Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 4.8% | 💥 Exploit | Blocksera Cryptocurrency Widgets Pack | 2/1/2023 | 17/6/2026 | The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Modificada | Media (4.8) | 0.56% | — | Codelights-shortcodes-and-widgets Project Codelights-shortcodes-and-widgets | 20/12/2022 | 17/6/2026 | The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Extra CSS class’ parameter in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Modificada | Crítica (9.8) | 2.3% | 💥 Exploit | Blocksera Cryptocurrency Widgets Pack | 15/12/2022 | 17/6/2026 | Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress. | |
| Modificada | Media (5.4) | 0.60% | — | Bootstrapped Dynamic Widgets | 28/2/2022 | 17/6/2026 | The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (5.7) | 0.42% | — | Catchplugins Catch Scroll Progress BARCatchplugins Catch Sticky MenuCatchplugins Catch Themes Demo ImportCatchplugins Catch Under Construction+6 | 18/10/2021 | 17/6/2026 | Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before… | |
| Modificada | Media (5.4) | 0.59% | — | Crocoblock Jetwidgets FOR Elementor | 5/5/2021 | 17/6/2026 | The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. | |
| Modificada | Media (5.3) | 2.1% | 💥 Exploit | Thrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+16 | 12/4/2021 | 17/6/2026 | The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive… | |
| Modificada | Media (5.4) | 0.97% | — | Widgets Project Widgets | 24/2/2020 | 17/6/2026 | An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser function. | |
| Modificada | Media (5.4) | 1.0% | — | Display-widgets Project Display-widgets | 26/9/2019 | 17/6/2026 | The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_base, widget_number, or instance parameter. | |
| Modificada | Media (6.5) | 0.88% | — | Vivwebsolutions Dynamic Widgets | 26/9/2019 | 17/6/2026 | The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit parameter. | |
| Modificada | Media (5.4) | 1.0% | — | Vivwebsolutions Dynamic Widgets | 26/9/2019 | 17/6/2026 | The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix or widget_id parameter. | |
| Modificada | Media (4.3) | 2.0% | — | Widgets Project Widgets | 1/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Widgets extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors involving base64 encoded content. | |
| Modificada | Media (5.4) | 0.27% | — | Awesomewidgets Rasta Weed Widgets HD | 22/9/2014 | 17/6/2026 | The Rasta Weed Widgets HD (aka aw.awesomewidgets.rastaweed) application 4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4) | 1.1% | — | Autocomplete Widgets Project Autocomplete Widgets | 9/6/2014 | 16/6/2026 | The autocomplete callback in Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-rc1 does not properly handle node permissions, which allows remote authenticated users to obtain sensitive field values via unspecified vectors. | |
| Modificada | Media (6.8) | 2.8% | — | Wxwidgets | 8/7/2009 | 16/6/2026 | Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JPEG file, which triggers a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details… | |
| Modificada | Alta (7.5) | 1.3% | — | Codewidgets Online Event Registration Template | 29/10/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in CodeWidgets.com Online Event Registration Template allow remote attackers to execute arbitrary SQL commands via the (1) Email Address and (2) Password fields in (a) login.asp and (b) admin_login.asp. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Codewidgets Online Event Registration Template | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in sign_in.aspx in WebStore (Online Store Application Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Codewidgets Online Event Registration Template | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in sign_in.aspx in WebEvents (Online Event Registration Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Codewidgets Threaded Discussion Forum Application | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Codewidgets Real Estate Listing Website Application Template | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Codewidgets PAY Roll - Time SheetCodewidgets Punch Card | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in login.asp in CodeWidgets Pay Roll - Time Sheet and Punch Card Application With Web Interface allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Alta (9.3) | 13% | 💥 Exploit | Yahoo Widgets | 27/7/2007 | 16/6/2026 | Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets before 4.0.5 allows remote attackers to execute arbitrary code via a long argument to the GetComponentVersion method. NOTE: some of these… |