Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.55% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Aplazada | Media (6.1) | 0.18% | — | TM Wordpress RedirectionAI | 12/5/2026 | 17/6/2026 | The Tm – WordPress Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a… | |
| Aplazada | Media (5.1) | 0.19% | — | Wordpress International SMS FOR Contact Form 7 IntegrationAI | 10/5/2026 | 24/7/2026 | WordPress International SMS for Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inject malicious scripts through the page parameter in class-sms-log-display.php to execute arbitrary JavaScript in… | |
| Aplazada | Media (5.1) | 0.21% | — | Wordpress Contact Form BuilderAI | 10/5/2026 | 24/7/2026 | WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary… | |
| Aplazada | Media (5.1) | 0.19% | — | Wordpress Picture GalleryAI | 10/5/2026 | 25/7/2026 | WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Edit Content URL field in the Access Control settings. Attackers can enter JavaScript payloads in the plugin options that are stored in the database and… | |
| Analizada | Media (6.5) | 0.52% | — | Apnotic Password Pusher | 8/5/2026 | 17/6/2026 | Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This could bypass the… | |
| Pendiente de análisis | Alta (8.1) | 2.6% | — | Zohocorp Manageengine Pam360AIZohocorp Manageengine Password Manager PROAI | 16/4/2026 | 17/6/2026 | Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module. | |
| Aplazada | Media (6.1) | 0.35% | — | Royal Wordpress Backup Restore PluginAI | 10/4/2026 | 17/6/2026 | The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpr_pending_template' parameter in all versions up to, and including, 1.0.16 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.4) | 0.23% | — | Ilghera JW Player FOR WordpressAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in ilGhera JW Player for WordPress jw-player-7-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JW Player for WordPress: from n/a through <= 2.3.6. | |
| Analizada | Alta (8.6) | 0.25% | — | Passfab Excel Password Recovery | 26/3/2026 | 17/6/2026 | PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget and shellcode that… | |
| Analizada | Alta (8.6) | 0.21% | — | Passfab RAR Password Recovery | 26/3/2026 | 17/6/2026 | PassFab RAR Password Recovery 9.3.2 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a payload with a buffer overflow, NSEH jump, and shellcode, then paste it into the 'Licensed E-mail… | |
| Analizada | Media (6.8) | 0.18% | — | Passfab Excel Password Recovery | 26/3/2026 | 17/6/2026 | Excel Password Recovery Professional 8.2.0.0 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long string to the 'E-Mail and Registrations Code' field. Attackers can paste a crafted payload containing 5000 bytes of data into the registration… | |
| Aplazada | Alta (8.1) | 0.26% | — | Wordpresschef Salon Booking System PROAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a through < 10.30.12. | |
| Aplazada | Alta (7.5) | 0.35% | — | Blueglass Jobs FOR WordpressAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in BlueGlass Interactive AG Jobs for WordPress job-postings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Jobs for WordPress: from n/a through <= 2.8. | |
| Aplazada | Alta (7.1) | 0.18% | — | Themepassion Ultra Wordpress AdminAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Ultra WordPress Admin ultra-admin allows Reflected XSS.This issue affects Ultra WordPress Admin: from n/a through <= 11.7. | |
| Aplazada | Media (6.4) | 0.33% | — | Wordpress Paypal DonationAI | 21/3/2026 | 17/6/2026 | The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortcode in all versions up to, and including, 1.01. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'amount', 'email', 'title',… | |
| Aplazada | Baja (2.1) | 0.56% | — | Bagofwords1 BagofwordsAI | 20/3/2026 | 17/6/2026 | A vulnerability was identified in bagofwords1 bagofwords up to 0.0.297. This impacts the function generate_df of the file backend/app/ai/code_execution/code_execution.py. Such manipulation leads to injection. The attack may be launched remotely. The exploit is publicly available and might be used. Upgrading to version… | |
| Modificada | Alta (7.1) | 0.54% | — | Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+6 | 16/3/2026 | 17/6/2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Media (5.4) | 0.22% | — | Giftup Gift UP Gift Cards FOR Wordpress AND WoocommerceAI | 13/3/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Gift Up! Gift Up Gift Cards for WordPress and WooCommerce gift-up allows Server Side Request Forgery.This issue affects Gift Up Gift Cards for WordPress and WooCommerce: from n/a through <= 3.1.7. | |
| Aplazada | Media (6.9) | 0.12% | — | RAR Password RecoveryAI | 11/3/2026 | 17/6/2026 | RAR Password Recovery 1.80 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload in the registration dialog. Attackers can craft a malicious input string exceeding 6000 bytes and paste it into the User Name and Registration Code field to trigger… | |
| Aplazada | Media (6.9) | 0.12% | — | Outlook Password RecoveryAI | 11/3/2026 | 17/6/2026 | Outlook Password Recovery 2.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can create a malicious text file containing 6000 bytes of data and paste it into the User Name and Registration Code field to trigger a denial of… | |
| Aplazada | Media (6.9) | 0.12% | — | SQL Server Password ChangerAI | 11/3/2026 | 17/6/2026 | SQL Server Password Changer 1.90 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can inject 6000 bytes of data into the User Name and Registration Code field to trigger a denial of service condition. | |
| Aplazada | Media (6.9) | 0.13% | — | Spotie Internet Explorer Password RecoveryAI | 11/3/2026 | 17/6/2026 | SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a… | |
| Aplazada | Media (4.3) | 0.39% | — | WordpressAI | 11/3/2026 | 17/6/2026 | WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collaboration annotations) was introduced in WordPress 6.9 to allow editorial comments directly on posts in the block editor. However, the REST API `create_item_permissions_check()` method in the comments… | |
| Aplazada | Alta (8.1) | 0.58% | — | Mikado-themes Topscore - Sports Wordpress ThemeAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes TopScorer - Sports WordPress Theme topscorer allows PHP Local File Inclusion.This issue affects TopScorer - Sports WordPress Theme: from n/a through <= 1.2. |