Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.40% | 💥 PoC | Strategy11 AWP ClassifiedsAI | 27/7/2026 | 27/7/2026 | Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. | |
| Aplazada | Alta (7.5) | 0.69% | — | Strategy11 AWP ClassifiedsAI | 5/5/2026 | 17/6/2026 | The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.34% | — | Strategy11 AWP ClassifiedsAI | 23/1/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Retrieve Embedded Sensitive Data.This issue affects AWP Classifieds: from n/a through <= 4.4.3. | |
| Modificada | Alta (8.8) | 0.32% | — | Strategy11 AWP Classifieds | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1. | |
| Aplazada | Media (4.3) | 0.21% | — | Strategy11 AWP ClassifiedsAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1. | |
| Modificada | Alta (8.8) | 0.25% | — | Strategy11 AWP Classifieds | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions. | |
| Modificada | Crítica (9.8) | 5.6% | 💥 Exploit | Strategy11 AWP Classifieds | 31/10/2022 | 17/6/2026 | The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Strategy11 AWP Classifieds | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action. | |
| Modificada | Media (4.3) | 1.6% | — | Strategy11 AWP Classifieds | 13/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI. |