Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2587▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.69%—Glossary BY WppediaAI21/5/202517/6/2026
The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.0 via deserialization of untrusted input from the 'posttypes' parameter. This makes it possible for authenticated attackers, with Administrator-level access…
AnalizadaMedia (4.8)0.31%—Cminds CM Tooltip Glossary15/5/202517/6/2026
The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AplazadaMedia (5.4)0.35%—Tcbarrett GlossaryAI2/1/202517/6/2026
Missing Authorization vulnerability in TCBarrett Glossary allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Glossary: from n/a through 3.1.2.
AplazadaAlta (7.1)0.29%—Dennis Encyclopedia Glossary WikiAI17/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dennis Encyclopedia / Glossary / Wiki encyclopedia-lexicon-glossary-wiki-dictionary allows Reflected XSS.This issue affects Encyclopedia / Glossary / Wiki: from n/a through <= 1.7.60.
AplazadaMedia (6.5)0.29%—Cminds CM Tooltip GlossaryAI11/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Tooltip Glossary enhanced-tooltipglossary allows Stored XSS.This issue affects CM Tooltip Glossary: from n/a through <= 4.3.9.
AplazadaMedia (6.5)0.26%—Cminds CM Tooltip GlossaryAI12/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Tooltip Glossary allows Stored XSS.This issue affects CM Tooltip Glossary: from n/a through 4.3.7.
AplazadaMedia (5.3)0.45%—GlossaryAI16/7/202417/6/2026
The Glossary plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.26. This is due the plugin utilizing wpdesk and not preventing direct access to the test files along with display_errors being enabled. This makes it possible for unauthenticated attackers to retrieve the…
AplazadaMedia (4.3)0.25%—Cminds CM Tooltip GlossaryAI2/5/202417/6/2026
The CM Tooltip Glossary – Powerful Glossary Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.11. This is due to missing or incorrect nonce validation when saving settings. This makes it possible for unauthenticated attackers to change the plugin's…
ModificadaMedia (5.4)0.38%—Codeat Glossary6/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Codeat Glossary plugin <= 2.1.27 versions.
ModificadaMedia (5.4)0.38%—WP Glossary Project WP Glossary21/3/202317/6/2026
Auth. (contributor+) Cross-Site Scripting vulnerability in TCBarrett WP Glossary plugin <= 3.1.2 versions.
ModificadaMedia (5.4)0.62%—Cminds Tooltip Glossary4/10/202117/6/2026
The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks
ModificadaAlta (7.1)2.0%—IBM Infosphere Information ServerIBM Infosphere Governance CatalogIBM Infosphere Information Server ON CloudIBM Infosphere Information Server Business Glossary+117/6/201917/6/2026
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.
ModificadaMedia (6.1)4.4%—Cminds Tooltip Glossary10/10/201617/6/2026
Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8
ModificadaMedia (5.4)0.87%—IBM Information Server FrameworkIBM Infosphere Information Governance CatalogIBM Infosphere Information Server Business Glossary8/8/201617/6/2026
Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server Framework and InfoSphere Information Server Business Glossary 9.1 before 9.1.2.0, Information Server Framework and…
ModificadaBaja (1.9)0.48%—IBM Infosphere Business GlossaryIBM Infosphere Information Server31/1/201316/6/2026
Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 and InfoSphere Business Glossary 8.1.1 and 8.1.2 does not have an off autocomplete attribute for the password field on the login page, which makes it easier for remote attackers to obtain access by leveraging an…
ModificadaMedia (4.3)0.93%—IBM Infosphere Business GlossaryIBM Infosphere Information Server31/1/201316/6/2026
Cross-site scripting (XSS) vulnerability in InfoSphere Business Glossary 8.1.1 and 8.1.2, InfoSphere DataStage Operation Console, InfoSphere Administration, and Reporting and Repository Management Web Console in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to inject arbitrary…
ModificadaMedia (4.3)1.6%—Nancy Wichmann GlossaryDrupal21/5/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Glossary module 6.x-1.x before 6.x-1.8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "taxonomy information."
ModificadaAlta (7.5)1.0%—TIM Lochmueller & Thomas Buss A21glossary Advanced Output22/7/201016/6/2026
SQL injection vulnerability in the A21glossary Advanced Output (a21glossary_advanced_output) extension before 0.1.12 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)1.0%—Andreas Schwarzkopf Accessibility Glossary23/4/201016/6/2026
SQL injection vulnerability in the Accessibility Glossary (a21glossary) extension 0.4.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)0.97%—Joomla GlossaryMambo Glossary31/1/200816/6/2026
SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action.
ModificadaAlta (7.5)1.3%—Funkyasp Glossary17/11/200616/6/2026
SQL injection vulnerability in demo/glossary/glossary.asp in FunkyASP Glossary 1.0 allows remote attackers to execute arbitrary SQL commands via the alpha parameter.