Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

368 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.20%—Wpexperts Contact Form 7 HoneypotAI1/10/20261/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in WPExperts CF7 Apps contact-form-7-honeypot allows Retrieve Embedded Sensitive Data.This issue affects CF7 Apps: from n/a through 3.7.2.
AplazadaMedia (5.3)0.23%—Wpexperts NEW User ApproveAI30/9/202630/9/2026
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
AplazadaMedia (5.4)0.29%—Wpexperts Post SmtpAI31/8/20261/9/2026
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1.
Pendiente de análisisCrítica (9.9)0.29%—IBM Administration Runtime Expert FOR IAIIBM Application Runtime Expert FOR IAI28/8/202631/8/2026
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining…
Pendiente de análisisAlta (7.5)0.43%—IBM Administration Runtime Expert FOR IAI28/8/20261/9/2026
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
AplazadaAlta (7.1)0.29%—Wpexperts License Manager FOR WoocommerceAI18/8/202620/8/2026
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
AplazadaAlta (7.5)0.44%—Wpexperts Password ProtectedAI7/8/202626/8/2026
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content…
AplazadaAlta (8.8)0.52%—Wpexperts Wholesale FOR WoocommerceAI29/7/202630/7/2026
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with…
AplazadaCrítica (9.4)0.42%—Themexpert JmediaAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.
AplazadaMedia (5.1)0.39%—Themexpert JmediaAI20/7/202623/7/2026
Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses.
AplazadaCrítica (9.4)0.41%—Themexpert JmediaAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.
AplazadaMedia (6.9)0.43%—Themexpert Quix Page BuilderAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses.
AplazadaAlta (8.7)0.41%—Themexpert Quix Page BuilderAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions.
AplazadaMedia (5.1)0.42%—Themexpert Quix Page BuilderAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.
AplazadaAlta (8.6)0.42%—Themexpert Quix Page BuilderAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output +…
AplazadaAlta (8.7)0.52%—Themexpert Quix Page BuilderAIJoomlaAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths and read arbitrary files.…
AplazadaAlta (8.9)0.53%—Themexpert Quix Page BuilderAI20/7/202623/7/2026
Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via…
AplazadaAlta (8.7)0.40%—Themexpert Quix Page Builder PROAIJoomlaAI16/7/202623/7/2026
Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection.
AplazadaMedia (5.4)0.29%—Wpexperts License Manager FOR WoocommerceAI13/7/202613/7/2026
Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.
AplazadaAlta (8.5)0.36%—Saad Iqbal Apiexperts Square FOR WoocommerceAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.4.
AplazadaMedia (4.3)0.33%—Codexpert INC ThumbpressAI1/7/20261/7/2026
Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2.
AplazadaMedia (6.5)0.33%—Wpexperts License Manager FOR WoocommerceAI25/6/202629/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
AplazadaAlta (8.3)0.32%—Saad Iqbal Apiexperts Square FOR WoocommerceAI25/6/202625/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.
AnalizadaBaja (3.7)0.34%—Fastapiexpert Python-multipart22/6/202626/6/2026
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a…
AnalizadaAlta (7.5)0.46%—Fastapiexpert Python-multipart22/6/202626/6/2026
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to…