Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.26% | — | Wpgogo Custom Post Type Page Template | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Post Type Page Template.This issue affects Custom Post Type Page Template: from n/a through 1.1. | |
| Modificada | Media (6.1) | 0.41% | — | Gillesdumas Which Template File | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gilles Dumas which template file allows Reflected XSS.This issue affects which template file: from n/a through 4.9.0. | |
| Modificada | Media (5.4) | 0.40% | — | Brainstormforce Starter Templates | 7/12/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4. | |
| Modificada | Alta (7.5) | 0.97% | 💥 PoC | Themeisle Cloud Templates & Patterns Collection | 23/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeIsle Cloud Templates & Patterns collection.This issue affects Cloud Templates & Patterns collection: from n/a through 1.2.2. | |
| Modificada | Media (6.1) | 0.41% | — | Ioannup Edit Woocommerce Templates | 16/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ioannup Edit WooCommerce Templates plugin <= 1.1.1 versions. | |
| Modificada | Alta (8.8) | 0.28% | — | Wpexperts Email Templates Customizer AND Designer | 7/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpexpertsio Email Templates Customizer and Designer for WordPress and WooCommerce email-templates allows Cross Site Request Forgery.This issue affects Email Templates Customizer and Designer for WordPress and WooCommerce: from n/a through 1.4.2. | |
| Modificada | Alta (7.5) | 0.61% | — | Templately | 6/11/2023 | 17/6/2026 | The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts. | |
| Modificada | Media (6.1) | 0.29% | — | Ericteubert Archivist - Custom Archive Templates | 27/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.5 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Gillesdumas Which Template File | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Gilles Dumas which template file plugin <= 4.6.0 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Dotsquares WP Custom Post Template | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dotsquares WP Custom Post Template <= 1.0 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Praveengoswami Advanced Category Template | 17/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Praveen Goswami Advanced Category Template plugin <= 0.1 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Wpgogo Custom Field Template | 7/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.9 versions. | |
| Modificada | Alta (7.5) | 46% | 💥 Exploit | Templatecookie Adlisting | 5/8/2023 | 17/6/2026 | A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-list of the component Redirect Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The identifier of this… | |
| Modificada | Alta (8.8) | 0.59% | — | Axis License Plate Verifier | 3/8/2023 | 17/6/2026 | User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections. | |
| Modificada | Alta (8.8) | 0.83% | — | Axis License Plate Verifier | 3/8/2023 | 17/6/2026 | User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution. | |
| Modificada | Alta (8.8) | 0.83% | — | Axis License Plate Verifier | 3/8/2023 | 17/6/2026 | User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution. | |
| Modificada | Crítica (9.8) | 0.63% | — | Axis License Plate Verifier | 3/8/2023 | 17/6/2026 | Due to insufficient file permissions, unprivileged users could gain access to unencrypted administrator credentials allowing the configuration of the application. | |
| Modificada | Crítica (9.8) | 0.63% | — | Axis License Plate Verifier | 3/8/2023 | 17/6/2026 | Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface towards 3rd party systems. | |
| Modificada | Alta (8.8) | 0.67% | — | Axis License Plate Verifier | 3/8/2023 | 17/6/2026 | A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges. | |
| Modificada | Media (4.3) | 0.38% | — | Coolplugins Process Steps Template Designer | 12/7/2023 | 17/6/2026 | The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save field icons via a forged request… | |
| Modificada | Alta (8.8) | 0.26% | — | Template Debugger Project Template Debugger | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Danny Hearnah - ChubbyNinjaa Template Debugger plugin <= 3.1.2 versions. | |
| Modificada | Alta (8.8) | 0.32% | — | Wpgogo Custom Field Template | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.8 versions. | |
| Modificada | Media (4.3) | 0.38% | — | Wpgogo Custom Field Template | 1/7/2023 | 17/6/2026 | The Custom Field Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on the edit_meta_value() function. This makes it possible for unauthenticated attackers to edit meta field values via a forged request… | |
| Modificada | Media (5.4) | 0.75% | — | Jenkins Template Workflows | 14/6/2023 | 17/6/2026 | Jenkins Template Workflows Plugin 41.v32d86a_313b_4a and earlier does not escape names of jobs used as buildings blocks for Template Workflow Job, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create jobs. | |
| Modificada | Media (6.1) | 0.45% | — | Udecode Plate | 9/6/2023 | 17/6/2026 | @udecode/plate-link is the link handler for the udecode/plate rich-text editor plugin system for Slate & React. Affected versions of the link plugin and link UI component do not sanitize URLs to prevent use of the `javascript:` scheme. As a result, links with JavaScript URLs can be inserted into the Plate editor… |