Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.9)0.79%—Daggerheart Query WranglerAI20/8/202620/8/2026
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
AplazadaAlta (8.8)1.0%—Daggerheart Query WranglerAI16/8/202620/8/2026
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options…
AplazadaMedia (6.4)0.35%—Techearty Easy AccordionAI8/8/202612/8/2026
The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, and including, 3.1.8. This is due to insufficient input sanitization and output escaping in the accordion_header_renderer() function, which emits the attacker-supplied tag…
AplazadaMedia (4.3)0.27%—Daggerheart Query WranglerAI23/7/202623/7/2026
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
AplazadaMedia (6.4)0.33%—Techearty Easy AccordionAI16/7/202616/7/2026
The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AnalizadaMedia (6.1)0.32%—Heartcombo Devise22/5/202623/7/2026
Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.referrer — the HTTP Referer header, which is attacker-controllable — without validation for any non-GET request that results…
AnalizadaMedia (6)0.34%—Heartcombo Devise18/3/202617/6/2026
Devise is an authentication solution for Rails based on Warden. Prior to version 5.0.3, a race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the `reconfirmable` option (the default when using Confirmable with email…
AplazadaMedia (5.3)0.32%—Webgeniuslab BigheartsAI13/3/202617/6/2026
Missing Authorization vulnerability in WebGeniusLab BigHearts bighearts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BigHearts: from n/a through <= 3.1.14.
AnalizadaMedia (4.4)0.14%—Anytype CLIAnytype DesktopAnytype Heart11/3/202617/6/2026
Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API can be bypassed, allowing an attacker to gain access without the 4-digit code. This vulnerability is fixed in anytype-heart 0.48.4, anytype-cli 0.1.11, and Anytype Desktop 0.54.5.
ModificadaAlta (8.1)0.50%—Axiomthemes Heartstar18/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes HeartStar heartstar allows PHP Local File Inclusion.This issue affects HeartStar: from n/a through <= 1.0.14.
ModificadaAlta (8.1)0.53%—Axiomthemes Heart18/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Heart heart allows PHP Local File Inclusion.This issue affects Heart: from n/a through <= 1.8.
ModificadaBaja (3.5)0.34%—Techearty Carousel, Slider, Gallery BY WP Carousel15/5/202517/6/2026
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AplazadaMedia (5.4)0.20%—Daggerheart Query WranglerAI1/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Jonathan Daggerhart Query Wrangler query-wrangler allows Cross Site Request Forgery.This issue affects Query Wrangler: from n/a through <= 1.5.54.
AplazadaAlta (7.1)0.37%—Securesubmit Heartland Management TerminalAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SecureSubmit Heartland Management Terminal allows Reflected XSS. This issue affects Heartland Management Terminal: from n/a through 1.3.0.
AnalizadaBaja (3.5)0.39%—Techearty Carousel, Slider, Gallery BY WP Carousel21/2/202517/6/2026
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaAlta (7.1)0.26%—Heart5 StatpresscnAI23/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in heart5 StatPressCN statpresscn allows Reflected XSS.This issue affects StatPressCN: from n/a through <= 1.9.1.
AplazadaAlta (7.1)0.39%—Siteheart HypercommentsAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in siteheart HyperComments comments-with-hypercommentscom allows Reflected XSS.This issue affects HyperComments: from n/a through <= 0.9.6.
AplazadaCrítica (9.8)0.52%—Phoenixheart Referrer DetectorAI16/11/202417/6/2026
Deserialization of Untrusted Data vulnerability in Phoenixheart Referrer Detector referrer-detector allows Object Injection.This issue affects Referrer Detector: from n/a through <= 4.2.1.0.
AplazadaCrítica (9.8)0.52%—Phoenixheart Ajax Random PostsAI16/11/202417/6/2026
Deserialization of Untrusted Data vulnerability in Phoenixheart AJAX Random Posts ajax-random-posts allows Object Injection.This issue affects AJAX Random Posts: from n/a through <= 0.3.3.
AnalizadaAlta (7.1)0.80%—Heartbeat17/7/202417/6/2026
Cross Site Scripting vulnerability in Heartbeat Chat v.15.2.1 allows a remote attacker to execute arbitrary code via the setname function.
AplazadaMedia (6.5)0.34%—HeartthisAI31/3/202417/6/2026
Contributor Cross Site Scripting (XSS) in HeartThis <= 0.1.0 versions.
ModificadaMedia (5.4)0.40%—Techearty Easy Accordion13/3/202417/6/2026
The Easy Accordion – Best Accordion FAQ Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordion_content_source' attribute in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
ModificadaAlta (7.5)0.62%—Heartcombo Devise12/12/202317/6/2026
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.
ModificadaMedia (6.1)0.38%—Daggerheart Query Wrangler16/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jonathan Daggerhart Query Wrangler plugin <= 1.5.51 versions.
ModificadaAlta (8.8)0.72%—Forget Heart Message BOX Project Forget Heart Message BOX1/2/202317/6/2026
Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php.