Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

454 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (6.5)——WC Fields FactoryAI6/10/20266/10/2026
Subscriber Cross Site Scripting (XSS) in WC Fields Factory <= 4.1.12 versions.
RecibidaMedia (6.1)0.27%—Calculated Fields FormAI3/10/20263/10/2026
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'arbitrary (whichever names the admin bound via url.<name>)' parameter in all versions up to, and including, 5.5.1.5 due to…
AplazadaMedia (4.7)0.20%—Calculated Fields FormAI1/10/20263/10/2026
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (attacker-chosen name matching the form's url.<name> predefined value)' parameter in all versions up to, and including, 5.5.1.3 due…
AplazadaMedia (6.1)0.21%—Calculatedfields Calculated Fields FormAI1/10/20261/10/2026
The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (any URL parameter consumed by the form's calculated equation)' parameter in all versions up to, and including, 5.5.1.3 due to…
Pendiente de análisisMedia (6.8)0.15%—Nvidia ConnectxAINvidia BluefieldAI29/9/202629/9/2026
NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (7.2)0.24%—Repeater Fields FOR Elementor FormsAI25/9/202625/9/2026
The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaAlta (7.1)0.18%—Calculated Fields FormAI23/9/202623/9/2026
Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.
AplazadaAlta (8.1)0.21%—WC Fields FactoryAI23/9/202623/9/2026
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to…
AplazadaBaja (3.3)0.13%—WC Fields FactoryAI23/9/202623/9/2026
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting…
AplazadaMedia (4.3)0.21%—Wpgogo Custom Field TemplateAI22/9/202622/9/2026
The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to delete…
AplazadaMedia (6.5)0.58%—Wpgogo Custom Field TemplateAI19/9/202621/9/2026
The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and including, 2.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaBaja (3.7)0.27%—Secure Custom FieldsAI19/9/202621/9/2026
The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to.
AplazadaMedia (4.3)0.25%—Checkout Field ManagerAI17/9/202618/9/2026
The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.
AplazadaMedia (4.3)0.25%—Checkout Field ManagerAI17/9/202618/9/2026
The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.
AplazadaAlta (7.7)0.34%—Oracle Field ServiceAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. While the…
AplazadaMedia (6.5)0.34%—Oracle Field ServiceAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of…
AplazadaAlta (7.1)0.29%—Oracle Field ServiceAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks…
Pendiente de análisisAlta (7.6)0.31%—Oracle Field ServiceAIOracle E-business SuiteAI15/9/202616/9/2026
Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of…
AplazadaMedia (5.4)0.21%—Oracle Field ServiceAI15/9/202621/9/2026
Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks…
Pendiente de análisisMedia (4.3)0.40%—Plone App.textfieldAI15/9/202630/9/2026
plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on the release line, RichTextValue.output returns an unsanitized stored RichText value when mimeType equals outputMimeType, including values that claim…
AplazadaCrítica (9.8)1.1%—Mipl Grouped Checkout Fields FOR WoocommerceAI11/9/202611/9/2026
The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated…
AplazadaAlta (8.6)0.53%—Studiowombat Advanced Product Fields Extended FOR WoocommerceAI10/9/202611/9/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6.
AplazadaMedia (4.3)0.43%—Checkout Custom Fields Builder FOR WoocommerceAI9/9/20269/9/2026
The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.2)0.51%—Repeater Fields FOR Gravity FormsAI9/9/20269/9/2026
The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AnalizadaMedia (5.3)0.33%—Data Field Project Data Field2/9/20269/9/2026
Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.