Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

736 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.40%—Expresstech Quiz AND Survey Master23/9/202417/6/2026
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaMedia (4.7)0.49%—Openjsf Express10/9/202417/6/2026
Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.
AnalizadaMedia (4.3)0.32%—Cisco Expressway-e4/9/202417/6/2026
A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system. This vulnerability is due to inadequate authorization checks for Mobile and Remote Access (MRA) users. An attacker could exploit this vulnerability by running a…
AnalizadaMedia (4.7)0.43%—Expresstech Quiz AND Survey Master26/8/202417/6/2026
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.
AnalizadaMedia (5.9)0.33%—Expresstech Quiz AND Survey Master3/8/202417/6/2026
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
AnalizadaAlta (7.5)0.41%—Thisfunctional CTT Expresso Para Woocommerce1/8/202417/6/2026
The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions up to and including 3.2.12 via the /wp-content/uploads/cepw directory. The generated .pdf and log files are publicly accessible and contain sensitive information such as sender and receiver names,…
ModificadaMedia (6.1)0.27%—Ali2woo Aliexpress Dropshipping With Alinext22/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ali2Woo Team Ali2Woo Lite allows Reflected XSS.This issue affects Ali2Woo Lite: from n/a through 3.3.5.
ModificadaMedia (5.4)0.27%—Celloexpressions Floating Social Media Links21/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nick Halsey Floating Social Media Links allows Stored XSS.This issue affects Floating Social Media Links: from n/a through 1.5.2.
ModificadaMedia (5.4)0.38%—Expresstech Quiz AND Survey Master11/7/202417/6/2026
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks
ModificadaAlta (8.8)0.59%—Expresstech Quiz AND Survey Master2/7/202417/6/2026
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role
AnalizadaMedia (5.5)0.35%—Expresstech Quiz AND Survey Master1/7/202417/6/2026
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
AnalizadaAlta (8.8)0.21%—Ali2woo Aliexpress Dropshipping With Alinext21/6/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ali2Woo Ali2Woo Lite.This issue affects Ali2Woo Lite: from n/a through 3.3.5.
ModificadaCrítica (9.8)0.69%—Icegram Express21/6/202417/6/2026
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.23 due to insufficient escaping on the user supplied parameter and lack of…
ModificadaMedia (6.3)0.33%—Ali2woo Aliexpress Dropshipping With Alinext19/6/202417/6/2026
The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ImportAjaxController.php file in all versions up to, and including, 3.3.6. This makes it possible for authenticated attackers, with subscriber-level…
ModificadaAlta (8.8)0.91%—Ali2woo Aliexpress Dropshipping With Alinext19/6/202417/6/2026
The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_save_image function in all versions up to, and including, 3.3.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
ModificadaMedia (6.1)0.30%—Expressionengine16/6/202417/6/2026
ExpressionEngine before 7.4.11 allows XSS.
ModificadaMedia (5.3)0.31%—Expresstech Quiz AND Survey Master14/6/202417/6/2026
Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16.
ModificadaAlta (8.8)0.45%—Icegram Express12/6/202417/6/2026
The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all versions up to, and including, 5.7.22 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
ModificadaMedia (5.4)0.30%—Icegram Express8/6/202417/6/2026
Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21.
ModificadaMedia (5.4)0.26%—Horea Radu ONE Page Express Companion7/6/202417/6/2026
The One Page Express Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's one_page_express_contact_form shortcode in all versions up to, and including, 1.6.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaMedia (6.5)0.48%—Expresstech Quiz AND Survey Master7/6/202417/6/2026
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaAlta (7.5)0.52%—Tips AND Tricks HQ WP Express CheckoutAI17/5/202417/6/2026
Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7.
AnalizadaAlta (7.3)0.26%—Tramyardg Autoexpress19/4/202417/6/2026
SQL Injection vulnerability in autoexpress v.1.3.0 allows attackers to run arbitrary SQL commands via the carId parameter.
AplazadaMedia (5.9)0.34%—Expresstechsoftware Quiz AND Survey MasterAI11/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 8.2.2.
AplazadaMedia (5.3)0.40%—Sharkdropship FOR Aliexpress Dropshipping AND AffiliateAI2/4/202417/6/2026
The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wads_removeProductFromShop() function in all versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to delete…