Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.79% | — | Daggerheart Query WranglerAI | 20/8/2026 | 20/8/2026 | Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. | |
| Aplazada | Alta (8.8) | 1.0% | — | Daggerheart Query WranglerAI | 16/8/2026 | 20/8/2026 | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options… | |
| Aplazada | Media (6.4) | 0.35% | — | Techearty Easy AccordionAI | 8/8/2026 | 12/8/2026 | The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, and including, 3.1.8. This is due to insufficient input sanitization and output escaping in the accordion_header_renderer() function, which emits the attacker-supplied tag… | |
| Aplazada | Media (4.3) | 0.27% | — | Daggerheart Query WranglerAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions. | |
| Aplazada | Media (6.4) | 0.33% | — | Techearty Easy AccordionAI | 16/7/2026 | 16/7/2026 | The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Analizada | Media (6.1) | 0.32% | — | Heartcombo Devise | 22/5/2026 | 23/7/2026 | Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.referrer — the HTTP Referer header, which is attacker-controllable — without validation for any non-GET request that results… | |
| Analizada | Media (6) | 0.34% | — | Heartcombo Devise | 18/3/2026 | 17/6/2026 | Devise is an authentication solution for Rails based on Warden. Prior to version 5.0.3, a race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application using the `reconfirmable` option (the default when using Confirmable with email… | |
| Aplazada | Media (5.3) | 0.32% | — | Webgeniuslab BigheartsAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WebGeniusLab BigHearts bighearts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BigHearts: from n/a through <= 3.1.14. | |
| Analizada | Media (4.4) | 0.14% | — | Anytype CLIAnytype DesktopAnytype Heart | 11/3/2026 | 17/6/2026 | Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API can be bypassed, allowing an attacker to gain access without the 4-digit code. This vulnerability is fixed in anytype-heart 0.48.4, anytype-cli 0.1.11, and Anytype Desktop 0.54.5. | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Heartstar | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes HeartStar heartstar allows PHP Local File Inclusion.This issue affects HeartStar: from n/a through <= 1.0.14. | |
| Modificada | Alta (8.1) | 0.53% | — | Axiomthemes Heart | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Heart heart allows PHP Local File Inclusion.This issue affects Heart: from n/a through <= 1.8. | |
| Modificada | Baja (3.5) | 0.34% | — | Techearty Carousel, Slider, Gallery BY WP Carousel | 15/5/2025 | 17/6/2026 | The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (5.4) | 0.20% | — | Daggerheart Query WranglerAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jonathan Daggerhart Query Wrangler query-wrangler allows Cross Site Request Forgery.This issue affects Query Wrangler: from n/a through <= 1.5.54. | |
| Aplazada | Alta (7.1) | 0.37% | — | Securesubmit Heartland Management TerminalAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SecureSubmit Heartland Management Terminal allows Reflected XSS. This issue affects Heartland Management Terminal: from n/a through 1.3.0. | |
| Analizada | Baja (3.5) | 0.39% | — | Techearty Carousel, Slider, Gallery BY WP Carousel | 21/2/2025 | 17/6/2026 | The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (7.1) | 0.26% | — | Heart5 StatpresscnAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in heart5 StatPressCN statpresscn allows Reflected XSS.This issue affects StatPressCN: from n/a through <= 1.9.1. | |
| Aplazada | Alta (7.1) | 0.39% | — | Siteheart HypercommentsAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in siteheart HyperComments comments-with-hypercommentscom allows Reflected XSS.This issue affects HyperComments: from n/a through <= 0.9.6. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Phoenixheart Referrer DetectorAI | 16/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Phoenixheart Referrer Detector referrer-detector allows Object Injection.This issue affects Referrer Detector: from n/a through <= 4.2.1.0. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Phoenixheart Ajax Random PostsAI | 16/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Phoenixheart AJAX Random Posts ajax-random-posts allows Object Injection.This issue affects AJAX Random Posts: from n/a through <= 0.3.3. | |
| Analizada | Alta (7.1) | 0.80% | — | Heartbeat | 17/7/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Heartbeat Chat v.15.2.1 allows a remote attacker to execute arbitrary code via the setname function. | |
| Aplazada | Media (6.5) | 0.34% | — | HeartthisAI | 31/3/2024 | 17/6/2026 | Contributor Cross Site Scripting (XSS) in HeartThis <= 0.1.0 versions. | |
| Modificada | Media (5.4) | 0.40% | — | Techearty Easy Accordion | 13/3/2024 | 17/6/2026 | The Easy Accordion – Best Accordion FAQ Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordion_content_source' attribute in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Alta (7.5) | 0.62% | — | Heartcombo Devise | 12/12/2023 | 17/6/2026 | The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access. | |
| Modificada | Media (6.1) | 0.38% | — | Daggerheart Query Wrangler | 16/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jonathan Daggerhart Query Wrangler plugin <= 1.5.51 versions. | |
| Modificada | Alta (8.8) | 0.72% | — | Forget Heart Message BOX Project Forget Heart Message BOX | 1/2/2023 | 17/6/2026 | Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php. |