Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

2432 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.35%—Simple-membership-plugin Simple MembershipAI6/8/202612/8/2026
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
AplazadaMedia (6.5)0.17%—Plugins Garbage CollectorAI6/8/202612/8/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
AplazadaAlta (7.1)0.25%—Wpplugin Easy Paypal BUY NOW ButtonAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
AplazadaAlta (7.1)0.25%—Siteguard WP PluginAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
AplazadaMedia (5.3)0.30%—Estatik Real Estate PluginAI6/8/202626/8/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a…
Pendiente de análisisAlta (7.5)0.96%💥 PoCGstreamer Gst-plugins-goodAI6/8/202623/9/2026
A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever…
Pendiente de análisisMedia (4.3)0.27%—Jenkins AWS Codebuild PluginAI5/8/202631/8/2026
Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Pendiente de análisisMedia (4.3)0.27%—Jenkins Codesonar PluginAI5/8/202631/8/2026
Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Pendiente de análisisMedia (4.3)0.29%—Jenkins Violation Comments TO Gitlab PluginAI5/8/202631/8/2026
A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Pendiente de análisisMedia (5.4)0.23%—Jenkins Summary Display PluginAI5/8/202631/8/2026
Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission.
Pendiente de análisisBaja (3.7)0.27%—Jenkins Webhook Secret Credentials Provider PluginAI5/8/202631/8/2026
Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.
Pendiente de análisisMedia (4.3)0.29%—Jenkins External Workspace Manager PluginAI5/8/202631/8/2026
Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in…
Pendiente de análisisMedia (4.2)0.19%—Jenkins Scm-manager PluginAI5/8/202631/8/2026
A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Pendiente de análisisMedia (4.2)0.11%—Jenkins Scm-manager PluginAI5/8/202631/8/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Pendiente de análisisMedia (4.3)0.27%—Jenkins HCL Appscan PluginAI5/8/202631/8/2026
Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Pendiente de análisisAlta (8.8)0.30%—Jenkins Multijob PluginAI5/8/202631/8/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.
Pendiente de análisisAlta (8.8)0.64%—Jenkins Multijob PluginAIJenkins Script Security PluginAI5/8/202631/8/2026
Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.
AplazadaMedia (4.3)0.16%—Mlsimport IDX Plugin MLS Plugin FOR Real Estate ListingsAI5/8/202626/8/2026
The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress…
Pendiente de análisisBaja (2.1)0.31%—Erlang Ecosystem Foundation Oidcc PlugAI4/8/20264/8/2026
Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser complete an authorization flow the victim never initiated. This vulnerability is associated with program file…
Pendiente de análisisMedia (6.3)0.44%—Erlang Ecosystem Foundation Oidcc PlugAI4/8/20264/8/2026
Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth control against replay of a stolen session. This vulnerability is associated with program files…
AplazadaAlta (7.1)0.37%—Getgrav Grav-plugin-formAI3/8/202631/8/2026
The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, and Grav::redirect() accepts external URLs without origin validation. When a form blueprint defines a redirect…
AplazadaMedia (6.1)0.27%—Simple-membership-plugin Simple MembershipAI3/8/202626/8/2026
The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary JavaScript that executes in an administrator's…
AplazadaCrítica (9.4)0.42%—Simple-membership-plugin Simple MembershipAI3/8/202626/8/2026
The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over…
AplazadaAlta (7.5)0.39%—Fivestarplugins Five Star Restaurant ReservationsAI2/8/202626/8/2026
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the…
AplazadaMedia (4.3)0.25%—Cleverplugins Clever Mega Menu FOR Visual ComposerAI2/8/202626/8/2026
The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public…
Orbitaley — Vulnerabilidades