Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.37% | — | Shawfactor LH EmailAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shawfactor LH Email lh-email allows Reflected XSS.This issue affects LH Email: from n/a through <= 1.12. | |
| Aplazada | Alta (7.1) | 0.41% | — | Shawfactor LH Login PageAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shawfactor LH Login Page lh-login-page allows Reflected XSS.This issue affects LH Login Page: from n/a through <= 2.14. | |
| Analizada | Crítica (9.8) | 0.46% | — | Two-factor Authentication Project Two-factor Authentication | 9/1/2025 | 17/6/2026 | Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0. | |
| Analizada | Crítica (9.8) | 0.56% | — | Two-factor Authentication Project Two-factor Authentication | 9/1/2025 | 17/6/2026 | Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0. | |
| Aplazada | Alta (7.1) | 0.28% | — | Wpfactory Wishlist FOR WoocommerceAI | 31/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce.This issue affects Wishlist for WooCommerce: from n/a through <= 3.1.2. | |
| Aplazada | Media (5.3) | 0.35% | — | Webfactoryltd Advanced Google RecaptchaAI | 24/12/2024 | 17/6/2026 | The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, 1.25. This is due to the plugin not utilizing a strong unique key when generating an unblock request. This makes it possible for unauthenticated attackers to unblock their IP after being locked out… | |
| Aplazada | Alta (7.6) | 0.30% | — | Keyfactor CommandAI | 18/12/2024 | 17/6/2026 | Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0. | |
| Aplazada | Media (4.3) | 0.29% | — | Keyfactor Remote File OrchestratorAI | 18/12/2024 | 17/6/2026 | Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensitive information could be exposed at the debug logging level. | |
| Aplazada | Alta (7.1) | 0.21% | — | Wpfactory WP Currency Exchange RatesAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates wp-currency-exchange-rates allows Stored XSS.This issue affects WP Currency Exchange Rates: from n/a through <= 1.2.0. | |
| Aplazada | Media (5.4) | 0.64% | — | Wpfactory Cost OF Goods FOR WoocommerceAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WPFactory Cost of Goods for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cost of Goods for WooCommerce: from n/a through 2.8.6. | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpfactory Awesome ShortcodesAI | 6/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Awesome Shortcodes awesome-shortcodes allows Reflected XSS.This issue affects Awesome Shortcodes: from n/a through <= 1.7.2. | |
| Analizada | Media (6.1) | 0.51% | — | Wpfactory Wishlist FOR Woocommerce | 23/11/2024 | 17/6/2026 | The Wishlist for WooCommerce: Multi Wishlists Per Customer PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wtab' parameter in versions 3.0.8 to 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Analizada | Crítica (9.8) | 2.3% | — | Hiyouga Llama-factory | 21/11/2024 | 17/6/2026 | LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This vulnerability arises from improper handling of user input, allowing malicious actors to execute arbitrary OS commands on the host system. The… | |
| Analizada | Alta (7) | 0.22% | — | Rockwellautomation Factorytalk View | 12/11/2024 | 17/6/2026 | A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory allowing anyone with local access to modify and/or delete files. Additionally, a malicious user could potentially leverage this vulnerability to escalate their privileges by… | |
| Aplazada | Media (6.5) | 0.25% | — | Shawfactor LH QR CodesAI | 11/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shawfactor LH QR Codes lh-qr-codes allows Stored XSS.This issue affects LH QR Codes: from n/a through <= 1.06. | |
| Analizada | Crítica (9.8) | 0.53% | — | Dfactory Responsive Lightbox | 23/10/2024 | 17/6/2026 | Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Lightbox: from n/a through 2.4.7. | |
| Modificada | Media (6.1) | 0.27% | — | Wpfactory Eu/uk VAT Manager FOR Woocommerce | 20/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EU/UK VAT Manager for WooCommerce eu-vat-for-woocommerce.This issue affects EU/UK VAT Manager for WooCommerce: from n/a through <= 2.12.14. | |
| Aplazada | Media (5.9) | 0.27% | — | Dfactory Responsive LightboxAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dFactory Responsive Lightbox responsive-lightbox allows Stored XSS.This issue affects Responsive Lightbox: from n/a through <= 2.4.8. | |
| Aplazada | Crítica (9.3) | 0.41% | — | Wpfactory Emails Verification FOR WoocommerceAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Email Verification for WooCommerce emails-verification-for-woocommerce allows SQL Injection.This issue affects Email Verification for WooCommerce: from n/a through <= 2.8.10. | |
| Analizada | Crítica (9.8) | 0.54% | — | Taismartfactory Qplant SF | 15/10/2024 | 17/6/2026 | SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow a remote attacker to retrieve all database information by sending a specially crafted SQL query to the ‘email’ parameter on the ‘RequestPasswordChange’ endpoint. | |
| Analizada | Alta (8.7) | 0.55% | — | Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Controllogix 5580 Process FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 Firmware+4 | 14/10/2024 | 17/6/2026 | CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To… | |
| Analizada | Media (6.1) | 0.44% | — | Wpfactory Products, Order & Customers Export FOR Woocommerce | 10/10/2024 | 17/6/2026 | The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.15. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (6.1) | 0.38% | — | Wpfactory Maximum Products PER User FOR Woocommerce | 10/10/2024 | 17/6/2026 | The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.2.8. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (6.1) | 0.39% | — | Wpfactory Quantity Dynamic Pricing & Bulk Discounts FOR Woocommerce | 4/10/2024 | 17/6/2026 | The Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to inject… | |
| Analizada | Media (5.3) | 0.48% | — | Wpfactory Eu/uk VAT Manager FOR Woocommerce | 28/9/2024 | 17/6/2026 | The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the alg_wc_eu_vat_exempt_vat_from_admin() function in all versions up to, and including, 2.12.12. This makes it possible for unauthenticated attackers to update the VAT… |