Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2507▼ 423 respecto a la semana anterior
Críticas / altas1283▲ 4 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.25% | — | ASK ME Anything AnonymouslyAI | 25/1/2025 | 17/6/2026 | The Ask Me Anything (Anonymously) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'askmeanythingpeople' shortcode in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.1) | 0.56% | — | Fusion Chat Chat AI Assistant ASK ME AnythingAI | 24/10/2024 | 17/6/2026 | A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | |
| Modificada | Media (4.7) | 0.38% | — | Inkthemes ASK ME | 21/11/2022 | 17/6/2026 | The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation. | |
| Modificada | Media (4.3) | 0.40% | — | Inkthemes ASK ME | 22/8/2022 | 17/6/2026 | The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request. | |
| Modificada | Media (6.5) | 0.53% | — | 2code ASK ME | 8/6/2022 | 17/6/2026 | The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site. | |
| Modificada | Media (6.1) | 0.79% | — | 2code ASK ME | 8/6/2022 | 17/6/2026 | The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Alta (8.8) | 16% | — | Satel-iberia Sennet Multitask MeterSatel-iberia Sennet Optimal DataloggerSatel-iberia Sennet Solar Datalogger | 19/5/2017 | 17/6/2026 | A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Successful exploitation of this vulnerability could result in the… |