Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.32% | — | Google DOC EmbedderAI | 30/4/2024 | 17/6/2026 | The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in versions up to, and including, 2.6.4. This can allow authenticated attackers with contributor-level permissions or above to make web requests to arbitrary locations originating from the web… | |
| Modificada | Alta (8.8) | 0.71% | — | Google DOC Embedder Project Google DOC Embedder | 14/8/2019 | 17/6/2026 | The google-document-embedder plugin before 2.6.2 for WordPress has CSRF. | |
| Modificada | Media (6.1) | 0.95% | — | Google DOC Embedder Project Google DOC Embedder | 14/8/2019 | 17/6/2026 | The google-document-embedder plugin before 2.6.2 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.95% | — | Google DOC Embedder Project Google DOC Embedder | 14/8/2019 | 17/6/2026 | The google-document-embedder plugin before 2.6.1 for WordPress has XSS. | |
| Modificada | Media (4.3) | 2.1% | — | Google DOC Embedder | 19/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the profile parameter in an edit action in the gde-settings page to wp-admin/options-general.php. | |
| Modificada | Alta (7.5) | 5.0% | — | Google DOC Embedder Project Google DOC Embedder | 2/12/2014 | 17/6/2026 | SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter. | |
| Modificada | Media (5) | 50% | — | Davistribe Google DOC Embedder | 29/5/2014 | 16/6/2026 | Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to libs/pdf.php. |