Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

228 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.0%—Commentapp.stetsonwood Project Commentapp.stetsonwood7/6/201817/6/2026
commentapp.stetsonwood is an http server. commentapp.stetsonwood is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (8.8)1.6%—Disable Comments Project19/3/201817/6/2026
Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that enable comments via a request to the disable_comments_settings page to wp-admin/options-general.php.
ModificadaAlta (8.8)0.91%—Subscribe TO Comments Reloaded Project Subscribe TO Comments Reloaded19/3/201817/6/2026
Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the…
ModificadaCrítica (9.1)8.6%—Contussupport Contus-video-comments6/10/201617/6/2026
Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin
ModificadaMedia (6.8)1.0%—Wpcommenttwit Project Wpcommenttwit19/12/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the wpCommentTwit plugin 0.5 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) username or (2) password parameter in the wpCommentTwit.php…
ModificadaMedia (6.8)4.9%💥 ExploitDisqus Comment System19/8/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) disqus_replace, (2) disqus_public_key, or (3)…
ModificadaMedia (6.8)2.7%💥 ExploitDisqus Comment System19/8/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin 2.77 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) activate or (2) deactivate the plugin via the active parameter to wp-admin/edit-comments.php, (3) import comments…
ModificadaMedia (4.3)6.1%💥 ExploitDisqus Comment System19/8/201417/6/2026
Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.
ModificadaMedia (4.3)1.6%—Verification Code FOR Comments Project Verification Code FOR Comments2/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in the Verification Code for Comments plugin 2.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) vp, (2) vs, (3) l, (4) vu, or (5) vm parameter.
ModificadaMedia (6.8)2.6%💥 ExploitFeatured Comments Plugin Project Featured Comments16/6/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that change the (1) buried or (2) featured status of a comment via a request to wp-admin/admin-ajax.php.
ModificadaMedia (4.3)4.5%💥 ExploitCommentluv3/3/201416/6/2026
Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/admin-ajax.php.
ModificadaMedia (4.3)1.3%💥 ExploitJoomla COM Jvcomment26/1/201417/6/2026
SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a comment.like action to index.php.
ModificadaMedia (4.3)2.0%—Wearegumball Comment-attachment3/10/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Comment Attachment plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Attachment field title."
ModificadaMedia (4.3)2.1%💥 ExploitVanillaforums Latestcomment23/5/201316/6/2026
Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web script or HTML via the discussion title.
ModificadaMedia (6.8)0.78%—David Stosik Comment Moderation21/6/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in the Comment Moderation module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to hijack the authentication of administrators for requests that publish comments.
ModificadaMedia (4.3)2.1%—Mg12 Wp-recentcomments14/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.
ModificadaAlta (7.5)2.0%—Mg12 Wp-recentcomments14/2/201216/6/2026
SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.7%💥 ExploitJoomlatune COM Jcomments23/11/201116/6/2026
Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inject arbitrary web script or HTML via the name parameter to index.php.
ModificadaAlta (7.5)1.0%—Raphael Zschorsch Commentsbe7/10/201116/6/2026
SQL injection vulnerability in the Commenting system Backend Module (commentsbe) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.0%—Jxtended Comments9/12/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the JXtended Comments component before 1.3.1 for Joomla allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.7%💥 ExploitRsjoomla COM Rscomments25/6/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.
ModificadaAlta (7.5)13%💥 ExploitM0r0n COM Mscomment25/5/201016/6/2026
Directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)16%💥 ExploitZimbllc COM Zimbcomment29/4/201016/6/2026
Directory traversal vulnerability in the ZiMB Comment (com_zimbcomment) component 0.8.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
ModificadaMedia (5)16%💥 ExploitJoomlamart COM Jacomment29/4/201016/6/2026
Directory traversal vulnerability in the JA Comment (com_jacomment) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.
ModificadaMedia (4.3)1.1%—Alkacon Oamp Comments26/3/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in OpenCMS OAMP Comments Module 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the name field in a comment, and other unspecified vectors.
Orbitaley — Vulnerabilidades