Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.33%—Vinodvaswani9 Bulk Assign Linked Products FOR WoocommerceAI24/4/202517/6/2026
Missing Authorization vulnerability in vinodvaswani9 Bulk Assign Linked Products For WooCommerce wc-bulk-assign-linked-products allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk Assign Linked Products For WooCommerce: from n/a through <= 2.1.
ModificadaMedia (4.8)0.28%—Shanebp BP Email Assign Templates11/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Stored XSS.This issue affects BP Email Assign Templates: from n/a through <= 1.6.
ModificadaMedia (4.9)0.45%—Shanebp BP Email Assign Templates11/3/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Email Assign Templates: from n/a through <= 1.7.
AplazadaAlta (7.1)0.28%—Shanebp BP Email Assign TemplatesAI3/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Reflected XSS.This issue affects BP Email Assign Templates: from n/a through <= 1.5.
AplazadaAlta (7.1)0.32%—Bulk Categories AssignAI3/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Haider Ali Bulk Categories Assign bulk-categories-assign allows Reflected XSS.This issue affects Bulk Categories Assign: from n/a through <= 1.0.
AplazadaMedia (6.1)0.42%—Shanebp BP Email Assign TemplatesAI12/12/202417/6/2026
The BP Email Assign Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
ModificadaCrítica (9.8)0.97%—Alykoshin Mini-deep-assign30/7/202417/6/2026
Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the _assign() method at (/lib/index.js:91)
AplazadaCrítica (9.8)0.56%—Alexbinary Object-deep-assignAI17/6/202417/6/2026
alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (/src/index.js)
ModificadaCrítica (9.8)1.8%—Deep.assign Project Deep.assign30/6/202217/6/2026
deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').
ModificadaMedia (4.3)0.65%—Discourse Assign26/4/202217/6/2026
Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform. Prior to version 1.0.1, the UserBookmarkSerializer serialized the whole User / Group object, which leaked some private information. The data was only being serialized to people who could view assignment info,…
ModificadaCrítica (9.8)1.6%—Binaryops X-assign20/10/202117/6/2026
This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.
ModificadaCrítica (9.8)1.2%—Record-like-deep-assign Project Record-like-deep-assign2/7/202117/6/2026
All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.
ModificadaAlta (7.5)1.5%—Getadigital Nested-object-assign31/1/202117/6/2026
The package nested-object-assign before 1.0.4 are vulnerable to Prototype Pollution via the default function, as demonstrated by running the PoC below.
ModificadaAlta (8.8)0.94%—Suse Openstack CloudSuse Keystone-json-assignmentHP Helion Openstack17/1/202017/6/2026
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources,…
ModificadaAlta (7.5)1.1%—Assign-deep Project Assign-deep20/8/201917/6/2026
assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload.
ModificadaAlta (8.8)2.0%—Assign-deep Project Assign-deep7/6/201817/6/2026
assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Orbitaley — Vulnerabilidades