Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
–

57 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.20%—Awesomesupport Awesome SupportAI1/10/20261/10/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.1)0.24%—Awesomesupport Awesome SupportAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.
AplazadaMedia (4.3)0.24%—Awesomesupport Awesome SupportAI9/9/202611/9/2026
The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or…
AplazadaMedia (5.3)0.44%—Awesomesupport Awesome SupportAI8/4/202625/7/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax() function failing to verify whether the authenticated user has permission to view the specific…
AplazadaMedia (6.5)0.40%—Awesomesupport Awesome SupportAI16/1/202617/6/2026
The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in all versions up to, and including, 6.3.6. This is due to the 'wpas_do_mr_activate_user' function not verifying that a user has permission to modify other users' roles,…
AplazadaAlta (7.2)0.47%—Awesomesupport Awesome SupportAI22/9/202530/9/2026
Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injection.This issue affects Awesome Support: from n/a through <= 6.3.5.
AplazadaMedia (5.3)0.29%—Awesomesupport Awesome SupportAI9/9/202517/6/2026
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a through <= 6.3.6.
AplazadaAlta (7.5)0.65%—Awesomesupport Awesome SupportAI1/4/202517/6/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.1 via the 'awesome-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the…
AplazadaMedia (5.5)0.27%—Rails ActivesupportAI9/1/202517/6/2026
ActiveSupport::EncryptedFile writes contents that will be encrypted to a temporary file. The temporary file's permissions are defaulted to the user's current `umask` settings, meaning that it's possible for other users on the same system to read the contents of the temporary file. Attackers that have access to the…
AplazadaMedia (5.3)0.92%—Rails ActivesupportAI9/1/202517/6/2026
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
AplazadaMedia (4.3)0.29%—Themesupport Hide Category BY User Role FOR WoocommerceAI7/1/202517/6/2026
Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce hide-category-by-user-role-for-woocommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through <= 2.1.1.
AplazadaMedia (6.5)0.60%—Awesomesupport Awesome SupportAI13/12/202417/6/2026
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.3.1.
AplazadaMedia (5.3)0.53%—Wponlinesupport Essential Plugin AccordionAIWponlinesupport Accordion SliderAI13/12/202417/6/2026
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Accordion and Accordion Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion and Accordion Slider: from n/a through 1.2.4.
AplazadaMedia (4.3)0.46%—Portfolio AND ProjectsAIWponlinesupport WP OnlinesupportAIEssentialplugin Essential PluginAI13/12/202417/6/2026
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Portfolio and Projects allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio and Projects: from n/a through 1.3.7.
ModificadaMedia (6.5)0.55%—Getawesomesupport Awesome Support9/12/202417/6/2026
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.7.
ModificadaMedia (5.4)0.48%—Getawesomesupport Awesome Support9/12/202417/6/2026
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.10.
ModificadaMedia (5.4)0.48%—Getawesomesupport Awesome Support9/12/202417/6/2026
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.1.4.
AplazadaMedia (5.3)0.42%—Wponlinesupport Featured Post CreativeAI9/12/202417/6/2026
Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Featured Post Creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through 1.2.7.
AplazadaAlta (8.5)0.54%—Wponlinesupport Essential Plugin Timeline AND History SliderAI19/8/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essential Plugin Timeline and History slider allows PHP Local File Inclusion.This issue affects Timeline and History slider: from n/a through 2.3.
ModificadaAlta (7.3)0.30%—Awesomesupport Awesome Support Wordpress Helpdesk & Support12/6/202417/6/2026
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.
ModificadaAlta (8.8)0.30%—Getawesomesupport Awesome Support10/6/202417/6/2026
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.
ModificadaMedia (5.4)0.31%—Getawesomesupport Awesome Support9/6/202417/6/2026
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.6.
ModificadaCrítica (9.8)0.40%—Getawesomesupport Awesome Support9/6/202417/6/2026
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.
ModificadaMedia (5.3)0.40%—Getawesomesupport Awesome Support10/2/202417/6/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access and…
ModificadaMedia (4.3)0.43%—Getawesomesupport Awesome Support10/2/202417/6/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level…