Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

322 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.3)3.6%💥 ExploitOpenapi-generator Openapi GeneratorAI27/5/202417/6/2026
OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory as…
AnalizadaBaja (3.4)0.23%—Wow-company Button Generator2/5/202417/6/2026
The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack
AplazadaMedia (4.3)0.37%—Supsystic Data Tables GeneratorAI26/4/202417/6/2026
Missing Authorization vulnerability in Supsystic Data Tables Generator by Supsystic.This issue affects Data Tables Generator by Supsystic: from n/a through 1.10.31.
AplazadaCrítica (10)0.70%—Deepak Anand WP Dummy Content GeneratorAI18/4/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator.This issue affects WP Dummy Content Generator: from n/a through <= 3.2.1.
AplazadaMedia (4.3)0.52%—Supsystic Data Tables GeneratorAI17/4/202417/6/2026
Incorrect Authorization vulnerability in Supsystic Data Tables Generator.This issue affects Data Tables Generator: from n/a through 1.10.25.
AplazadaMedia (5.9)0.34%—Hideki Tanaka What S NEW GeneratorAI17/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hideki Tanaka What's New Generator allows Stored XSS.This issue affects What's New Generator: from n/a through 2.0.2.
ModificadaAlta (8.8)0.22%—Themeisle Multiple Page Generator12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
AplazadaMedia (6.3)0.52%—AI Post GeneratorAI9/4/202417/6/2026
The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized access, modification or deletion of posts due to a missing capability check on functions hooked by AJAX actions in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with subscriber access or…
ModificadaAlta (7.2)0.60%—Themeisle Multiple Page Generator3/4/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows Upload a Web Shell to a Web Server.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
ModificadaMedia (4.3)0.18%—Logicore Pocket News Generator29/3/202417/6/2026
The Pocket News Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.0. This is due to missing or incorrect nonce validation on the option_page() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged…
ModificadaMedia (4.8)0.32%—Logicore Pocket News Generator29/3/202417/6/2026
The Pocket News Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as "Consumer Key" and "Access Token" in all versions up to, and including, 0.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
ModificadaAlta (7.2)2.3%💥 ExploitWensolutions WP Child Theme Generator26/3/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.
ModificadaAlta (8.8)0.44%—Themeisle Multiple Page Generator26/3/202417/6/2026
Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
AplazadaMedia (5.3)0.36%—Deepak Anand WP Dummy Content GeneratorAI26/3/202417/6/2026
Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 3.1.2.
AnalizadaMedia (6.1)0.43%—Tabatkins Railroad-diagram Generator26/2/202417/6/2026
A DOM based cross-site scripting (XSS) vulnerability in the component generator.html of tabatkins/railroad-diagrams before commit ea9a123 allows attackers to execute arbitrary Javascript via sending a crafted URL.
ModificadaMedia (5.4)0.39%—Wpmanageninja PDF Generator FOR Fluent Forms5/2/202417/6/2026
The PDF Generator For Fluent Forms – The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the header, PDF body and footer content parameters in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for…
ModificadaCrítica (9.8)0.59%—Projectworlds Online Time Table Generator19/1/202417/6/2026
A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file course_ajax.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
ModificadaAlta (7.2)0.54%—Wpzinc Page Generator31/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Zinc Page Generator.This issue affects Page Generator: from n/a through 1.7.1.
ModificadaMedia (6.1)0.51%—Code-projects QR Code Generator29/12/202317/6/2026
A vulnerability was found in code-projects QR Code Generator 1.0. It has been classified as problematic. This affects an unknown part of the file /download.php?file=author.png. The manipulation of the argument file with the input "><iMg src=N onerror=alert(document.domain)> leads to cross site scripting. It is…
ModificadaAlta (8.8)0.29%—Wow-company Button Generator18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder.This issue affects Button Generator – easily Button Builder: from n/a through 2.3.8.
ModificadaMedia (6.1)0.75%—Oretnom23 Simple Invoice Generator System10/12/202317/6/2026
A vulnerability was found in SourceCodester Simple Invoice Generator System 1.0 and classified as problematic. This issue affects some unknown processing of the file login.php. The manipulation of the argument cashier leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed…
ModificadaAlta (8.8)0.32%—Webternsolutions Video XML Sitemap Generator18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tradebooster Video XML Sitemap Generator.This issue affects Video XML Sitemap Generator: from n/a through 1.0.0.
ModificadaMedia (6.1)0.24%—Baidu-tongji-generator Project Baidu-tongji-generator13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Haoqisir Baidu Tongji generator allows Stored XSS.This issue affects Baidu Tongji generator: from n/a through 1.0.2.
ModificadaAlta (8.8)0.30%—Wpgrim Dynamic XML Sitemaps Generator FOR Google13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPGrim Dynamic XML Sitemaps Generator for Google plugin <= 1.3.3 versions.
ModificadaCrítica (9.8)0.59%—Creative-solutions Contact Form Generator6/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creative Solutions Contact Form Generator : Creative form builder for WordPress allows SQL Injection.This issue affects Contact Form Generator : Creative form builder for WordPress: from n/a through 2.6.0.
Orbitaley — Vulnerabilidades