Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.43%—Dokan PROAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
AplazadaAlta (7.1)0.29%—Wedevs Dokan PROAI23/7/202623/7/2026
Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
AplazadaAlta (7.5)0.40%—Dokan PROAI23/7/202623/7/2026
Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
AplazadaAlta (7.1)0.25%—Wedevs Dokan PROAI23/7/202621/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs Dokan Pro allows Reflected XSS. This issue affects Dokan Pro: from n/a before 5.0.7.
AplazadaCrítica (9.8)0.48%—Dokan PROAI26/6/202626/6/2026
Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.
AplazadaMedia (6.5)0.38%—Dokan PROAI25/6/202626/6/2026
The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
AplazadaAlta (7.5)0.46%—Dokan PROAI25/6/202629/6/2026
The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (6.5)0.15%—Dokan PROAI5/1/202630/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan Dokan Pro allows Stored XSS.This issue affects Dokan Pro: from n/a through 3.14.5.
AplazadaAlta (8.8)0.44%—Wedevs Dokan PROAI26/8/202517/6/2026
The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.5. This is due to the plugin not properly validating a user's identity prior to updating their password during a staff password reset. This makes it possible for authenticated…