Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.33% | — | Vinodvaswani9 Bulk Assign Linked Products FOR WoocommerceAI | 24/4/2025 | 17/6/2026 | Missing Authorization vulnerability in vinodvaswani9 Bulk Assign Linked Products For WooCommerce wc-bulk-assign-linked-products allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk Assign Linked Products For WooCommerce: from n/a through <= 2.1. | |
| Modificada | Media (4.8) | 0.28% | — | Shanebp BP Email Assign Templates | 11/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Stored XSS.This issue affects BP Email Assign Templates: from n/a through <= 1.6. | |
| Modificada | Media (4.9) | 0.45% | — | Shanebp BP Email Assign Templates | 11/3/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Email Assign Templates: from n/a through <= 1.7. | |
| Aplazada | Alta (7.1) | 0.28% | — | Shanebp BP Email Assign TemplatesAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Reflected XSS.This issue affects BP Email Assign Templates: from n/a through <= 1.5. | |
| Aplazada | Alta (7.1) | 0.32% | — | Bulk Categories AssignAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Haider Ali Bulk Categories Assign bulk-categories-assign allows Reflected XSS.This issue affects Bulk Categories Assign: from n/a through <= 1.0. | |
| Aplazada | Media (6.1) | 0.42% | — | Shanebp BP Email Assign TemplatesAI | 12/12/2024 | 17/6/2026 | The BP Email Assign Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Crítica (9.8) | 0.97% | — | Alykoshin Mini-deep-assign | 30/7/2024 | 17/6/2026 | Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the _assign() method at (/lib/index.js:91) | |
| Aplazada | Crítica (9.8) | 0.56% | — | Alexbinary Object-deep-assignAI | 17/6/2024 | 17/6/2026 | alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (/src/index.js) | |
| Modificada | Crítica (9.8) | 1.8% | — | Deep.assign Project Deep.assign | 30/6/2022 | 17/6/2026 | deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). | |
| Modificada | Media (4.3) | 0.65% | — | Discourse Assign | 26/4/2022 | 17/6/2026 | Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform. Prior to version 1.0.1, the UserBookmarkSerializer serialized the whole User / Group object, which leaked some private information. The data was only being serialized to people who could view assignment info,… | |
| Modificada | Crítica (9.8) | 1.6% | — | Binaryops X-assign | 20/10/2021 | 17/6/2026 | This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object. | |
| Modificada | Crítica (9.8) | 1.2% | — | Record-like-deep-assign Project Record-like-deep-assign | 2/7/2021 | 17/6/2026 | All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality. | |
| Modificada | Alta (7.5) | 1.5% | — | Getadigital Nested-object-assign | 31/1/2021 | 17/6/2026 | The package nested-object-assign before 1.0.4 are vulnerable to Prototype Pollution via the default function, as demonstrated by running the PoC below. | |
| Modificada | Alta (8.8) | 0.94% | — | Suse Openstack CloudSuse Keystone-json-assignmentHP Helion Openstack | 17/1/2020 | 17/6/2026 | The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources,… | |
| Modificada | Alta (7.5) | 1.1% | — | Assign-deep Project Assign-deep | 20/8/2019 | 17/6/2026 | assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload. | |
| Modificada | Alta (8.8) | 2.0% | — | Assign-deep Project Assign-deep | 7/6/2018 | 17/6/2026 | assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects. |