Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | GetgenieAI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | GetgenieAI | 26/6/2026 | 26/6/2026 | Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions. | |
| Aplazada | Media (6.5) | 0.35% | — | GetgenieAI | 16/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions. | |
| Aplazada | Media (5.4) | 0.38% | — | GetgenieAI | 13/3/2026 | 17/6/2026 | The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.2. This is due to missing validation on the `id` parameter in the `create()` method of the `GetGenieChat` REST API endpoint. The method accepts a user-controlled post ID and, when a post with… | |
| Aplazada | Media (6.4) | 0.23% | — | GetgenieAI | 13/3/2026 | 17/6/2026 | The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.2 due to missing validation on a user controlled key in the `action` function. This makes it possible for authenticated attackers, with Author-level access and above, to update post metadata… | |
| Aplazada | Media (4.9) | 0.27% | — | Roxnor GetgenieAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Roxnor GetGenie getgenie allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GetGenie: from n/a through <= 4.3.0. | |
| Aplazada | Media (4.3) | 0.24% | — | GetgenieAI | 16/1/2026 | 17/6/2026 | The GetGenie plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.0. This is due to the plugin not properly verifying that a user is authorized to delete a specific post. This makes it possible for authenticated attackers, with Author-level access and above, to delete… |