Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.21% | — | Automatic.cssAI | 26/9/2026 | 28/9/2026 | The Automatic.css plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in all version 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute whenever an administrator accesses… | |
| Aplazada | Alta (7.1) | 0.25% | — | Valvepress AutomaticAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Swit WP Sessions Time Monitoring Full AutomaticAI | 16/6/2026 | 17/6/2026 | Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions. | |
| Modificada | Media (5.5) | 0.19% | — | Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux | 13/6/2026 | 21/9/2026 | A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject… | |
| Modificada | Alta (7.8) | 0.23% | — | Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux | 13/6/2026 | 21/9/2026 | A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the… | |
| Aplazada | Media (5.3) | 0.29% | — | Swit WP Sessions Time Monitoring Full AutomaticAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.1.3. | |
| Aplazada | Media (4.3) | 0.23% | — | Webdevstudios Automatic Featured Images From VideosAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-from-videos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic Featured Images from Videos: from n/a through <= 1.2.7. | |
| Aplazada | Media (5.3) | 0.27% | — | Autochat Automatic ConversationAI | 25/11/2025 | 17/6/2026 | The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_auycht_saveCid' AJAX endpoint in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to connect and disconnect… | |
| Aplazada | Media (5.4) | 0.20% | — | Automaticwp AutomatormwpAI | 9/9/2025 | 17/6/2026 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple plugin's functions in all versions up to, and including, 5.3.7. This makes it possible… | |
| Aplazada | Media (4.7) | 0.19% | — | Valvepress Wordpress Automatic PluginAI | 26/8/2025 | 17/6/2026 | The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.118.0. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to update campaigns and inject malicious web… | |
| Aplazada | Alta (8.5) | 0.28% | — | Valvepress Pinterest Automatic PINAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows SQL Injection.This issue affects Pinterest Automatic Pin: from n/a through < 4.19.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | Turpak Automatic Station Monitoring SystemAI | 21/7/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Privilege Escalation. This issue affects Automatic Station Monitoring System: before 5.0.6.51. | |
| Aplazada | Media (6.5) | 0.23% | — | Atakanau Automatically Hierarchic Categories IN MenuAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atakan Au Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu allows Stored XSS.This issue affects Automatically Hierarchic Categories in Menu: from n/a through <= 2.0.9. | |
| Aplazada | Alta (8.8) | 0.74% | — | Valvepress Wordpress Automatic PluginAI | 11/6/2025 | 17/6/2026 | The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'core.php' file in all versions up to, and including, 3.115.0. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on… | |
| Aplazada | Media (4.3) | 0.28% | — | Valvepress Pinterest Automatic PINAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinterest Automatic Pin: from n/a through <= 4.19.0. | |
| Aplazada | Alta (7.1) | 0.14% | — | Milat Jquery Automatic PopupAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in milat Milat jQuery Automatic Popup milat-jquery-automatic-popup allows Stored XSS.This issue affects Milat jQuery Automatic Popup: from n/a through <= 1.3.1. | |
| Aplazada | Media (4.3) | 0.28% | — | Woocommerce Automatic Order PrintingAI | 24/4/2025 | 17/6/2026 | The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1 via the xc_woo_printer_preview AJAX action due to missing validation on a user controlled key. This makes it possible… | |
| Aplazada | Alta (7.1) | 0.29% | — | Autoglot Automatic Wordpress TranslationAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Autoglot Autoglot – Automatic WordPress Translation autoglot allows Reflected XSS.This issue affects Autoglot – Automatic WordPress Translation: from n/a through <= 2.4.7. | |
| Aplazada | Alta (7.1) | 0.23% | — | Dzynit Seo-automatic-seo-toolsAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dzynit SEO Tools seo-automatic-seo-tools allows Reflected XSS.This issue affects SEO Tools: from n/a through <= 4.0.7. | |
| Aplazada | Alta (7.1) | 0.34% | — | Kaizencoders Automatic BAN IPAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Automatic Ban IP automatic-ban-ip allows Reflected XSS.This issue affects Automatic Ban IP: from n/a through <= 1.0.7. | |
| Aplazada | Media (4.3) | 0.33% | — | Webdevstudios Automatic Featured Images From VideosAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-from-videos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic Featured Images from Videos: from n/a through <= 1.2.4. | |
| Aplazada | Media (4.7) | 0.46% | — | Wpfactory Scheduled Automatic Order Status Controller FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPFactory Scheduled & Automatic Order Status Controller for WooCommerce order-status-rules-for-woocommerce allows Phishing.This issue affects Scheduled & Automatic Order Status Controller for WooCommerce: from n/a through <= 3.7.1. | |
| Analizada | Media (6.5) | 0.84% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system by sending a specially crafted request to the application. | |
| Analizada | Media (6.1) | 0.42% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type application/html. If a victim accesses the malicious link, it will execute arbitrary JavaScript in the victim's… | |
| Analizada | Media (6.5) | 0.82% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server… |