Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

322 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.68%—Themeisle Multiple Page Generator31/10/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG multiple-pages-generator-by-porthas allows SQL Injection.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.3.19.
ModificadaMedia (4.8)0.41%—Anuragdeshmukh CPT Shortcode Generator25/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anurag Deshmukh CPT Shortcode Generator plugin <= 1.0 versions.
ModificadaAlta (8.8)38%💥 Exploit01generator Pireospay17/10/202317/6/2026
In the module "PireosPay" (pireospay) before version 1.7.10 from 01generator.com for PrestaShop, a guest can perform SQL injection via `PireosPayValidationModuleFrontController::postProcess().`
ModificadaAlta (8.8)0.21%—Anuragdeshmukh CPT Shortcode Generator16/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Anurag Deshmukh CPT Shortcode Generator plugin <= 1.0 versions.
ModificadaAlta (8.8)0.52%—Debian LinuxBabeljs BabelBabeljs Babel-helper-define-polyfill-providerBabeljs Babel-plugin-polyfill-corejs2+512/10/202317/6/2026
Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the…
ModificadaMedia (4.8)0.47%—Nikolov Serial Codes Generator AND Validator With Woocommerce Support19/9/202317/6/2026
The Serial Codes Generator and Validator with WooCommerce Support WordPress plugin before 2.4.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…
ModificadaMedia (6.1)0.46%—Sosidee Dynamic QR Code Generator30/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rakib Hasan Dynamic QR Code Generator plugin <= 0.0.5 versions.
ModificadaMedia (5.4)0.36%—Kayastudio Kaya QR Code Generator16/8/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kaya Studio Kaya QR Code Generator plugin <= 1.5.2 versions.
ModificadaMedia (6.1)1.3%💥 ExploitCreative-solutions Contact Form Generator10/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions.
ModificadaMedia (4.8)0.37%—Custom Post Type Generator Project Custom Post Type Generator18/7/202317/6/2026
Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Hijiri Custom Post Type Generator plugin <= 2.4.2 versions.
ModificadaAlta (8.8)0.25%—Wpexperts WP PDF Generator17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpexperts.Io WP PDF Generator plugin <= 1.2.2 versions.
ModificadaMedia (6.5)0.22%—Wow-company Button Generator11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.5 versions.
ModificadaAlta (8.8)0.33%—WP Dummy Content Generator Project WP Dummy Content Generator10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Deepak Anand WP Dummy Content Generator plugin <= 2.3.0 versions.
ModificadaMedia (6.1)1.00%💥 ExploitCodeermeneer Companion Sitemap Generator10/7/202317/6/2026
The Companion Sitemap Generator WordPress plugin before 4.5.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
ModificadaMedia (6.1)0.39%—Meldekarten Generator Project Meldekarten Generator27/6/202317/6/2026
Meldekarten generator is an open source project to create a program, running locally in the browser without the need for an internet-connection, to create, store and print registration cards for volunteers. All text fields on the webpage are vulnerable to XSS attacks. The user input isn't (fully) sanitized after…
ModificadaMedia (4.8)0.37%—Wow-estore Button Generator - Easily Button Builder22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.3 versions.
ModificadaMedia (6.1)0.46%—Wow-company Bubble MenuWow-company Button GeneratorWow-company Calculator-builderWow-company Counter BOX+812/6/202317/6/2026
The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before…
ModificadaAlta (7.2)0.84%—Themeisle Multiple Page Generator9/6/202317/6/2026
The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
ModificadaAlta (8.8)0.49%—Favicon BY Realfavicongenerator6/6/202317/6/2026
A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPress. This affects the function install_new_favicon of the file admin/class-favicon-by-realfavicongenerator-admin.php. The manipulation leads to cross-site request forgery. It is possible to initiate…
ModificadaAlta (8.8)0.28%—Logaster Logo Generator25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Logaster Logaster Logo Generator plugin <= 1.3 versions.
AnalizadaMedia (4.8)0.37%—Baidu-tongji-generator Project Baidu-tongji-generator18/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Haoqisir Baidu Tongji generator plugin <= 1.0.2 versions.
ModificadaMedia (4.3)0.36%—Themeisle Multiple Page Generator17/5/202317/6/2026
The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to missing nonce verification on the projects_list function and insufficient escaping on the user supplied…
ModificadaMedia (5.4)0.54%—Employee Payslip Generator System Project Employee Payslip Generator System2/4/202317/6/2026
A vulnerability classified as problematic has been found in SourceCodester Employee Payslip Generator 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_position of the component Create News Handler. The manipulation of the argument name with the input <script>alert(document.cookie)</script>…
ModificadaCrítica (9.1)0.94%—Openapi-generator Openapi Generator31/3/20239/7/2026
openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
ModificadaCrítica (9.8)0.74%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System27/3/202317/6/2026
A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. This vulnerability affects unknown code of the file users/classes/view_class.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can…
Orbitaley — Vulnerabilidades