Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
380 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.24% | — | Pluginus Wordpress Meta Data AND Taxonomies Filter | 29/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.1. | |
| Modificada | Alta (7.2) | 0.76% | — | Pluginus Husky - Products Filter Professional FOR Woocommerce | 29/3/2024 | 17/6/2026 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.5.2 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary… | |
| Modificada | Media (6.1) | 0.42% | — | Pluginus Wordpress Meta Data AND Taxonomies Filter | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Reflected XSS.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3. | |
| Modificada | Media (5.4) | 0.35% | — | Pluginus Wordpress Meta Data AND Taxonomies Filter | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Stored XSS.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.2. | |
| Modificada | Media (5.4) | 0.33% | — | Pluginus Wordpress Meta Data AND Taxonomies Filter | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Stored XSS.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.2. | |
| Modificada | Alta (8.8) | 0.23% | — | Pluginus Husky - Products Filter Professional FOR Woocommerce | 15/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 HUSKY – Products Filter for WooCommerce (formerly WOOF).This issue affects HUSKY – Products Filter for WooCommerce (formerly WOOF): from n/a through 1.3.4.3. | |
| Modificada | Media (5.4) | 0.34% | — | Pluginus Husky - Products Filter Professional FOR Woocommerce | 15/3/2024 | 17/6/2026 | The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'woof' shortcode in all versions up to, and including, 1.3.5.1 due to insufficient input sanitization and output escaping on user supplied attributes such as 'swoof_slug'. This… | |
| Modificada | Alta (8.8) | 0.56% | — | Pluginus Husky - Products Filter Professional FOR Woocommerce | 15/3/2024 | 17/6/2026 | The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to SQL Injection via the 'name' parameter in the woof shortcode in all versions up to, and including, 1.3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Modificada | Alta (8.8) | 0.21% | — | Developingtheweb Quicksand Post Filter Jquery | 21/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from n/a through 3.1.1. | |
| Modificada | Alta (7.8) | 0.13% | — | Intel HID Event Filter Driver | 19/1/2024 | 17/6/2026 | Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 0.45% | — | Berocket Advanced Ajax Product Filters | 16/1/2024 | 17/6/2026 | The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting issue. | |
| Modificada | Crítica (9.8) | 0.59% | — | Pluginus Husky - Products Filter Professional FOR Woocommerce | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in realmag777 HUSKY – Products Filter for WooCommerce Professional.This issue affects HUSKY – Products Filter for WooCommerce Professional: from n/a through 1.3.4.2. | |
| Modificada | Crítica (9.8) | 0.66% | — | Nxfilter | 18/12/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Jahastech NxFilter 4.3.2.5. This issue affects some unknown processing of the file user,adap.jsp?actionFlag=test&id=1 of the component Bind Request Handler. The manipulation leads to ldap injection. The attack may be initiated remotely. The… | |
| Modificada | Alta (8.8) | 0.31% | — | Nxfilter | 17/12/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Jahastech NxFilter 4.3.2.5. This vulnerability affects unknown code of the file /config,admin.jsp. The manipulation of the argument admin_name leads to cross-site request forgery. The attack can be initiated remotely. VDB-248266 is the identifier assigned to this… | |
| Modificada | Alta (8.8) | 0.26% | — | Andrealandonio Taxonomy Filter | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Andrea Landonio Taxonomy filter allows Cross Site Request Forgery.This issue affects Taxonomy filter: from n/a through 2.2.9. | |
| Modificada | Media (6.1) | 0.49% | — | Communitydeveloper Amazzing Filter | 28/11/2023 | 17/6/2026 | Cross Site Scripting (XSS) in Search filters in Prestashop Amazzing filter version up to version 3.2.5, allows remote attackers to inject arbitrary JavaScript code. | |
| Modificada | Media (5.4) | 0.37% | — | Jonashjalmarsson Html Filter AND Csv-file Search | 22/11/2023 | 17/6/2026 | The HTML filter and csv-file search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'csvsearch' shortcode in versions up to, and including, 2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Alta (7.3) | 0.21% | — | Intel HID Event Filter Driver | 14/11/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) NUC 12 Pro Kits & Mini PCs - NUC12WS Intel(R) HID Event Filter Driver installation software before version 2.2.2.1 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 0.41% | — | Antonbond Additional Order Filters FOR Woocommerce | 13/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Anton Bond Additional Order Filters for WooCommerce plugin <= 1.10 versions. | |
| Modificada | Alta (8.8) | 0.85% | — | Jonashjalmarsson Html Filter AND Csv-file Search | 31/10/2023 | 17/6/2026 | The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 via the 'src' attribute of the 'csvsearch' shortcode. This allows authenticated attackers, with contributor-level permissions and above, to include and execute arbitrary files on the… | |
| Modificada | Media (5.4) | 0.44% | — | Vektor-inc VK Filter Search | 27/10/2023 | 17/6/2026 | The VK Filter Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk_filter_search' shortcode in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Modificada | Media (6.1) | 0.33% | — | ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters | 26/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions. | |
| Analizada | Alta (8.8) | 0.26% | — | ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions. | |
| Modificada | Media (5.4) | 0.51% | — | Awplife Blog Filter | 4/10/2023 | 17/6/2026 | The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'AWL-BlogFilter' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Modificada | Media (5.4) | 0.40% | — | Awplife Blog Filter | 30/9/2023 | 17/6/2026 | The Comments by Startbit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vivafbcomment' shortcode in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… |