Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

42 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.8)0.43%—Wp-feedstats Wordpress PluginAI5/9/20268/9/2026
The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who…
AplazadaAlta (8.2)0.20%—Wp-feedstats Wordpress PluginAI2/9/20263/9/2026
The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc
AplazadaAlta (7.5)0.41%—Wp-feedstats Wordpress PluginAI31/7/202626/8/2026
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.
AplazadaMedia (5.3)0.30%—Wp-feedstats Wordpress PluginAI22/7/202622/7/2026
The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.
AplazadaMedia (5.4)0.14%—Wp-feedstats Wordpress PluginAI20/7/202620/7/2026
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's…
AplazadaNinguna (0)0.44%—Rdstation ConversasAI13/7/20269/9/2026
Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas chat feature. The vulnerability lies in the ‘name’ parameter of the initialisation process due to incorrect sanitisation of user-supplied input. Exploitation allows specially crafted JavaScript code to be injected, which is executed within…
AplazadaAlta (8.8)0.43%—Wp-feedstats Wordpress PluginAI23/6/202623/6/2026
The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above.
AplazadaCrítica (9.9)0.52%—Rdstation RD StationAI16/6/202617/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0.
AplazadaBaja (3.2)0.15%—Clickstudios PasswordstateAI16/9/202530/9/2026
Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwordstate Administration section.
AplazadaAlta (8.8)0.41%—Clickstudios PasswordstateAI29/11/202417/6/2026
In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.
ModificadaMedia (5.4)0.33%—Rdstation RD Station5/9/202417/6/2026
The RD Station plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping of post metaboxes added by the plugin. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AplazadaMedia (6.5)0.31%—Clickstudios PasswordstateAI24/6/202417/6/2026
Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass.
ModificadaMedia (4.7)0.44%—Clickstudios Passwordstate13/11/202317/6/2026
An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API endpoint. It is also possible to use the Copy/Move Password Record API Key to…
ModificadaBaja (3.5)0.24%—Clickstudios Passwordstate31/10/202317/6/2026
Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a local attacker to execute arbitrary code via a crafted request.
ModificadaMedia (6.5)0.75%—Clickstudios Passwordstate19/12/202217/6/2026
A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as critical. This issue affects some unknown processing of the component Browser Extension Provisioning. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit…
ModificadaMedia (6.5)0.88%—Clickstudios Passwordstate19/12/202217/6/2026
A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as problematic. This vulnerability affects unknown code. The manipulation leads to insufficiently protected credentials. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaMedia (5.3)1.3%—Clickstudios Passwordstate19/12/202217/6/2026
A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This affects an unknown part. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may…
ModificadaMedia (5.5)0.24%—Clickstudios Passwordstate19/12/202217/6/2026
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected by this issue is some unknown functionality. The manipulation leads to risky cryptographic algorithm. Local access is required to approach this attack. The exploit…
ModificadaMedia (5.4)0.66%—Clickstudios Passwordstate19/12/202217/6/2026
A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected is an unknown function of the component URL Field Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has…
ModificadaMedia (6.5)0.88%—Clickstudios Passwordstate19/12/202217/6/2026
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This issue affects some unknown processing of the file /api/browserextension/UpdatePassword/ of the component API. The manipulation of the argument PasswordID leads to…
ModificadaAlta (7.5)1.0%—Clickstudios Passwordstate19/12/202217/6/2026
A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This vulnerability affects unknown code of the component API. The manipulation leads to authentication bypass by assumed-immutable data. The attack can be initiated remotely. The exploit has been…
ModificadaAlta (8.8)0.33%—Rdstation RD Station13/9/202217/6/2026
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in RD Station plugin <= 5.2.0 at WordPress.
ModificadaAlta (8.8)0.42%—BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Ciisafe FirmwareBD Pyxis Logistics FirmwareBD Pyxis Medbank Firmware+122/6/202217/6/2026
Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product…
ModificadaMedia (6.5)0.82%—Clickstudios Passwordstate21/3/202217/6/2026
In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all…
ModificadaMedia (5.5)0.23%—BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Anesthesia Station 4000 FirmwareBD Pyxis Cato FirmwareBD Pyxis Ciisafe Firmware+2011/2/202217/6/2026
Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health…