Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2587▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.69% | — | Glossary BY WppediaAI | 21/5/2025 | 17/6/2026 | The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.0 via deserialization of untrusted input from the 'posttypes' parameter. This makes it possible for authenticated attackers, with Administrator-level access… | |
| Analizada | Media (4.8) | 0.31% | — | Cminds CM Tooltip Glossary | 15/5/2025 | 17/6/2026 | The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (5.4) | 0.35% | — | Tcbarrett GlossaryAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in TCBarrett Glossary allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Glossary: from n/a through 3.1.2. | |
| Aplazada | Alta (7.1) | 0.29% | — | Dennis Encyclopedia Glossary WikiAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dennis Encyclopedia / Glossary / Wiki encyclopedia-lexicon-glossary-wiki-dictionary allows Reflected XSS.This issue affects Encyclopedia / Glossary / Wiki: from n/a through <= 1.7.60. | |
| Aplazada | Media (6.5) | 0.29% | — | Cminds CM Tooltip GlossaryAI | 11/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Tooltip Glossary enhanced-tooltipglossary allows Stored XSS.This issue affects CM Tooltip Glossary: from n/a through <= 4.3.9. | |
| Aplazada | Media (6.5) | 0.26% | — | Cminds CM Tooltip GlossaryAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Tooltip Glossary allows Stored XSS.This issue affects CM Tooltip Glossary: from n/a through 4.3.7. | |
| Aplazada | Media (5.3) | 0.45% | — | GlossaryAI | 16/7/2024 | 17/6/2026 | The Glossary plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.26. This is due the plugin utilizing wpdesk and not preventing direct access to the test files along with display_errors being enabled. This makes it possible for unauthenticated attackers to retrieve the… | |
| Aplazada | Media (4.3) | 0.25% | — | Cminds CM Tooltip GlossaryAI | 2/5/2024 | 17/6/2026 | The CM Tooltip Glossary – Powerful Glossary Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.11. This is due to missing or incorrect nonce validation when saving settings. This makes it possible for unauthenticated attackers to change the plugin's… | |
| Modificada | Media (5.4) | 0.38% | — | Codeat Glossary | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Codeat Glossary plugin <= 2.1.27 versions. | |
| Modificada | Media (5.4) | 0.38% | — | WP Glossary Project WP Glossary | 21/3/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting vulnerability in TCBarrett WP Glossary plugin <= 3.1.2 versions. | |
| Modificada | Media (5.4) | 0.62% | — | Cminds Tooltip Glossary | 4/10/2021 | 17/6/2026 | The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (7.1) | 2.0% | — | IBM Infosphere Information ServerIBM Infosphere Governance CatalogIBM Infosphere Information Server ON CloudIBM Infosphere Information Server Business Glossary+1 | 17/6/2019 | 17/6/2026 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905. | |
| Modificada | Media (6.1) | 4.4% | — | Cminds Tooltip Glossary | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8 | |
| Modificada | Media (5.4) | 0.87% | — | IBM Information Server FrameworkIBM Infosphere Information Governance CatalogIBM Infosphere Information Server Business Glossary | 8/8/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server Framework and InfoSphere Information Server Business Glossary 9.1 before 9.1.2.0, Information Server Framework and… | |
| Modificada | Baja (1.9) | 0.48% | — | IBM Infosphere Business GlossaryIBM Infosphere Information Server | 31/1/2013 | 16/6/2026 | Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 and InfoSphere Business Glossary 8.1.1 and 8.1.2 does not have an off autocomplete attribute for the password field on the login page, which makes it easier for remote attackers to obtain access by leveraging an… | |
| Modificada | Media (4.3) | 0.93% | — | IBM Infosphere Business GlossaryIBM Infosphere Information Server | 31/1/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in InfoSphere Business Glossary 8.1.1 and 8.1.2, InfoSphere DataStage Operation Console, InfoSphere Administration, and Reporting and Repository Management Web Console in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to inject arbitrary… | |
| Modificada | Media (4.3) | 1.6% | — | Nancy Wichmann GlossaryDrupal | 21/5/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Glossary module 6.x-1.x before 6.x-1.8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "taxonomy information." | |
| Modificada | Alta (7.5) | 1.0% | — | TIM Lochmueller & Thomas Buss A21glossary Advanced Output | 22/7/2010 | 16/6/2026 | SQL injection vulnerability in the A21glossary Advanced Output (a21glossary_advanced_output) extension before 0.1.12 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | Andreas Schwarzkopf Accessibility Glossary | 23/4/2010 | 16/6/2026 | SQL injection vulnerability in the Accessibility Glossary (a21glossary) extension 0.4.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.97% | — | Joomla GlossaryMambo Glossary | 31/1/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action. | |
| Modificada | Alta (7.5) | 1.3% | — | Funkyasp Glossary | 17/11/2006 | 16/6/2026 | SQL injection vulnerability in demo/glossary/glossary.asp in FunkyASP Glossary 1.0 allows remote attackers to execute arbitrary SQL commands via the alpha parameter. |