Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.47% | — | Microsoft ExcelMicrosoft PowerpointMicrosoft WordMicrosoft Windows 10 1607+12 | 9/6/2026 | 23/7/2026 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft ExcelMicrosoft PowerpointMicrosoft WordMicrosoft Windows 10 1607+12 | 9/6/2026 | 23/7/2026 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |
| Aplazada | Crítica (9.3) | 0.84% | — | Wordpress Background Image CropperAI | 8/6/2026 | 23/7/2026 | WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitrary files by accessing the ups.php endpoint. Attackers can upload PHP files through the file upload form in the plugin directory to execute arbitrary code on the server. | |
| Aplazada | Alta (8.7) | 0.53% | — | Wordpress Augmented RealityAI | 8/6/2026 | 23/7/2026 | WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to upload and execute arbitrary PHP files. Attackers can send POST requests to the connector.minimal.php endpoint with mkfile and put commands to create malicious PHP files… | |
| Aplazada | Media (6.9) | 0.34% | — | Admin Word Count ColumnAI | 8/6/2026 | 23/7/2026 | WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting null byte injection in the path parameter. Attackers can send GET requests to download-csv.php with a crafted path parameter containing directory traversal… | |
| Aplazada | Media (5.1) | 0.17% | — | Wordpress Popup BuilderAI | 4/6/2026 | 22/7/2026 | WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payloads in the post_title… | |
| Aplazada | Media (4.4) | 0.39% | — | Word ReplacerAI | 2/6/2026 | 22/7/2026 | The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in all versions up to, and including, 0.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and… | |
| Aplazada | Alta (7.5) | 0.42% | — | Wordplus BP Better MessagesAI | 27/5/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Better Messages: from n/a through <= 2.14.16. | |
| Aplazada | Media (6.5) | 0.33% | — | Strategy11 Another Wordpress Classifieds PluginAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AWP Classifieds: from n/a through <= 4.4.5. | |
| Aplazada | Media (6.4) | 0.26% | — | Team Master Modern Wordpress Team Showcase Team MasterAI | 27/5/2026 | 17/6/2026 | The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.21% | — | Wordpress Ultimate Form Builder LiteAI | 23/5/2026 | 23/7/2026 | WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter. Attackers can send POST requests to the admin-ajax.php endpoint with the… | |
| Aplazada | Media (4.6) | 0.17% | — | Siber Systems Roboform Password ManagerAI | 20/5/2026 | 23/7/2026 | Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmation nor notification. | |
| Aplazada | Media (6.1) | 0.18% | — | Word2cash Word 2 CashAI | 20/5/2026 | 24/7/2026 | The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and including 0.9.2. This is due to the complete absence of nonce verification on the settings save handler in the w2c_admin() function, combined with missing input sanitization… | |
| Aplazada | Alta (8.7) | 0.64% | — | Google Drive FOR WordpressAI | 17/5/2026 | 17/6/2026 | Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter. Attackers can send POST requests to gdrive-ajaxs.php with the ajaxstype parameter set to del_fl_bkp and file_name… | |
| Aplazada | Alta (8.7) | 0.65% | — | Wordfence Anti Malware Security AND Bruteforce FirewallAI | 16/5/2026 | 17/6/2026 | WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the file parameter. Attackers can send requests to the duplicator_download action via admin-ajax.php with path traversal… | |
| Aplazada | Alta (7.5) | 0.57% | — | Database Backup FOR WordpressAI | 14/5/2026 | 17/6/2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database backups are written. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.1) | 0.57% | — | Database Backup FOR WordpressAI | 14/5/2026 | 17/6/2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter.… | |
| Aplazada | Alta (8.8) | 0.45% | — | AntswordAI | 12/5/2026 | 17/6/2026 | AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vulnerability is fixed in 2.1.16. | |
| Analizada | Media (5.5) | 0.31% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. | |
| Analizada | Media (5.5) | 0.31% | — | Microsoft Word | 12/5/2026 | 17/6/2026 | Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. | |
| Modificada | Media (4.3) | 0.70% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Modificada | Alta (8.4) | 0.45% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 12/5/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |