Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
815 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.12% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 14/8/2025 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | |
| Aplazada | Media (6.4) | 0.25% | — | Master-addons Master AddonsAI | 12/8/2025 | 17/6/2026 | The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.0.8.6 due to insufficient input sanitization and output escaping. This makes it… | |
| Modificada | Media (6.1) | 0.53% | — | Addonmaster Post Grid Master | 24/7/2025 | 17/6/2026 | The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘argsArray['read_more_text']’ parameter in all versions up to, and including, 3.4.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.5) | 0.61% | — | Masterstudy LMS PROAI | 18/7/2025 | 17/6/2026 | The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'install_and_activate_plugin' function in all versions up to, and including, 4.7.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload… | |
| Aplazada | Media (6.4) | 0.33% | — | Master-addons Master AddonsAI | 16/7/2025 | 17/6/2026 | The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS extension in all versions up to, and including, 2.0.8.2 due to insufficient capability restriction, and insufficient input… | |
| Aplazada | Alta (8.1) | 0.58% | — | Cmsmasters Content ComposerAI | 4/7/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through < 2.5.7. | |
| Analizada | Media (6.4) | 0.22% | — | Qazomardok Paymaster FOR Woocommerce | 4/7/2025 | 17/6/2026 | The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.4.31 via the 'wp_ajax_paym_status' AJAX action This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations… | |
| Analizada | Media (5.4) | 0.26% | — | Averta Master Slider | 17/6/2025 | 17/6/2026 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's masterslider_pb and ms_slide shortcodes in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Analizada | Alta (7.2) | 0.74% | — | Airleader Easy FirmwareAirleader Master II+ Firmware | 10/6/2025 | 17/6/2026 | The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/workspace.jsp unrestricted file upload. To exploit this, the attacker must login to the administrator console (default credentials are weak and easily guessable) and upload a JSP… | |
| Aplazada | Media (4.3) | 0.15% | — | Vuong Nguyen WP Security MasterAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Vuong Nguyen WP Security Master wp-security-master allows Cross Site Request Forgery.This issue affects WP Security Master: from n/a through <= 1.0.2. | |
| Modificada | Alta (8.8) | 0.34% | — | Addonmaster Post Grid Master | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Akhtarujjaman Shuvo Post Grid Master ajax-filter-posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid Master: from n/a through <= 3.4.17. | |
| Aplazada | Crítica (9.2) | 0.47% | — | WF Steuerungstechnik Gmbh Airleader MasterAI | 4/6/2025 | 17/6/2026 | Path Traversal vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Retrieve Embedded Sensitive Data.This issue affects airleader MASTER: 3.0046. | |
| Aplazada | Crítica (10) | 0.41% | — | WF Steuerungstechnik Gmbh Airleader MasterAI | 4/6/2025 | 17/6/2026 | Improper Authentication vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Authentication Bypass.This issue affects airleader MASTER: 3.00571. | |
| Aplazada | Alta (8.8) | 1.1% | — | Masterstudylms PROAI | 28/5/2025 | 17/6/2026 | The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validation in the stm_lms_add_assignment_attachment function in all versions up to, and including, 4.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload… | |
| Analizada | Media (6.1) | 0.30% | 💥 PoC | Code-projects Online Exam Mastering System | 27/5/2025 | 17/6/2026 | code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the feedback form. | |
| Aplazada | Alta (8.1) | 0.64% | — | Goodlayers TourmasterAI | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GoodLayers Tourmaster tourmaster allows PHP Local File Inclusion.This issue affects Tourmaster: from n/a through <= 5.3.8. | |
| Modificada | Media (4.3) | 0.23% | — | Averta Master Slider | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in averta Master Slider master-slider.This issue affects Master Slider: from n/a through <= 3.11.0. | |
| Modificada | Media (5.3) | 0.93% | 💥 Exploit | Themegrill Masteriyo | 19/5/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.3. | |
| Aplazada | Media (4.3) | 0.17% | — | Lukas Hartmann Seznam-webmasterAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lukáš Hartmann Seznam Webmaster seznam-webmaster allows Cross Site Request Forgery.This issue affects Seznam Webmaster: from n/a through <= 1.4.7. | |
| Aplazada | Alta (7.5) | 0.91% | — | Mitsubishielectric Cc-link IE TSN Remote IO ModuleAIMitsubishielectric Cc-link IE TSN Analog-digital Converter ModuleAIMitsubishielectric Cc-link IE TSN Digital-analog Converter ModuleAIMitsubishielectric Cc-link IE TSN Fpga ModuleAI+8 | 25/4/2025 | 27/8/2026 | Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote Station Communication LSI CP620 with… | |
| Aplazada | Alta (7.1) | 0.14% | — | Offshorewebmaster Availability CalendarAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Steve Availability Calendar availability allows Stored XSS.This issue affects Availability Calendar: from n/a through <= 0.2.4. | |
| Aplazada | Alta (7.2) | 0.88% | — | WpmastertoolkitAI | 24/4/2025 | 17/6/2026 | The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to read and modify the contents of arbitrary files on the server, which… | |
| Analizada | Media (6.1) | 0.90% | 💥 Exploit | Code-projects Online Exam Mastering System | 21/4/2025 | 17/6/2026 | code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code. | |
| Aplazada | Crítica (9.9) | 0.48% | — | Wisdom Master PROAI | 17/4/2025 | 17/6/2026 | A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to perform arbitrary system commands by running a malicious file. | |
| Aplazada | Media (5.3) | 0.45% | — | Wisdom Master PROAI | 17/4/2025 | 17/6/2026 | An unrestricted upload of file with dangerous type vulnerability in the course management function of Wisdom Master Pro versions 5.0 through 5.2 allows remote authenticated users to craft a malicious file. |