Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.22% | — | Awesomemotive WP Mail LoggingAI | 2/10/2026 | 2/10/2026 | The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log… | |
| Aplazada | Media (6.4) | 0.20% | — | Awesomesupport Awesome SupportAI | 1/10/2026 | 1/10/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.24% | — | Awesomesupport Awesome SupportAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions. | |
| Aplazada | Media (4.3) | 0.24% | — | Awesomesupport Awesome SupportAI | 9/9/2026 | 11/9/2026 | The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or… | |
| Aplazada | Media (4.3) | 0.27% | — | Advancedcustomfields Font Awesome FieldAI | 6/8/2026 | 12/8/2026 | Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions. | |
| Aplazada | Baja (2.1) | 0.37% | — | Aianytime Awesome-mcp-serverAI | 5/7/2026 | 6/7/2026 | A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. Affected by this issue is some unknown functionality of the file mcp-wiki/src/mcp_wiki/server.py of the component mcp-wiki/wiki-summary. This manipulation of the argument url causes server-side request forgery. The… | |
| Aplazada | Media (6.5) | 0.22% | — | Advancedcustomfields Font Awesome FieldAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced Custom Fields: Font Awesome Field allows Stored XSS. This issue affects Advanced Custom Fields: Font Awesome Field: from n/a through 5.0.2. | |
| Aplazada | Media (6.4) | 0.35% | — | Advanced Custom Fields Font AwesomeAI | 15/5/2026 | 17/6/2026 | The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due to insufficient input validation of JSON field values and unsafe client-side HTML construction in the update_preview() JavaScript function. This makes it… | |
| Aplazada | Baja (2.1) | 1.8% | — | Kleneway Awesome-cursor-mpc-serverAI | 2/5/2026 | 17/6/2026 | A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Review Tool. Executing a manipulation can lead to command injection. The attack may be launched remotely. The exploit has been published and may… | |
| Aplazada | Media (5.3) | 0.44% | — | Awesomesupport Awesome SupportAI | 8/4/2026 | 25/7/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax() function failing to verify whether the authenticated user has permission to view the specific… | |
| Analizada | Alta (8.2) | 0.37% | — | Theunwindai Awesome LLM Apps | 30/3/2026 | 17/6/2026 | A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19). The affected Streamlit-based GitHub MCP Agent stores user-supplied API tokens in process-wide environment variables using os.environ without proper session… | |
| Analizada | Alta (7.5) | 0.65% | — | Theunwindai Awesome LLM Apps | 27/3/2026 | 17/6/2026 | A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19) in the Beifong AI News and Podcast Agent backend in FastAPI backend, stream-audio endpoint, in file routers/podcast_router.py, in function stream_audio. The stream-audio endpoint… | |
| Aplazada | Media (6.4) | 0.24% | — | EDS Font AwesomeAI | 21/3/2026 | 17/6/2026 | The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_awesome` shortcode in all versions up to, and including, 2.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (7.5) | 0.39% | — | Awesomemotive WP Mail LoggingAI | 28/2/2026 | 17/6/2026 | The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.15.0 via deserialization of untrusted input from the email log message field. This is due to the `BaseModel` class constructor calling `maybe_unserialize()` on all properties retrieved from the… | |
| Aplazada | Media (6.4) | 0.30% | — | Advanced Custom Fields Font Awesome FieldAI | 19/2/2026 | 17/6/2026 | The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping. This makes it possible forauthenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (6.5) | 0.40% | — | Awesomesupport Awesome SupportAI | 16/1/2026 | 17/6/2026 | The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in all versions up to, and including, 6.3.6. This is due to the 'wpas_do_mr_activate_user' function not verifying that a user has permission to modify other users' roles,… | |
| Aplazada | Media (5.3) | 0.26% | — | Awesome Hotel BookingAI | 7/1/2026 | 17/6/2026 | The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect authorization in the room-single.php shortcode handler in all versions up to, and including, 1.0.3. This is due to the plugin relying solely on nonce verification without capability checks. This makes it… | |
| Aplazada | Media (4.3) | 0.18% | — | Themesawesome History TimelineAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in themesawesome History Timeline timeline-awesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects History Timeline: from n/a through <= 1.0.6. | |
| Analizada | Alta (7.3) | 0.26% | — | Awesomeminer Awesome Miner | 18/11/2025 | 17/6/2026 | A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an unprivileged user. This is due to the implementation of an insecure version of WinRing0 (1.2.0.5, renamed to IntelliBreeze.Maintenance.Service.sys) that lacks a properly… | |
| Aplazada | Alta (7.1) | 0.12% | — | Prakash Awesome TestimonialsAI | 27/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Prakash Awesome Testimonials awesome-testimonials allows Stored XSS.This issue affects Awesome Testimonials: from n/a through <= 2.2.1. | |
| Aplazada | Alta (7.2) | 0.47% | — | Awesomesupport Awesome SupportAI | 22/9/2025 | 30/9/2026 | Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injection.This issue affects Awesome Support: from n/a through <= 6.3.5. | |
| Aplazada | Media (5.3) | 0.29% | — | Awesomesupport Awesome SupportAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a through <= 6.3.6. | |
| Aplazada | Media (6.5) | 0.22% | — | Shiful H SS Font Awesome IconAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shiful H SS Font Awesome Icon ss-font-awesome-icon allows Stored XSS.This issue affects SS Font Awesome Icon: from n/a through <= 4.1.3. | |
| Aplazada | Alta (7.1) | 0.12% | — | Looks Awesome Onionbuzz Viral QuizAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Looks Awesome OnionBuzz onionbuzz-viral-quiz allows Stored XSS.This issue affects OnionBuzz: from n/a through <= 1.0.7. | |
| Analizada | Media (5.4) | 0.34% | — | Awesomemotive Easy Digital Downloads | 29/5/2025 | 17/6/2026 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode in all versions up to, and including, 3.3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This… |