Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
3425 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.68% | — | Trueview Security Camera T18161AI | 7/7/2026 | 10/7/2026 | Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware. | |
| Aplazada | Media (6.4) | 0.33% | — | Reviews Widgets FOR Google Yelp AND TripadvisorAI | 6/7/2026 | 7/7/2026 | The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Shortcode::fbrev()… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpdeveloper ReviewxAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | JetreviewsAI | 2/7/2026 | 2/7/2026 | Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions. | |
| Aplazada | Alta (7.5) | 0.46% | — | WP Review Slider PROAI | 2/7/2026 | 2/7/2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action in versions up to, and including, 12.7.2. The parameter is read via $_POST['notinstring'] and passed through sanitize_text_field() — which strips HTML and whitespace but… | |
| Aplazada | Media (6.1) | 0.37% | — | WP Google Places Review SliderAI | 1/7/2026 | 1/7/2026 | The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, and including, 18.1. This is due to insufficient input sanitization and output escaping in admin/partials/googlecrawl_dfs.php, where the $_GET['place'] value is… | |
| Aplazada | Alta (8.6) | 0.39% | — | H.view IP CameraAI | 26/6/2026 | 29/6/2026 | A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations… | |
| Aplazada | Alta (8.6) | 0.63% | — | H.view IP CameraAI | 26/6/2026 | 29/6/2026 | A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate creation command without proper input validation. This may allow for command execution with elevated… | |
| Aplazada | Media (5.3) | 0.31% | — | Gravityplugins GravityviewAI | 26/6/2026 | 26/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Panorama Viewer 360 Degree Image AND Video ViewerAI | 26/6/2026 | 26/6/2026 | Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions. | |
| Pendiente de análisis | Alta (8.7) | 0.68% | — | Zaproxy ZAPAIZaproxy Viewstate Add-onAI | 26/6/2026 | 14/7/2026 | Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState HTTP response parameter. The… | |
| Aplazada | Media (6.5) | 0.37% | — | Geminilabs Site ReviewsAI | 26/6/2026 | 26/6/2026 | Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Cusrev Customer Reviews FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions. | |
| Aplazada | Alta (7.5) | 0.60% | — | Faststone Image ViewerAI | 26/6/2026 | 26/6/2026 | An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file. | |
| Aplazada | Media (6.5) | 0.46% | — | Faststone Image ViewerAI | 26/6/2026 | 26/6/2026 | A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the current process via supplying a crafted JPEG 2000 (JP2) file. | |
| Aplazada | Alta (7.5) | 0.35% | — | Checkview Automated TestingAI | 25/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions. | |
| Aplazada | Alta (7.4) | 0.28% | — | Bootstrapped Visual Link PreviewAI | 25/6/2026 | 26/6/2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. | |
| Aplazada | Media (4.3) | 0.42% | — | Reviews AND Rating DocplannerAI | 24/6/2026 | 25/6/2026 | The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Alta (7.2) | 0.38% | — | URL PreviewAI | 24/6/2026 | 25/6/2026 | The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0 via the 'url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify… | |
| Analizada | Alta (8.8) | 0.49% | — | Wdmtech Vreview | 19/6/2026 | 21/8/2026 | Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cmId parameter. Attackers can send POST requests to the editReview task endpoint with URL-encoded SQL UNION statements in the cmId… | |
| Aplazada | Alta (8.1) | 0.82% | — | WP Review Slider PROAI | 16/6/2026 | 17/6/2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function,… | |
| Aplazada | Alta (8.8) | 0.46% | — | WP Review Slider PROAI | 16/6/2026 | 17/6/2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type casting, then concatenating each array… | |
| Aplazada | Alta (8.8) | 0.46% | — | WP Review Slider PROAI | 16/6/2026 | 17/6/2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslashes() on user-supplied JSON strings prior to json_decode(), which… | |
| Aplazada | Media (6.5) | 0.37% | — | Bootstrapped Visual Link PreviewAI | 15/6/2026 | 17/6/2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Wpdeveloper ReviewxAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions. |