Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

267 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.33%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional31/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional allows Reflected XSS.This issue affects WOLF – WordPress Posts Bulk Editor and Manager Professional: from n/a through 1.0.8.
ModificadaAlta (8.8)0.27%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional25/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7.1 versions.
ModificadaMedia (4.8)0.28%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional17/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7.1 versions.
ModificadaMedia (4.8)0.44%—Mrdemonwolf Livestream Notice30/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MrDemonWolf Livestream Notice plugin <= 1.2.0 versions.
ModificadaMedia (4.8)0.37%—Wolfgangertl Weebotlite25/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wolfgang Ertl weebotLite plugin <= 1.0.0 versions.
ModificadaMedia (6.1)0.21%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional18/8/202317/6/2026
Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.6 versions.
ModificadaCrítica (9.8)0.95%—Wolf18 Easyadmin815/8/202317/6/2026
File Upload vulnerability in Wolf-leo EasyAdmin8 v.1.0 allows a remote attacker to execute arbtirary code via the upload type function.
ModificadaMedia (6.6)0.64%—Wolfcode Easyadmin820/7/202317/6/2026
A vulnerability was found in EasyAdmin8 2.0.2.2. It has been classified as problematic. Affected is an unknown function of the file /admin/index/index.html#/admin/mall.goods/index.html of the component File Upload Module. The manipulation leads to unrestricted upload. The complexity of an attack is rather high. The…
ModificadaAlta (8.8)0.65%—Wolfssl17/7/202317/6/2026
If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default predictable buffer gets used for the IKM (Input Keying Material) value when generating the session master secret. Using a potentially known IKM value when generating the…
ModificadaAlta (8.8)0.26%—Pluginus Wolf - Wordpress Posts Bulk Editor AND Manager Professional22/6/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7 versions.
ModificadaAlta (7.5)0.29%—Blitzwolf Bw-is22 Firmware24/5/202317/6/2026
Weak security in the transmitter of Blitzwolf BW-IS22 Smart Home Security Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.
ModificadaCrítica (9.1)2.1%—Wolfssl7/11/202217/6/2026
In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes. (WOLFSSL_CALLBACKS is only intended for debugging.)
ModificadaMedia (5.3)0.57%—Wolfssl15/10/202217/6/2026
An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclosure. Users performing signing operations with private ECC keys, such as in server-side TLS connections, might leak faulty ECC signatures. These signatures can be processed via an advanced technique…
ModificadaAlta (7.5)5.8%—Wolfssl29/9/202217/6/2026
In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous TLS session. During the resumption Client Hello a Hello Retry Request must be triggered. Both Client Hellos are required to contain a list of duplicate cipher…
ModificadaMedia (5.9)0.74%—Wolfssl2/9/202217/6/2026
wolfSSL through 5.0.0 allows an attacker to cause a denial of service and infinite loop in the client component by sending crafted traffic from a Machine-in-the-Middle (MITM) position. The root cause is that the client module accepts TLS messages that normally are only sent to TLS servers.
ModificadaMedia (5.9)2.3%—Wolfssl31/8/202217/6/2026
An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is exploitable. Man-in-the-middle attackers or a malicious server can crash TLS 1.2 clients during a handshake. If an attacker injects a large ticket (more than 256 bytes) into a NewSessionTicket message…
ModificadaAlta (7.5)2.7%—Wolfssl31/8/202217/6/2026
An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its session, the server crashes with a segmentation fault. This occurs in the second session, which is created through TLS session resumption and reuses the initial struct WOLFSSL. If the…
ModificadaAlta (7.5)1.4%—Wolfssl8/8/202217/6/2026
wolfSSL before 5.4.0 allows remote attackers to cause a denial of service via DTLS because a check for return-routability can be skipped.
ModificadaCrítica (9.8)1.9%💥 PoCWolfssh13/7/202217/6/2026
WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR.
ModificadaMedia (6.8)0.86%—Joyebike Wolf 2022 Firmware29/6/202217/6/2026
Joy ebike Wolf Manufacturing year 2022 is vulnerable to Denial of service, which allows remote attackers to jam the key fob request via RF.
ModificadaMedia (6.1)0.85%—Wolfcms Wolf CMS9/6/202217/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfcms/?/admin/user/add of the component User Add. The manipulation of the argument name leads to basic cross site scripting. The attack may be…
ModificadaMedia (6.5)0.65%—Joybike Wolf Firmware7/6/202217/6/2026
joyebike Joy ebike Wolf Manufacturing year 2022 is vulnerable to Authentication Bypass by Capture-replay.
ModificadaAlta (7.5)1.4%💥 PoCWolfssl24/2/202217/6/2026
In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.
ModificadaMedia (6.5)0.63%—Wolfssl24/2/202217/6/2026
In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differs between the certificate_verify message and the certificate message.
ModificadaCrítica (9.1)1.4%—Wolfssl18/1/202217/6/2026
wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations. This affects connections (without AEAD) using AES-CBC or DES3 with TLS 1.1 or 1.2 or DTLS 1.1 or 1.2. This occurs because of misplaced memory initialization in BuildMessage in internal.c.
Orbitaley — Vulnerabilidades