Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.25% | — | WBW Product FilterAI | 23/9/2026 | 23/9/2026 | Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions. | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Request-filtering-agentAI | 22/9/2026 | 25/9/2026 | request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rejecting a literal private-IP host such as 169.254.169.254 or 127.0.0.1. Because… | |
| Rechazada | Sin puntuar | — | — | CupsAICups-filtersAI | 22/9/2026 | 22/9/2026 | Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed. | |
| Aplazada | Alta (8.1) | 0.65% | — | Wpusb Husky Products FilterAI | 22/9/2026 | 22/9/2026 | The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.4 via the 'shortcode' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server,… | |
| Aplazada | Alta (8.1) | 0.54% | — | Filter GalleryAI | 18/9/2026 | 18/9/2026 | The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Media (4.3) | 0.39% | — | Filter GalleryAI | 18/9/2026 | 18/9/2026 | The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Alta (7.1) | 0.34% | — | Filter GalleryAI | 18/9/2026 | 18/9/2026 | The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the content of arbitrary posts and delete the Filter Gallery WordPress plugin before 1.1.5's stored… | |
| Pendiente de análisis | Alta (8.8) | 0.16% | — | Avast Sandbox Minifilter DriverAI | 16/9/2026 | 17/9/2026 | Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox virtualizes a file it copies the original security descriptor, but the driver opened… | |
| Aplazada | Media (6.1) | 0.37% | — | Themify Woocommerce Product FilterAI | 11/9/2026 | 11/9/2026 | The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.1) | 0.23% | — | Husky Products Filter ProfessionalAI | 11/9/2026 | 11/9/2026 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3. This is due to insufficient input sanitization and output escaping in the wp_load_js() function, which… | |
| Aplazada | Media (6.1) | 0.46% | — | WBW Product Filter FOR WoocommerceAI | 9/9/2026 | 9/9/2026 | The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpf_fid' parameter in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Crítica (9.8) | 0.59% | — | Divi Ajax FilterAI | 4/9/2026 | 7/9/2026 | The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Beautiful Taxonomy FiltersAI | 27/8/2026 | 28/8/2026 | Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions. | |
| Pendiente de análisis | Media (5.7) | 0.19% | — | Drupal Lunr Exposed FiltersAI | 25/8/2026 | 28/8/2026 | Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Woobewoo Product Filter PROAI | 24/8/2026 | 26/8/2026 | Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions. | |
| Aplazada | Media (6.8) | 0.43% | — | YMC FilterAI | 8/8/2026 | 26/8/2026 | The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed. | |
| Aplazada | Media (5.4) | 0.23% | — | YMC FilterAI | 8/8/2026 | 26/8/2026 | The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is saved, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any… | |
| Aplazada | Alta (7.1) | 0.25% | — | Berocket Advanced Ajax Product FiltersAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Openprinting LibcupsfiltersAI | 23/7/2026 | 19/8/2026 | A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer… | |
| Pendiente de análisis | Alta (7.5) | 0.70% | — | LibcupsfiltersAICups-filtersAI | 20/7/2026 | 24/8/2026 | A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted… | |
| Aplazada | Alta (7.1) | 0.25% | — | Kofimokome Message Filter FOR Contact Form 7AI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.3.8. | |
| Aplazada | Alta (7.2) | 0.32% | — | Connekthq Ajax Load More FiltersAI | 30/6/2026 | 30/6/2026 | The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Crítica (9.3) | 0.40% | — | JetsmartfiltersAI | 26/6/2026 | 26/6/2026 | Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions. | |
| Aplazada | Alta (7.5) | 1.5% | — | YMC FilterAI | 26/6/2026 | 26/6/2026 | The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public posts. | |
| Aplazada | Crítica (9.3) | 1.3% | — | YMC FilterAI | 25/6/2026 | 26/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a through 3.11.5. |