Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

163 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.20%—Wpexperts Contact Form 7 HoneypotAI1/10/20261/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in WPExperts CF7 Apps contact-form-7-honeypot allows Retrieve Embedded Sensitive Data.This issue affects CF7 Apps: from n/a through 3.7.2.
AplazadaMedia (5.3)0.23%—Wpexperts NEW User ApproveAI30/9/202630/9/2026
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
AplazadaAlta (7.1)0.25%—WpadvertsAI10/9/202610/9/2026
Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.
AplazadaAlta (8.2)0.85%—Erlang OTPAIErlang ErtsAI1/9/20268/9/2026
An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond up to about 2 GB. This would easily trash the allocated block's allocator metadata…
AplazadaMedia (5.4)0.29%—Wpexperts Post SmtpAI31/8/20261/9/2026
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1.
AplazadaAlta (7.1)0.29%—Wpexperts License Manager FOR WoocommerceAI18/8/202620/8/2026
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
AplazadaAlta (7.5)1.6%—WpadvertsAI18/8/202620/8/2026
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site…
AplazadaAlta (7.5)0.44%—Wpexperts Password ProtectedAI7/8/202626/8/2026
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content…
AplazadaAlta (8.8)0.52%—Wpexperts Wholesale FOR WoocommerceAI29/7/202630/7/2026
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with…
AnalizadaMedia (5.1)0.29%—Erlang/otpErlang Erts27/7/202610/8/2026
Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer and crash the virtual machine. When decoding a LARGE_TUPLE_EXT term, the validation pass…
AnalizadaAlta (8.2)0.42%—Erlang/otpErlang Erts27/7/202610/8/2026
Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Overflow, Excessive Allocation. This vulnerability is associated with program files erts/emulator/beam/external.c, emulator/beam/external.c. The BIT_BINARY_EXT tag (77)…
AnalizadaMedia (6.3)0.43%—Erlang/otpErlang Erts27/7/202610/8/2026
Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemon (epmd) via connection slot exhaustion. The do_accept function in erts/epmd/src/epmd_srv.c calls epmd_cleanup_exit() when accept(2) returns…
AplazadaMedia (6.5)0.52%—Caxperts Universalplantviewer Webservices ServerAI14/7/202615/7/2026
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver.
AplazadaMedia (5.4)0.29%—Wpexperts License Manager FOR WoocommerceAI13/7/202613/7/2026
Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.
AplazadaAlta (8.5)0.36%—Saad Iqbal Apiexperts Square FOR WoocommerceAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.4.
AplazadaAlta (8.1)0.48%—Caxperts UpvwebservicesAICaxperts Udith PortalAI8/7/20269/7/2026
In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license.
AplazadaAlta (7.1)0.25%—WpadvertsAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.1 versions.
AplazadaMedia (6.5)0.33%—Wpexperts License Manager FOR WoocommerceAI25/6/202629/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
AplazadaAlta (8.3)0.32%—Saad Iqbal Apiexperts Square FOR WoocommerceAI25/6/202625/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.
AplazadaAlta (7.1)0.25%—Wpexperts Post SmtpAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions.
AplazadaMedia (6.5)0.33%—WpadvertsAI15/6/202617/6/2026
Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.
ModificadaAlta (8.8)0.50%—Erlang/otpErlang Erts10/6/202624/9/2026
Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size…
AplazadaAlta (8.5)0.36%—Saad Iqbal Apiexperts Square FOR WoocommerceAI12/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.1.
AplazadaMedia (6.5)0.33%—Wpexperts NEW User ApproveAI25/3/202617/6/2026
Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through <= 3.2.3.
AplazadaAlta (7.2)0.39%—Wpexperts Post SmtpAI18/3/202617/6/2026
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘event_type’ parameter in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This…