Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2573▼ 368 respecto a la semana anterior
Críticas / altas1324▲ 44 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.91%—Count PER DAY Project Count PER DAY21/8/201916/6/2026
The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.
ModificadaMedia (6.1)0.98%—Count PER DAY Project Count PER DAY15/6/201917/6/2026
The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter.
ModificadaAlta (7.2)7.2%—Count PER DAY Project Count PER DAY23/10/201717/6/2026
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE: this can be leveraged using CSRF to allow remote attackers to…
ModificadaMedia (4.3)2.4%—TOM Braider Count PER DAY15/8/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in userperspan.php in the Count Per Day module before 3.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) datemin, or (3) datemax parameter.
ModificadaMedia (5)23%—Count PER DAY Project Count PER DAYTOM Braider Count PER DAY20/1/201216/6/2026
Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.
ModificadaMedia (4.3)5.3%—TOM Braider Count PER DAY20/1/201216/6/2026
Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map parameter.