Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3071▲ 536 respecto a la semana anterior
Críticas / altas1456▲ 257 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)384▲ 177 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.25% | — | CreateAI | 19/9/2026 | 21/9/2026 | The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.28% | — | CreateAI | 19/9/2026 | 21/9/2026 | The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.27% | — | CreateAI | 9/8/2026 | 26/8/2026 | The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly… | |
| Aplazada | Media (6.5) | 0.27% | — | CreateAI | 9/8/2026 | 26/8/2026 | The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available. | |
| Aplazada | Alta (8) | 0.46% | — | Create BlockAI | 4/8/2026 | 26/8/2026 | The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite subsite administrator (who holds the capability gating this action but is denied the capability that normally gates PHP file editing) to inject and… | |
| Aplazada | Media (5.3) | 0.33% | — | Mediavine CreateAI | 23/7/2026 | 18/9/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in John-Michael L'Allier Create mediavine-create allows Retrieve Embedded Sensitive Data.This issue affects Create: from n/a through 2.6.0. | |
| Aplazada | Alta (8.5) | 0.36% | — | John-michael L Allier CreateAI | 23/7/2026 | 21/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create mediavine-create allows Blind SQL Injection.This issue affects Create: from n/a through 2.5.3. | |
| Pendiente de análisis | Media (4.3) | 0.28% | — | SAP Create Single PaymentAI | 14/7/2026 | 14/7/2026 | SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and availability of the application. | |
| Aplazada | Media (5.5) | 2.1% | — | Facebook Create-react-appAIFacebook React-dev-utilsAI | 6/7/2026 | 6/7/2026 | A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and… | |
| Aplazada | Crítica (9.1) | 0.89% | — | Create DB TablesAI | 22/4/2026 | 17/6/2026 | The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action hooks for creating tables (admin_post_add_table) and deleting tables (admin_post_delete_db_table) without implementing any capability checks via… | |
| Aplazada | Alta (7.1) | 0.15% | — | Valentin Agachi Create Posts AND TermsAI | 9/12/2025 | 30/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Valentin Agachi Create Posts & Terms create-posts-terms allows Stored XSS.This issue affects Create Posts & Terms: from n/a through <= 1.3.1. | |
| Aplazada | Crítica (9.3) | 1.3% | — | Akoskm Create-mcp-server-stdioAI | 8/9/2025 | 17/6/2026 | @akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. The MCP Server exposes the… | |
| Modificada | Alta (8.2) | 0.42% | — | Getprojects Create School Management System | 30/7/2025 | 17/6/2026 | GetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_form1.php. | |
| Aplazada | Media (4.3) | 0.24% | — | Sminozzi Real Estate Property 2024 Create Your OWN Fields AND Search BARAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in sminozzi Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin real-estate-right-now allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin: from n/a… | |
| Analizada | Alta (7.8) | 0.97% | — | Create-cloudflareOpennextjs Opennext FOR Cloudflare | 16/6/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open Next, which allowed unauthenticated users to proxy arbitrary remote content via the /_next/image endpoint. This issue allowed… | |
| Aplazada | Media (4.3) | 0.14% | — | Mariusz88atelierweb Atelier Create CVAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mariusz88atelierweb Atelier Create CV atelier-create-cv allows Cross Site Request Forgery.This issue affects Atelier Create CV: from n/a through <= 1.1.5. | |
| Aplazada | Alta (7.3) | 0.54% | — | Create Custom Forms FOR Wordpress With A Smart Form Plugin FOR Smart BusinessesAI | 26/4/2025 | 17/6/2026 | The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.4. This is due to the software allowing users to execute an action that does not properly validate a value before running… | |
| Aplazada | Media (6.5) | 0.35% | — | Pddring Create With CodeAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pddring Create with Code create-with-code allows DOM-Based XSS.This issue affects Create with Code: from n/a through <= 1.4. | |
| Aplazada | Media (4.3) | 0.33% | — | Ecreate Infotech Auto TAG CreatorAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Ecreate Infotech Auto Tag Creator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Tag Creator: from n/a through 1.0.2. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Fliperrr Create-flipbook-from-pdfAI | 16/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in fliperrr Creates 3D Flipbook, PDF Flipbook create-flipbook-from-pdf allows Upload a Web Shell to a Web Server.This issue affects Creates 3D Flipbook, PDF Flipbook: from n/a through <= 1.2. | |
| Analizada | Media (5.3) | 0.33% | — | Miraheze Createwiki | 7/10/2024 | 17/6/2026 | CreateWiki is an extension used at Miraheze for requesting & creating wikis. The name of requested wikis is not escaped on Special:RequestWikiQueue, so a user can insert arbitrary HTML that is displayed in the request wiki queue when requesting a wiki. If a wiki creator comes across the XSS payload, their user session… | |
| Modificada | Media (5.9) | 0.23% | — | Catchthemes Create | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchthemes Create create allows Stored XSS.This issue affects Create: from n/a through <= 2.9.1. | |
| Aplazada | Media (6.8) | 0.15% | — | Siemens Sinumerik 828dAISiemens Sinumerik 840d SLAISiemens Sinumerik ONEAISiemens Create MyconfigAI | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SINUMERIK 828D V4 (All versions < V4.95 SP3), SINUMERIK 840D sl V4 (All versions < V4.95 SP3 in connection with using Create MyConfig (CMC) <= V4.8 SP1 HF6), SINUMERIK ONE (All versions < V6.23 in connection with using Create MyConfig (CMC) <= V6.6), SINUMERIK ONE (All versions <… | |
| Modificada | Alta (7.5) | 0.37% | — | Mediavine Create | 26/8/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in mischiefmarmot Create by Mediavine mediavine-create.This issue affects Create by Mediavine: from n/a through <= 1.9.8. | |
| Modificada | Media (5.4) | 0.28% | — | Mediavine Create | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mischiefmarmot Create by Mediavine mediavine-create.This issue affects Create by Mediavine: from n/a through <= 1.9.7. |