Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.45% | — | Lexiforest Curl Cffi | 6/4/2026 | 17/6/2026 | curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automatically via the underlying libcurl. Because of this, an attacker-controlled URL can redirect requests to internal services such as cloud metadata endpoints. In addition,… | |
| Aplazada | Media (6.4) | 0.23% | — | Riverforest-wp Simple Blog CardAI | 13/3/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Katsushi Kawamori Simple Blog Card simple-blog-card allows Server Side Request Forgery.This issue affects Simple Blog Card: from n/a through <= 2.37. | |
| Analizada | Baja (2) | 0.36% | — | Rymcu Forest | 22/2/2026 | 17/6/2026 | A vulnerability was detected in rymcu forest up to 0.0.5. This affects the function updateUserInfo of the file - src/main/java/com/rymcu/forest/web/api/user/UserInfoController.java of the component User Profile Handler. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit… | |
| Analizada | Baja (2) | 0.36% | — | Rymcu Forest | 22/2/2026 | 17/6/2026 | A security vulnerability has been detected in rymcu forest up to 0.0.5. Affected by this issue is the function XssUtils.replaceHtmlCode of the file src/main/java/com/rymcu/forest/util/XssUtils.java of the component Article Content/Comments/Portfolio. The manipulation leads to cross site scripting. Remote exploitation… | |
| Aplazada | Crítica (9.8) | 0.60% | — | Scriptsbundle AdforestAI | 12/2/2026 | 17/6/2026 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (7.1) | 0.27% | — | Scriptsbundle Adforest ElementorAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scriptsbundle AdForest Elementor adforest-elementor allows Reflected XSS.This issue affects AdForest Elementor: from n/a through <= 3.0.11. | |
| Aplazada | Alta (8.1) | 0.59% | — | Scriptsbundle AdforestAIPHPAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in scriptsbundle AdForest adforest allows PHP Local File Inclusion.This issue affects AdForest: from n/a through <= 6.0.11. | |
| Aplazada | Media (5.4) | 0.24% | — | Kitforest Better Elementor AddonsAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in wpdive Better Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Elementor Addons: from n/a through 1.3.7. | |
| Aplazada | Media (6.4) | 0.23% | — | Kitforest Better Elementor AddonsAI | 12/12/2025 | 17/6/2026 | The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider widget in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.25% | — | Scriptsbundle AdforestAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in scriptsbundle AdForest adforest allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AdForest: from n/a through <= 6.0.11. | |
| Modificada | Media (5.3) | 0.34% | — | Rymcu Forest | 10/11/2025 | 17/6/2026 | A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the file src/main/java/com/rymcu/forest/web/api/bank/BankController.java. The manipulation leads to missing authorization. The attack may be initiated remotely. This product… | |
| Modificada | Media (6.9) | 0.44% | — | Rymcu Forest | 10/11/2025 | 30/9/2026 | A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserDicController.java. The manipulation results in missing authorization. The attack may be launched… | |
| Analizada | Media (6.5) | 0.25% | — | Rymcu Forest | 7/11/2025 | 17/6/2026 | An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/security/AuthorshipAspect.java, allowing authorized attackers to delete arbitrary users posts. | |
| Aplazada | Alta (7.5) | 0.34% | — | Scriptsbundle AdforestAI | 30/10/2025 | 17/6/2026 | AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed by Muhammad Jawad Arshad, contains an improper access control vulnerability in its authentication mechanism. The app uses a Base64-encoded email address as the authorization credential, which can be manipulated by… | |
| Aplazada | Crítica (9.8) | 0.49% | — | Scriptsbundle AdforestAI | 6/9/2025 | 1/10/2026 | The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as other users, including administrators,… | |
| Analizada | Crítica (9.8) | 0.34% | — | Forestryks Process-sync | 24/5/2025 | 17/6/2026 | In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked. | |
| Analizada | Media (5.1) | 0.34% | — | Forestblog Project Forestblog | 31/3/2025 | 17/6/2026 | A vulnerability was found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this issue is some unknown functionality of the component Friend Link Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.1) | 0.34% | — | Forestblog Project Forestblog | 31/3/2025 | 17/6/2026 | A vulnerability has been found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /search. The manipulation of the argument keywords leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (4.8) | 0.28% | — | Forestblog Project Forestblog | 3/2/2025 | 17/6/2026 | Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function. | |
| Analizada | Crítica (9.8) | 0.75% | — | Scriptsbundle Adforest | 22/1/2025 | 17/6/2026 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they… | |
| Analizada | Media (5.4) | 0.27% | — | Scriptsbundle Adforest | 8/1/2025 | 17/6/2026 | The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions like 'sb_remove_ad' in all versions up to, and including, 5.1.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete posts,… | |
| Analizada | Crítica (9.8) | 0.70% | — | Scriptsbundle Adforest | 8/1/2025 | 17/6/2026 | The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password through the adforest_reset_password() function. This makes it possible for… | |
| Analizada | Crítica (9.8) | 1.2% | — | Scriptsbundle Adforest | 21/12/2024 | 17/6/2026 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the sb_login_user_with_otp_fun() function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.5) | 0.35% | — | Auburnforest DatamentorAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AuburnForest DataMentor datamentor allows DOM-Based XSS.This issue affects DataMentor: from n/a through <= 1.7. | |
| Modificada | Media (5.4) | 0.24% | — | Auburnforest Blogmentor | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AuburnForest Blogmentor – Blog Layouts for Elementor allows Stored XSS.This issue affects Blogmentor – Blog Layouts for Elementor: from n/a through 1.5. |