Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

172 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)4.8%💥 ExploitBlocksera Cryptocurrency Widgets Pack2/1/202317/6/2026
The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
ModificadaMedia (4.8)0.56%—Codelights-shortcodes-and-widgets Project Codelights-shortcodes-and-widgets20/12/202217/6/2026
The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Extra CSS class’ parameter in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
ModificadaCrítica (9.8)2.3%💥 ExploitBlocksera Cryptocurrency Widgets Pack15/12/202217/6/2026
Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.
ModificadaMedia (5.4)0.60%—Bootstrapped Dynamic Widgets28/2/202217/6/2026
The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (5.7)0.42%—Catchplugins Catch Scroll Progress BARCatchplugins Catch Sticky MenuCatchplugins Catch Themes Demo ImportCatchplugins Catch Under Construction+618/10/202117/6/2026
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before…
ModificadaMedia (5.4)0.59%—Crocoblock Jetwidgets FOR Elementor5/5/202117/6/2026
The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
ModificadaMedia (5.3)2.1%💥 ExploitThrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+1612/4/202117/6/2026
The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive…
ModificadaMedia (5.4)0.97%—Widgets Project Widgets24/2/202017/6/2026
An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser function.
ModificadaMedia (5.4)1.0%—Display-widgets Project Display-widgets26/9/201917/6/2026
The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_base, widget_number, or instance parameter.
ModificadaMedia (6.5)0.88%—Vivwebsolutions Dynamic Widgets26/9/201917/6/2026
The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit parameter.
ModificadaMedia (5.4)1.0%—Vivwebsolutions Dynamic Widgets26/9/201917/6/2026
The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix or widget_id parameter.
ModificadaMedia (4.3)2.0%—Widgets Project Widgets1/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Widgets extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors involving base64 encoded content.
ModificadaMedia (5.4)0.27%—Awesomewidgets Rasta Weed Widgets HD22/9/201417/6/2026
The Rasta Weed Widgets HD (aka aw.awesomewidgets.rastaweed) application 4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4)1.1%—Autocomplete Widgets Project Autocomplete Widgets9/6/201416/6/2026
The autocomplete callback in Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-rc1 does not properly handle node permissions, which allows remote authenticated users to obtain sensitive field values via unspecified vectors.
ModificadaMedia (6.8)2.8%—Wxwidgets8/7/200916/6/2026
Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JPEG file, which triggers a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details…
ModificadaAlta (7.5)1.3%—Codewidgets Online Event Registration Template29/10/200716/6/2026
Multiple SQL injection vulnerabilities in CodeWidgets.com Online Event Registration Template allow remote attackers to execute arbitrary SQL commands via the (1) Email Address and (2) Password fields in (a) login.asp and (b) admin_login.asp.
ModificadaAlta (7.5)1.2%💥 ExploitCodewidgets Online Event Registration Template31/7/200716/6/2026
SQL injection vulnerability in sign_in.aspx in WebStore (Online Store Application Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaAlta (7.5)1.3%—Codewidgets Online Event Registration Template31/7/200716/6/2026
SQL injection vulnerability in sign_in.aspx in WebEvents (Online Event Registration Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaAlta (7.5)1.2%💥 ExploitCodewidgets Threaded Discussion Forum Application31/7/200716/6/2026
SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaMedia (6.8)1.1%💥 ExploitCodewidgets Real Estate Listing Website Application Template31/7/200716/6/2026
SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaMedia (6.8)1.1%💥 ExploitCodewidgets PAY Roll - Time SheetCodewidgets Punch Card31/7/200716/6/2026
SQL injection vulnerability in login.asp in CodeWidgets Pay Roll - Time Sheet and Punch Card Application With Web Interface allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaAlta (9.3)13%💥 ExploitYahoo Widgets27/7/200716/6/2026
Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets before 4.0.5 allows remote attackers to execute arbitrary code via a long argument to the GetComponentVersion method. NOTE: some of these…
Orbitaley — Vulnerabilidades