Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 162 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

329 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.54%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view administrator dashboard.
AplazadaAlta (8.8)0.40%—Superfly Responsive MenuAI2/8/202417/6/2026
The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.29. This is due to missing or incorrect nonce validation on the ajax_handle_delete_icons() function. This makes it possible for unauthenticated attackers to…
AnalizadaMedia (5.9)0.43%—Wpdarko Responsive Tabs30/7/202417/6/2026
The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (4.8)0.28%—Oxilab Responsive Tabs22/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Biplob Adhikari Tabs allows Stored XSS.This issue affects Tabs: from n/a through 4.0.6.
ModificadaMedia (6.1)0.29%—Marcelotorres Simple Responsive Slider20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in marcelotorres Simple Responsive Slider allows Reflected XSS.This issue affects Simple Responsive Slider: from n/a through 0.2.2.5.
AplazadaMedia (6.5)0.26%—Cyberchimps Responsive MobileAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive Mobile allows Stored XSS.This issue affects Responsive Mobile: from n/a through 1.15.1.
AnalizadaMedia (5.4)0.37%—Lepileppanen Responsive Video Embed20/6/202417/6/2026
The Responsive video embed WordPress plugin before 0.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (8.8)0.36%—Awplife Slider Responsive Slideshow10/6/202417/6/2026
Missing Authorization vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow.This issue affects Slider Responsive Slideshow – Image slider, Gallery slideshow: from n/a through 1.4.0.
AnalizadaAlta (8.8)0.36%—Dfactory Responsive Lightbox & Gallery9/6/202417/6/2026
Missing Authorization vulnerability in dFactory Responsive Lightbox.This issue affects Responsive Lightbox: from n/a through 2.4.6.
ModificadaMedia (5.4)0.32%—Cyberchimps Responsive Addons5/6/202417/6/2026
The Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes…
ModificadaMedia (5.4)0.26%—Cyberchimps Responsive4/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive allows Stored XSS.This issue affects Responsive: from n/a through 5.0.3.
AplazadaMedia (6.5)0.36%—Vsourz Digital Responsive Slick SliderAI4/6/202417/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vsourz Digital Responsive Slick Slider WordPress allows Code Injection.This issue affects Responsive Slick Slider WordPress: from n/a through 1.4.
AplazadaMedia (5.4)0.34%—Wpdarko Responsive TabsAI4/6/202417/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Darko Responsive Tabs allows Code Injection.This issue affects Responsive Tabs: from n/a before 4.0.6.
AplazadaAlta (8.8)0.69%—Responsive OWL Carousel FOR ElementorAI31/5/202417/6/2026
The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.0 via the layout parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server,…
AplazadaMedia (5.4)0.33%—Responsive Contact Form Builder Lead Generation PluginAI22/5/202417/6/2026
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes…
AnalizadaCrítica (9.8)0.74%—Arox School ERP Pro+responsive14/5/202417/6/2026
Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, examname, classes_id, es_voucherid, es_class, etc. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the…
AnalizadaMedia (6.1)0.47%—Arox School ERP Pro+responsive14/5/202417/6/2026
Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the index '/schoolerp/office_admin/' in the parameters es_bankacc, es_bank_name, es_bank_pin, es_checkno, es_teller_number, dc1 and dc2. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their…
AnalizadaMedia (6.1)0.44%—Arox School ERP Pro+responsive14/5/202417/6/2026
Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the username and password parameters in '/index.php'. This vulnerability allows an attacker to partially take control of the victim's browser session.
AplazadaMedia (5.3)0.59%—Richteam Slider Carousel Responsive Image SliderAI3/5/202417/6/2026
Missing Authorization vulnerability in Richteam Slider Carousel – Responsive Image Slider.This issue affects Slider Carousel – Responsive Image Slider: from n/a through 1.5.1.
AplazadaAlta (7.5)0.91%—Photo Gallery Responsive Photo Gallery Image Gallery Portfolio Gallery Logo Gallery AND Team GalleryAI2/5/202417/6/2026
The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.2 via deserialization via shortcode of untrusted input from the 'awl_lg_settings_' attribute. This makes it…
AplazadaMedia (4.3)0.27%—Responsive Contact Form Builder Lead Generation PluginAI2/5/202417/6/2026
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on several functions in all versions up to, and including, 1.8.9. This makes it possible for unauthenticated attackers to invoke those functions.
AplazadaMedia (4.3)0.27%—Responsive Contact Form Builder Lead Generation PluginAI2/5/202417/6/2026
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.9. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those…
AplazadaMedia (5.4)0.39%—Kutethemes Ovic Responsive WpbakeryAI18/4/202417/6/2026
Missing Authorization vulnerability in Ovic Team Ovic Responsive WPBakery.This issue affects Ovic Responsive WPBakery: from n/a through 1.3.0.
AnalizadaMedia (5.4)0.50%—Wpdarko Responsive Tabs15/4/202417/6/2026
The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
AplazadaMedia (6.5)0.31%—I13websolution WP Responsive Tabs Horizontal Vertical AND Accordion TabsAI11/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs allows Stored XSS.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17.
Orbitaley — Vulnerabilidades