)0.35%—Checkview Automated TestingAI25/6/202629/6/2026
Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
AplazadaAlta (7.4)0.28%—Bootstrapped Visual Link PreviewAI25/6/202626/6/2026
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.
AplazadaMedia (4.3)0.42%—Reviews AND Rating DocplannerAI24/6/202625/6/2026
The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access…
AplazadaAlta (7.2)0.38%—URL PreviewAI24/6/202625/6/2026
The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0 via the 'url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify…
AnalizadaAlta (8.8)0.49%—Wdmtech Vreview19/6/202621/8/2026
Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cmId parameter. Attackers can send POST requests to the editReview task endpoint with URL-encoded SQL UNION statements in the cmId…
AplazadaAlta (8.1)0.82%—WP Review Slider PROAI16/6/202617/6/2026
The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function,…
AplazadaAlta (8.8)0.46%—WP Review Slider PROAI16/6/202617/6/2026
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type casting, then concatenating each array…
AplazadaAlta (8.8)0.46%—WP Review Slider PROAI16/6/202617/6/2026
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslashes() on user-supplied JSON strings prior to json_decode(), which…
AplazadaMedia (6.5)0.37%—Bootstrapped Visual Link PreviewAI15/6/202617/6/2026
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions.
AplazadaAlta (7.5)0.43%—Wpdeveloper ReviewxAI15/6/202617/6/2026
Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.