Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—GetgenieAI27/7/202628/7/2026
Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.
AplazadaMedia (6.5)0.37%—GetgenieAI26/6/202626/6/2026
Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.
AplazadaMedia (6.5)0.35%—GetgenieAI16/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.
AplazadaMedia (5.4)0.38%—GetgenieAI13/3/202617/6/2026
The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.2. This is due to missing validation on the `id` parameter in the `create()` method of the `GetGenieChat` REST API endpoint. The method accepts a user-controlled post ID and, when a post with…
AplazadaMedia (6.4)0.23%—GetgenieAI13/3/202617/6/2026
The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.2 due to missing validation on a user controlled key in the `action` function. This makes it possible for authenticated attackers, with Author-level access and above, to update post metadata…
AplazadaMedia (4.9)0.27%—Roxnor GetgenieAI22/1/202617/6/2026
Missing Authorization vulnerability in Roxnor GetGenie getgenie allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GetGenie: from n/a through <= 4.3.0.
AplazadaMedia (4.3)0.24%—GetgenieAI16/1/202617/6/2026
The GetGenie plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.0. This is due to the plugin not properly verifying that a user is authorized to delete a specific post. This makes it possible for authenticated attackers, with Author-level access and above, to delete…