Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 48 respecto a la semana anterior
Críticas / altas1479▲ 371 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Meril Blog Floating ButtonAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions. | |
| Aplazada | Media (6.1) | 0.27% | — | Meril Blog Floating ButtonAI | 3/8/2026 | 26/8/2026 | The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. This allows an unauthenticated attacker to store a malicious script that… | |
| Aplazada | Media (5.3) | 0.42% | — | Quantumcloud Floating Buttons FOR WoocommerceAI | 19/11/2024 | 17/6/2026 | Missing Authorization vulnerability in QuantumCloud Floating Buttons for WooCommerce shop-assistant-for-woocommerce-jarvis allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Floating Buttons for WooCommerce: from n/a through <= 2.8.8. | |
| Aplazada | Alta (7.5) | 0.56% | — | Istmoplugins Instant-chat-floating-button-for-wordpress-websitesAI | 5/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Instant Chat Floating Button for WordPress Websites instant-chat-wp allows PHP Local File Inclusion.This issue affects Instant Chat Floating Button for WordPress Websites: from n/a through <= 1.0.5. | |
| Modificada | Alta (8.8) | 0.22% | — | Wow-company Floating Button | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button.This issue affects Floating Button: from n/a through 6.0. | |
| Modificada | Alta (8.8) | 0.30% | — | Meril Blog Floating Button | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Meril Inc. Blog Floating Button plugin <= 1.4.12 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Wow-company Bubble MenuWow-company Button GeneratorWow-company Calculator-builderWow-company Counter BOX+8 | 12/6/2023 | 17/6/2026 | The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before… |