Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.21%—Automatic.cssAI26/9/202628/9/2026
The Automatic.css plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in all version 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute whenever an administrator accesses…
AplazadaAlta (7.1)0.25%—Valvepress AutomaticAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.
AplazadaAlta (8.5)0.36%—Swit WP Sessions Time Monitoring Full AutomaticAI16/6/202617/6/2026
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
ModificadaMedia (5.5)0.19%—Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux13/6/202621/9/2026
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject…
ModificadaAlta (7.8)0.23%—Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux13/6/202621/9/2026
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the…
AplazadaMedia (5.3)0.29%—Swit WP Sessions Time Monitoring Full AutomaticAI13/3/202617/6/2026
Missing Authorization vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.1.3.
AplazadaMedia (4.3)0.23%—Webdevstudios Automatic Featured Images From VideosAI23/1/202617/6/2026
Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-from-videos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic Featured Images from Videos: from n/a through <= 1.2.7.
AplazadaMedia (5.3)0.27%—Autochat Automatic ConversationAI25/11/202517/6/2026
The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_auycht_saveCid' AJAX endpoint in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to connect and disconnect…
AplazadaMedia (5.4)0.20%—Automaticwp AutomatormwpAI9/9/202517/6/2026
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple plugin's functions in all versions up to, and including, 5.3.7. This makes it possible…
AplazadaMedia (4.7)0.19%—Valvepress Wordpress Automatic PluginAI26/8/202517/6/2026
The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.118.0. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to update campaigns and inject malicious web…
AplazadaAlta (8.5)0.28%—Valvepress Pinterest Automatic PINAI14/8/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows SQL Injection.This issue affects Pinterest Automatic Pin: from n/a through < 4.19.0.
AplazadaAlta (7.1)0.29%—Turpak Automatic Station Monitoring SystemAI21/7/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Privilege Escalation. This issue affects Automatic Station Monitoring System: before 5.0.6.51.
AplazadaMedia (6.5)0.23%—Atakanau Automatically Hierarchic Categories IN MenuAI20/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atakan Au Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu allows Stored XSS.This issue affects Automatically Hierarchic Categories in Menu: from n/a through <= 2.0.9.
AplazadaAlta (8.8)0.74%—Valvepress Wordpress Automatic PluginAI11/6/202517/6/2026
The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'core.php' file in all versions up to, and including, 3.115.0. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on…
AplazadaMedia (4.3)0.28%—Valvepress Pinterest Automatic PINAI16/5/202517/6/2026
Missing Authorization vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinterest Automatic Pin: from n/a through <= 4.19.0.
AplazadaAlta (7.1)0.14%—Milat Jquery Automatic PopupAI24/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in milat Milat jQuery Automatic Popup milat-jquery-automatic-popup allows Stored XSS.This issue affects Milat jQuery Automatic Popup: from n/a through <= 1.3.1.
AplazadaMedia (4.3)0.28%—Woocommerce Automatic Order PrintingAI24/4/202517/6/2026
The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1 via the xc_woo_printer_preview AJAX action due to missing validation on a user controlled key. This makes it possible…
AplazadaAlta (7.1)0.29%—Autoglot Automatic Wordpress TranslationAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Autoglot Autoglot – Automatic WordPress Translation autoglot allows Reflected XSS.This issue affects Autoglot – Automatic WordPress Translation: from n/a through <= 2.4.7.
AplazadaAlta (7.1)0.23%—Dzynit Seo-automatic-seo-toolsAI15/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dzynit SEO Tools seo-automatic-seo-tools allows Reflected XSS.This issue affects SEO Tools: from n/a through <= 4.0.7.
AplazadaAlta (7.1)0.34%—Kaizencoders Automatic BAN IPAI11/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Automatic Ban IP automatic-ban-ip allows Reflected XSS.This issue affects Automatic Ban IP: from n/a through <= 1.0.7.
AplazadaMedia (4.3)0.33%—Webdevstudios Automatic Featured Images From VideosAI1/4/202517/6/2026
Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-from-videos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic Featured Images from Videos: from n/a through <= 1.2.4.
AplazadaMedia (4.7)0.46%—Wpfactory Scheduled Automatic Order Status Controller FOR WoocommerceAI27/3/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPFactory Scheduled & Automatic Order Status Controller for WooCommerce order-status-rules-for-woocommerce allows Phishing.This issue affects Scheduled & Automatic Order Status Controller for WooCommerce: from n/a through <= 3.7.1.
AnalizadaMedia (6.5)0.84%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system by sending a specially crafted request to the application.
AnalizadaMedia (6.1)0.42%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type application/html. If a victim accesses the malicious link, it will execute arbitrary JavaScript in the victim's…
AnalizadaMedia (6.5)0.82%—Automatic1111 Stable-diffusion-webui20/3/202517/6/2026
A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server…