Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

135 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.6)0.38%—WP Activity LOGAI30/9/202630/9/2026
Administrator SQL Injection in WP Activity Log <= 5.6.6 versions.
AplazadaAlta (7.1)0.13%—Activity LOGAI2/9/20263/9/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
AplazadaMedia (5.4)0.14%—Melapress WP Activity LOGAIMelapress WP Activity LOG PremiumAI23/7/20265/8/2026
Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.
AplazadaAlta (7.1)0.25%—WP Activity LOGAI25/6/202625/6/2026
Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.
AplazadaAlta (7.5)0.35%—Ghost ActivitypubAI24/6/202625/6/2026
@tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0.
AplazadaCrítica (9.8)0.64%—Melapress WP Activity LOGAI17/6/202617/6/2026
Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
AplazadaAlta (7.5)0.42%—Logtivity Activity LogsAILogtivity User Activity TrackingAILogtivity Multisite Activity LOGAI1/6/202622/7/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a…
AplazadaMedia (6.5)0.22%—Melapress WP Activity LOGAI25/5/202624/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS. This issue affects WP Activity Log: from n/a through 5.6.3.
AplazadaAlta (8.1)0.83%—Dev4press CoreactivityAI13/5/202617/6/2026
The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0. This is due to the plugin failing to validate or strip PHP serialization syntax from the User-Agent HTTP header before storing it in the logmeta table, and subsequently…
AnalizadaAlta (7.5)0.44%—Automattic Activitypub8/4/202624/7/2026
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts
AplazadaMedia (6.5)0.38%—Activitypub-federation-rustAIJoin-lemmy LemmyAI27/3/202617/6/2026
Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in `activitypub-federation-rust` (`src/utils.rs`) does not check for `Ipv4Addr::UNSPECIFIED` (0.0.0.0). An unauthenticated attacker controlling a remote domain can point it to 0.0.0.0, bypass the SSRF…
AplazadaMedia (6.4)0.24%—Tour Activity Operator Plugin FOR TourcmsAI21/3/202617/6/2026
The Tour & Activity Operator Plugin for TourCMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the tourcms_doc_link shortcode in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaAlta (7.7)0.42%—Activitypub FederationAIPict-rsAIJoin-lemmy LemmyAI6/3/202617/6/2026
Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. Prior to version 0.19.16, the GET /api/v4/image/{filename} endpoint is vulnerable to unauthenticated SSRF through parameter…
AplazadaMedia (6.5)0.16%—Melapress WP Activity LOGAI19/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log wp-security-audit-log allows DOM-Based XSS.This issue affects WP Activity Log: from n/a through <= 5.5.4.
AplazadaMedia (6.5)0.30%—Winter Activity LOGAI12/2/202617/6/2026
The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the winter_activity_log_action() function in all versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
AplazadaMedia (5.3)0.30%—Solwininfotech User Activity LOGAI28/1/202617/6/2026
The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowing unauthenticated users to set arbitrary options to 1 (for example to enable User Registration when it has been turned off)
AplazadaAlta (7.5)0.37%—Solwininfotech User Activity LOGAI7/1/202617/6/2026
The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed-login handler 'ual_shook_wp_login_failed' lacks a capability check and writes failed usernames directly into update_option() calls. This makes it possible for unauthenticated attackers to push…
AplazadaMedia (6.5)0.17%—Buddydev Buddypress Activity ShortcodeAI31/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev BuddyPress Activity Shortcode bp-activity-shortcode allows Stored XSS.This issue affects BuddyPress Activity Shortcode: from n/a through <= 1.1.8.
AplazadaMedia (6.5)0.20%—Buddydev Activity Plus ReloadedAIBuddypressAI27/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress bp-activity-plus-reloaded allows Stored XSS.This issue affects Activity Plus Reloaded for BuddyPress: from n/a through <= 1.1.2.
AplazadaMedia (6.5)0.20%—Activity-log.com Profiler - What Slowing Down Your WPAI16/7/202517/6/2026
Missing Authorization vulnerability in activity-log.com Profiler - What Slowing Down Your WP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Profiler - What Slowing Down Your WP: from n/a through 1.0.0.
AplazadaMedia (5.4)0.32%—Buddydev Activity Plus ReloadedAIBuddypressAI6/6/202517/6/2026
Missing Authorization vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress bp-activity-plus-reloaded allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Activity Plus Reloaded for BuddyPress: from n/a through <= 1.1.2.
ModificadaMedia (5.3)0.36%—Mooveagency User Activity Tracking AND LOG15/5/202517/6/2026
This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.
ModificadaAlta (8.8)0.68%—Dev4press Coreactivity15/5/202517/6/2026
The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated users to perform Stored XSS attack against high privilege users such as admin
AnalizadaMedia (5.4)0.84%—Deryckoe Logdash Activity LOG15/5/202517/6/2026
The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based…
ModificadaCrítica (9.8)0.29%—Wbcomdesigns Activity Link Preview FOR Buddypress7/5/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress activity-link-preview-for-buddypress allows Server Side Request Forgery.This issue affects Wbcom Designs - Activity Link Preview For BuddyPress: from n/a through <= 1.4.4.