Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

54 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.1)0.27%—Zyxware Disable Login Page2/9/20268/9/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
AnalizadaMedia (4.3)0.27%—Dell Cloud Disaster Recovery26/8/20263/9/2026
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
AnalizadaAlta (7.2)1.6%—Dell Cloud Disaster Recovery26/8/20263/9/2026
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
AnalizadaCrítica (9.1)2.0%—Dell Cloud Disaster Recovery26/8/20263/9/2026
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Pendiente de análisisMedia (5.7)0.22%—Drupal Disable Login PageAI25/8/20262/9/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
AnalizadaMedia (5.4)0.28%—Budda Login Disable10/7/20266/8/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This issue affects Login Disable versions: from 0.0.0 to 2.1.4.
AplazadaAlta (7.1)0.44%—Themeisle Disable Comments FOR ANY Post TypesAI27/5/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types (Remove comments) comments-plus allows Password Recovery Exploitation.This issue affects Disable Comments for Any Post Types (Remove comments): from n/a through <= 1.3.0.
AnalizadaMedia (4.3)0.20%—Budda Login Disable25/3/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypass.This issue affects Login Disable: from 0.0.0 before 2.1.3.
AplazadaMedia (4.3)0.13%—Disable Admin Notices Hide Dashboard NotificationsAI25/2/202617/6/2026
The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing nonce validation in the `showPageContent()` function. This makes it possible for unauthenticated attackers to add arbitrary URLs…
AnalizadaMedia (4.2)0.24%—Zyxware Disable Login Page28/1/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass.This issue affects Disable Login Page: from 0.0.0 before 1.1.3.
AplazadaMedia (5.4)0.12%—Meks Quick Plugin DisablerAI16/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Meks Meks Quick Plugin Disabler meks-quick-plugin-disabler allows Cross Site Request Forgery.This issue affects Meks Quick Plugin Disabler: from n/a through <= 1.0.
AplazadaMedia (4.3)0.13%—Disable Content Editor FOR Specific TemplateAI24/10/202517/6/2026
The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing nonce validation on template configuration updates. This makes it possible for unauthenticated attackers to add or delete template…
AnalizadaMedia (6.7)0.46%—Dell Cloud Disaster Recovery25/9/202517/6/2026
Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
AplazadaMedia (6.5)0.16%—Damian BP BP Disable Activation ReloadedAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Damian BP Disable Activation Reloaded bp-disable-activation-reloaded allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BP Disable Activation Reloaded: from n/a through <= 1.2.1.
AplazadaCrítica (9.8)0.44%—Disable-right-click-powered-by-pixtermeAIPixter-image-digital-licenseAI14/8/202517/6/2026
The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who control it, but it currently displays an alert marketing security…
AplazadaCrítica (9.9)0.77%—Wildermyth WilderforgeAIWildermyth ExamplemodAIWildermyth WilderworkspaceAIWildermythgameproviderAI+59/6/202517/6/2026
WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe usage of `${{ github.event.review.body }}` and other user controlled variables directly inside shell script contexts in GitHub Actions…
AplazadaAlta (7.1)0.19%—Awplife Right Click Disable OR BANAI16/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban right-click-disable-or-ban allows Stored XSS.This issue affects Right Click Disable OR Ban: from n/a through <= 1.1.17.
AplazadaMedia (5.4)0.15%—Misteraon Simple Trackback DisablerAI28/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in misteraon Simple Trackback Disabler simple-trackback-disabler allows Cross Site Request Forgery.This issue affects Simple Trackback Disabler: from n/a through <= 1.4.
AplazadaMedia (4.3)0.23%—Disable Elementor Editor TranslationAI27/3/202517/6/2026
Missing Authorization vulnerability in Leap13 Disable Elementor Editor Translation disable-elementor-editor-translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Disable Elementor Editor Translation: from n/a through <= 1.0.2.
AnalizadaMedia (4.3)0.17%—Exeebit Disable Auto Updates19/2/202517/6/2026
The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'disable-auto-updates' page. This makes it possible for unauthenticated attackers to disable all auto updates via a forged…
AnalizadaMedia (5.4)0.26%—Login Disable Project Login Disable9/1/202517/6/2026
Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1.
AplazadaMedia (4.3)0.19%—Themeisle Disable Admin NoticesAI19/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Disable Admin Notices individually disable-admin-notices allows Cross Site Request Forgery.This issue affects Disable Admin Notices individually: from n/a through <= 1.4.0.
AplazadaAlta (7.6)0.52%—Wpzest Disable CommentsAI15/4/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPZest Disable Comments | WPZest.This issue affects Disable Comments | WPZest: from n/a through 1.51.
ModificadaAlta (8.8)0.22%—Atakanau Click Disable ALL28/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au 1 click disable all.This issue affects 1 click disable all: from n/a through 1.0.1.
ModificadaMedia (4.3)0.40%—Veeam Availability OrchestratorVeeam Disaster Recovery OrchestratorVeeam Recovery Orchestrator7/2/202417/6/2026
Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to.