Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.8) | 0.20% | — | ELI Anti-malware Security AND Brute-force FirewallAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eli Anti-Malware Security and Brute-Force Firewall gotmls allows Reflected XSS.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through <= 4.23.89. | |
| Aplazada | Alta (8.8) | 0.52% | — | Anti-malware Security AND Brute-force FirewallAIPHPAI | 15/6/2026 | 17/6/2026 | Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions. | |
| Aplazada | Crítica (9) | 0.87% | — | ELI Scheetz Anti-malware Security AND Brute-force FirewallAI | 25/4/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows Code Injection.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through 4.21.96. | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | Anti-malware Security AND Brute-force Firewall Project Anti-malware Security AND Brute-force Firewall | 29/8/2022 | 17/6/2026 | The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some parameters before outputting them back in an admin dashboard, leading to Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 3.1% | — | Download Anti-malware Security AND Brute-force Firewall Project Download Anti-malware Security AND Brute-force Firewall | 25/4/2022 | 17/6/2026 | The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters | |
| Modificada | Media (4.8) | 0.60% | — | Anti-malware Security AND Brute-force Firewall Project Anti-malware Security AND Brute-force Firewall | 21/2/2022 | 17/6/2026 | The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can only… |