Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.36% | — | Alexacrm Dynamics 365 IntegrationAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.12. | |
| Aplazada | Media (6.4) | 0.41% | — | Streamweasels Youtube IntegrationAI | 28/11/2024 | 17/6/2026 | The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-youtube-embed' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Xpresslane Fast CheckoutAIXpresslane Integration FOR WoocommerceAI | 20/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in xpresslane Xpresslane Fast Checkout xpresslane-integration-for-woocommerce allows Object Injection.This issue affects Xpresslane Fast Checkout: from n/a through <= 1.0.0. | |
| Analizada | Media (6.1) | 0.57% | — | Advancedformintegration Advanced Form Integration | 13/11/2024 | 17/6/2026 | The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.92.0. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Alta (7.1) | 0.27% | — | Askewbrook Bing Search API IntegrationAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in askewbrook Bing Search API Integration abbs-bing-search allows Reflected XSS.This issue affects Bing Search API Integration: from n/a through <= 0.3.3. | |
| Analizada | Media (6.1) | 0.43% | — | Wedevs Recaptcha Integration | 2/11/2024 | 17/6/2026 | The ReCaptcha Integration for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (6.4) | 0.38% | — | Streamweasels Youtube IntegrationAI | 29/10/2024 | 17/6/2026 | The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-youtube-embed shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.38% | — | Streamweasels Kick IntegrationAI | 29/10/2024 | 17/6/2026 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-kick-embed shortcode in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.4) | 0.35% | — | Streamweasels Twitch Integration | 19/10/2024 | 17/6/2026 | The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-twitch-embed shortcode in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (4.3) | 0.32% | — | Javmah Spreadsheet Integration | 25/9/2024 | 17/6/2026 | The Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including,… | |
| Aplazada | Alta (8.5) | 0.27% | — | Hitachivantara Pentaho Data IntegrationAIHitachivantara Pentaho AnalyticsAI | 12/9/2024 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields. | |
| Aplazada | Media (6.5) | 0.32% | — | Alps System IntegrationAI | 10/9/2024 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated attacker to hijack the authentication of the user and to perform unintended operations if the user views a malicious page while logged in. | |
| Analizada | Crítica (9.9) | 0.55% | — | IBM Webmethods Integration | 4/9/2024 | 17/6/2026 | IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying operating system. | |
| Modificada | Alta (8.8) | 0.45% | — | IBM Webmethods Integration | 4/9/2024 | 17/6/2026 | IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to missing authentication. | |
| Analizada | Media (6.5) | 0.48% | — | IBM Webmethods Integration | 4/9/2024 | 17/6/2026 | IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Analizada | Media (4.3) | 0.18% | — | Advancedformintegration Advanced Form Integration | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nasirahmed Advanced Form Integration.This issue affects Advanced Form Integration: from n/a through 1.89.4. | |
| Modificada | Alta (7.5) | 2.6% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Build OF KeycloakRedhat Data Grid+5 | 21/8/2024 | 24/9/2026 | A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder… | |
| Aplazada | Media (5.3) | 0.46% | — | Flamix Bitrix24 AND Contact Form 7 IntegrationsAI | 21/8/2024 | 17/6/2026 | The Flamix: Bitrix24 and Contact Form 7 integrations plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.1.0. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the… | |
| Aplazada | Media (5.9) | 0.28% | — | Wedevs Recaptcha Integration FOR WordpressAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs ReCaptcha Integration for WordPress wp-recaptcha-integration allows DOM-Based XSS.This issue affects ReCaptcha Integration for WordPress: from n/a through <= 1.2.7. | |
| Aplazada | Alta (7.7) | 0.40% | — | Pingone MFA Integration KITAI | 9/7/2024 | 17/6/2026 | PingOne MFA Integration Kit contains a vulnerability where the skipMFA action can be configured such that user authentication does not require the second factor authentication from the user's existing registered devices. A threat actor might be able to exploit this vulnerability to authenticate as a target user if… | |
| Aplazada | Alta (8.7) | 0.40% | — | Pingidentity Pingone MFA Integration KITAI | 9/7/2024 | 17/6/2026 | PingOne MFA Integration Kit contains a vulnerability related to the Prompt Users to Set Up MFA configuration. Under certain conditions, this configuration could allow for a new MFA device to be paired with a target user account without requiring second-factor authentication from the target’s existing registered… | |
| Aplazada | Media (4.3) | 0.41% | — | Mailerlite - Woocommerce IntegrationAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8. | |
| Modificada | Alta (8.8) | 0.36% | — | Themekraft Buddypress Woocommerce MY Account Integration. Create Woocommerce Member Pages | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.19. | |
| Aplazada | Media (4.3) | 0.17% | — | Crmperks Integration FOR Contact Form 7 AND Constant ContactAI | 3/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks. Integration for Contact Form 7 and Constant Contact.This issue affects Integration for Contact Form 7 and Constant Contact: from n/a through 1.1.5. | |
| Aplazada | Media (4.3) | 0.19% | — | Crmperks Integration FOR Contact Form 7 HubspotAI | 17/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 HubSpot.This issue affects Integration for Contact Form 7 HubSpot: from n/a through 1.3.1. |