Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
2432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.35% | — | Simple-membership-plugin Simple MembershipAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Plugins Garbage CollectorAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpplugin Easy Paypal BUY NOW ButtonAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Siteguard WP PluginAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. | |
| Aplazada | Media (5.3) | 0.30% | — | Estatik Real Estate PluginAI | 6/8/2026 | 26/8/2026 | The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a… | |
| Pendiente de análisis | Alta (7.5) | 0.96% | 💥 PoC | Gstreamer Gst-plugins-goodAI | 6/8/2026 | 23/9/2026 | A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever… | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins AWS Codebuild PluginAI | 5/8/2026 | 31/8/2026 | Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins Codesonar PluginAI | 5/8/2026 | 31/8/2026 | Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Jenkins Violation Comments TO Gitlab PluginAI | 5/8/2026 | 31/8/2026 | A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Jenkins Summary Display PluginAI | 5/8/2026 | 31/8/2026 | Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission. | |
| Pendiente de análisis | Baja (3.7) | 0.27% | — | Jenkins Webhook Secret Credentials Provider PluginAI | 5/8/2026 | 31/8/2026 | Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token. | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Jenkins External Workspace Manager PluginAI | 5/8/2026 | 31/8/2026 | Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in… | |
| Pendiente de análisis | Media (4.2) | 0.19% | — | Jenkins Scm-manager PluginAI | 5/8/2026 | 31/8/2026 | A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Pendiente de análisis | Media (4.2) | 0.11% | — | Jenkins Scm-manager PluginAI | 5/8/2026 | 31/8/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins HCL Appscan PluginAI | 5/8/2026 | 31/8/2026 | Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Pendiente de análisis | Alta (8.8) | 0.30% | — | Jenkins Multijob PluginAI | 5/8/2026 | 31/8/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM. | |
| Pendiente de análisis | Alta (8.8) | 0.64% | — | Jenkins Multijob PluginAIJenkins Script Security PluginAI | 5/8/2026 | 31/8/2026 | Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM. | |
| Aplazada | Media (4.3) | 0.16% | — | Mlsimport IDX Plugin MLS Plugin FOR Real Estate ListingsAI | 5/8/2026 | 26/8/2026 | The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress… | |
| Pendiente de análisis | Baja (2.1) | 0.31% | — | Erlang Ecosystem Foundation Oidcc PlugAI | 4/8/2026 | 4/8/2026 | Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser complete an authorization flow the victim never initiated. This vulnerability is associated with program file… | |
| Pendiente de análisis | Media (6.3) | 0.44% | — | Erlang Ecosystem Foundation Oidcc PlugAI | 4/8/2026 | 4/8/2026 | Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth control against replay of a stolen session. This vulnerability is associated with program files… | |
| Aplazada | Alta (7.1) | 0.37% | — | Getgrav Grav-plugin-formAI | 3/8/2026 | 31/8/2026 | The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, and Grav::redirect() accepts external URLs without origin validation. When a form blueprint defines a redirect… | |
| Aplazada | Media (6.1) | 0.27% | — | Simple-membership-plugin Simple MembershipAI | 3/8/2026 | 26/8/2026 | The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary JavaScript that executes in an administrator's… | |
| Aplazada | Crítica (9.4) | 0.42% | — | Simple-membership-plugin Simple MembershipAI | 3/8/2026 | 26/8/2026 | The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over… | |
| Aplazada | Alta (7.5) | 0.39% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 2/8/2026 | 26/8/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the… | |
| Aplazada | Media (4.3) | 0.25% | — | Cleverplugins Clever Mega Menu FOR Visual ComposerAI | 2/8/2026 | 26/8/2026 | The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public… |