Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.68% | — | Themeisle Multiple Page Generator | 31/10/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG multiple-pages-generator-by-porthas allows SQL Injection.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.3.19. | |
| Modificada | Media (4.8) | 0.41% | — | Anuragdeshmukh CPT Shortcode Generator | 25/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anurag Deshmukh CPT Shortcode Generator plugin <= 1.0 versions. | |
| Modificada | Alta (8.8) | 38% | 💥 Exploit | 01generator Pireospay | 17/10/2023 | 17/6/2026 | In the module "PireosPay" (pireospay) before version 1.7.10 from 01generator.com for PrestaShop, a guest can perform SQL injection via `PireosPayValidationModuleFrontController::postProcess().` | |
| Modificada | Alta (8.8) | 0.21% | — | Anuragdeshmukh CPT Shortcode Generator | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Anurag Deshmukh CPT Shortcode Generator plugin <= 1.0 versions. | |
| Modificada | Alta (8.8) | 0.52% | — | Debian LinuxBabeljs BabelBabeljs Babel-helper-define-polyfill-providerBabeljs Babel-plugin-polyfill-corejs2+5 | 12/10/2023 | 17/6/2026 | Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the… | |
| Modificada | Media (4.8) | 0.47% | — | Nikolov Serial Codes Generator AND Validator With Woocommerce Support | 19/9/2023 | 17/6/2026 | The Serial Codes Generator and Validator with WooCommerce Support WordPress plugin before 2.4.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in… | |
| Modificada | Media (6.1) | 0.46% | — | Sosidee Dynamic QR Code Generator | 30/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rakib Hasan Dynamic QR Code Generator plugin <= 0.0.5 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Kayastudio Kaya QR Code Generator | 16/8/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kaya Studio Kaya QR Code Generator plugin <= 1.5.2 versions. | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | Creative-solutions Contact Form Generator | 10/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Custom Post Type Generator Project Custom Post Type Generator | 18/7/2023 | 17/6/2026 | Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Hijiri Custom Post Type Generator plugin <= 2.4.2 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Wpexperts WP PDF Generator | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpexperts.Io WP PDF Generator plugin <= 1.2.2 versions. | |
| Modificada | Media (6.5) | 0.22% | — | Wow-company Button Generator | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.5 versions. | |
| Modificada | Alta (8.8) | 0.33% | — | WP Dummy Content Generator Project WP Dummy Content Generator | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Deepak Anand WP Dummy Content Generator plugin <= 2.3.0 versions. | |
| Modificada | Media (6.1) | 1.00% | 💥 Exploit | Codeermeneer Companion Sitemap Generator | 10/7/2023 | 17/6/2026 | The Companion Sitemap Generator WordPress plugin before 4.5.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (6.1) | 0.39% | — | Meldekarten Generator Project Meldekarten Generator | 27/6/2023 | 17/6/2026 | Meldekarten generator is an open source project to create a program, running locally in the browser without the need for an internet-connection, to create, store and print registration cards for volunteers. All text fields on the webpage are vulnerable to XSS attacks. The user input isn't (fully) sanitized after… | |
| Modificada | Media (4.8) | 0.37% | — | Wow-estore Button Generator - Easily Button Builder | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.3 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Wow-company Bubble MenuWow-company Button GeneratorWow-company Calculator-builderWow-company Counter BOX+8 | 12/6/2023 | 17/6/2026 | The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before… | |
| Modificada | Alta (7.2) | 0.84% | — | Themeisle Multiple Page Generator | 9/6/2023 | 17/6/2026 | The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.49% | — | Favicon BY Realfavicongenerator | 6/6/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPress. This affects the function install_new_favicon of the file admin/class-favicon-by-realfavicongenerator-admin.php. The manipulation leads to cross-site request forgery. It is possible to initiate… | |
| Modificada | Alta (8.8) | 0.28% | — | Logaster Logo Generator | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Logaster Logaster Logo Generator plugin <= 1.3 versions. | |
| Analizada | Media (4.8) | 0.37% | — | Baidu-tongji-generator Project Baidu-tongji-generator | 18/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Haoqisir Baidu Tongji generator plugin <= 1.0.2 versions. | |
| Modificada | Media (4.3) | 0.36% | — | Themeisle Multiple Page Generator | 17/5/2023 | 17/6/2026 | The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to missing nonce verification on the projects_list function and insufficient escaping on the user supplied… | |
| Modificada | Media (5.4) | 0.54% | — | Employee Payslip Generator System Project Employee Payslip Generator System | 2/4/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Employee Payslip Generator 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_position of the component Create News Handler. The manipulation of the argument name with the input <script>alert(document.cookie)</script>… | |
| Modificada | Crítica (9.1) | 0.94% | — | Openapi-generator Openapi Generator | 31/3/2023 | 9/7/2026 | openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request. | |
| Modificada | Crítica (9.8) | 0.74% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 27/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. This vulnerability affects unknown code of the file users/classes/view_class.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can… |