Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

108 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.42%—Really-simple-plugins Really Simple SecurityAI18/9/202618/9/2026
The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages.
AplazadaBaja (2.3)0.36%—Really-simple-plugins Really Simple SecurityAI14/9/202619/9/2026
Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a…
AplazadaAlta (7.5)0.34%—Really-simple-plugins Really Simple SecurityAI13/9/202614/9/2026
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.
AplazadaAlta (7.4)0.39%—Really Simple SSLAI3/9/20263/9/2026
Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.
AplazadaMedia (5.3)0.40%—Really Simple SSLAI2/9/20262/9/2026
Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.
AplazadaMedia (6.6)0.43%—Really-simple-plugins Really Simple SecurityAI30/8/202631/8/2026
The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to install and execute arbitrary code in the…
AplazadaMedia (5.3)0.33%—Really-simple-plugins ComplianzAI23/7/202612/8/2026
Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
AplazadaAlta (7.2)0.54%—Really-simple-plugins ComplianzAI23/7/202623/7/2026
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
AplazadaMedia (4.4)0.21%—Really-simple-plugins ComplianzAI23/7/202623/7/2026
Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
AplazadaCrítica (9.1)0.50%—Really Simple CSV ImporterAI23/7/202623/7/2026
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
AplazadaAlta (8.1)0.46%—Really Simple SSLAI15/6/202617/6/2026
Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.
AplazadaMedia (6.5)0.30%—Really Simple SSLAI15/6/202617/6/2026
Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
AplazadaAlta (7.5)0.39%—Really-simple-plugins Really Simple SecurityAI2/6/202622/7/2026
The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the email OTP challenge.
AplazadaMedia (4.4)0.31%—ContinuallyAI12/5/202617/6/2026
The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject…
AnalizadaCrítica (9.6)1.1%⚠ Explotación activaTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AplazadaMedia (5.3)0.44%—Really-simple-plugins ComplianzAI29/4/202617/6/2026
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at /wp-json/complianz/v1/consent-area/{post_id}/{block_id} using __return_true as the permission_callback, allowing any…
AplazadaMedia (6.5)0.36%—Really-simple-plugins Really Simple Security PROAI19/3/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Really Simple Security Pro: from n/a through 9.5.4.0.
AplazadaMedia (4.3)0.26%—Really-simple-plugins Really Simple SSLAI13/3/202617/6/2026
Missing Authorization vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Really Simple SSL: from n/a through <= 9.5.7.
AplazadaAlta (7.5)2.3%—A11y AllyAI11/3/202617/6/2026
The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all versions up to, and including, 4.0.3. This is due to insufficient escaping on the user-supplied URL parameter in the `get_global_remediations()` method, where it is directly concatenated into an SQL…
AplazadaMedia (5.3)0.22%—Elementor AllyAI19/2/202617/6/2026
Missing Authorization vulnerability in Elementor Ally pojo-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ally: from n/a through <= 4.0.2.
AplazadaMedia (6.4)0.26%—Really-simple-plugins ComplianzAI18/2/202617/6/2026
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cmplz-accept-link shortcode in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (5.3)0.26%—Custom Fonts Host Your Fonts LocallyAI20/1/202617/6/2026
The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'BCF_Google_Fonts_Compatibility' class constructor function in all versions up to, and including, 2.1.16. This makes it possible for unauthenticated attackers to delete…
AplazadaCrítica (9.3)0.77%—AccessallyAI9/1/202617/6/2026
AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The plugin processes the login_error parameter as PHP code, allowing an attacker to supply and execute arbitrary PHP in the context of the WordPress web server process,…
ModificadaAlta (8.1)0.50%—Axiomthemes Rally18/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Rally rally allows PHP Local File Inclusion.This issue affects Rally: from n/a through <= 1.1.
AplazadaMedia (6.5)0.23%—Hogash KallyasAI9/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hogash KALLYAS kallyas allows DOM-Based XSS.This issue affects KALLYAS: from n/a through < 4.25.0.