Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.42% | — | Really-simple-plugins Really Simple SecurityAI | 18/9/2026 | 18/9/2026 | The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages. | |
| Aplazada | Baja (2.3) | 0.36% | — | Really-simple-plugins Really Simple SecurityAI | 14/9/2026 | 19/9/2026 | Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a… | |
| Aplazada | Alta (7.5) | 0.34% | — | Really-simple-plugins Really Simple SecurityAI | 13/9/2026 | 14/9/2026 | The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator. | |
| Aplazada | Alta (7.4) | 0.39% | — | Really Simple SSLAI | 3/9/2026 | 3/9/2026 | Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions. | |
| Aplazada | Media (5.3) | 0.40% | — | Really Simple SSLAI | 2/9/2026 | 2/9/2026 | Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions. | |
| Aplazada | Media (6.6) | 0.43% | — | Really-simple-plugins Really Simple SecurityAI | 30/8/2026 | 31/8/2026 | The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to install and execute arbitrary code in the… | |
| Aplazada | Media (5.3) | 0.33% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 12/8/2026 | Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 23/7/2026 | Administrator PHP Object Injection in Complianz <= 7.5.0 versions. | |
| Aplazada | Media (4.4) | 0.21% | — | Really-simple-plugins ComplianzAI | 23/7/2026 | 23/7/2026 | Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Really Simple CSV ImporterAI | 23/7/2026 | 23/7/2026 | Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. | |
| Aplazada | Alta (8.1) | 0.46% | — | Really Simple SSLAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | Really Simple SSLAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Really-simple-plugins Really Simple SecurityAI | 2/6/2026 | 22/7/2026 | The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge. | |
| Aplazada | Media (4.4) | 0.31% | — | ContinuallyAI | 12/5/2026 | 17/6/2026 | The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Media (5.3) | 0.44% | — | Really-simple-plugins ComplianzAI | 29/4/2026 | 17/6/2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at /wp-json/complianz/v1/consent-area/{post_id}/{block_id} using __return_true as the permission_callback, allowing any… | |
| Aplazada | Media (6.5) | 0.36% | — | Really-simple-plugins Really Simple Security PROAI | 19/3/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Really Simple Security Pro: from n/a through 9.5.4.0. | |
| Aplazada | Media (4.3) | 0.26% | — | Really-simple-plugins Really Simple SSLAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Really Simple SSL: from n/a through <= 9.5.7. | |
| Aplazada | Alta (7.5) | 2.3% | — | A11y AllyAI | 11/3/2026 | 17/6/2026 | The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all versions up to, and including, 4.0.3. This is due to insufficient escaping on the user-supplied URL parameter in the `get_global_remediations()` method, where it is directly concatenated into an SQL… | |
| Aplazada | Media (5.3) | 0.22% | — | Elementor AllyAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Elementor Ally pojo-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ally: from n/a through <= 4.0.2. | |
| Aplazada | Media (6.4) | 0.26% | — | Really-simple-plugins ComplianzAI | 18/2/2026 | 17/6/2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cmplz-accept-link shortcode in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.26% | — | Custom Fonts Host Your Fonts LocallyAI | 20/1/2026 | 17/6/2026 | The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'BCF_Google_Fonts_Compatibility' class constructor function in all versions up to, and including, 2.1.16. This makes it possible for unauthenticated attackers to delete… | |
| Aplazada | Crítica (9.3) | 0.77% | — | AccessallyAI | 9/1/2026 | 17/6/2026 | AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The plugin processes the login_error parameter as PHP code, allowing an attacker to supply and execute arbitrary PHP in the context of the WordPress web server process,… | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Rally | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Rally rally allows PHP Local File Inclusion.This issue affects Rally: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.23% | — | Hogash KallyasAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hogash KALLYAS kallyas allows DOM-Based XSS.This issue affects KALLYAS: from n/a through < 4.25.0. |