Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Houzez Property FeedAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. | |
| Aplazada | Alta (8.2) | 0.32% | — | Favethemes Houzez Login RegisterAI | 13/7/2026 | 13/7/2026 | Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3. | |
| Aplazada | Media (4.9) | 0.48% | — | Wp-property-hive Houzez Property FeedAI | 2/7/2026 | 2/7/2026 | The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.5.46 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the prepare_items() method of the… | |
| Aplazada | Media (6.5) | 0.15% | — | Favethemes Houzez Theme FunctionalityAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-functionality allows Stored XSS.This issue affects Houzez Theme - Functionality: from n/a through <= 4.2.6. | |
| Aplazada | Media (6.3) | 0.26% | — | Favethemes HouzezAI | 26/11/2025 | 17/6/2026 | The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted input in saved-search-item.php. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is… | |
| Aplazada | Media (6.1) | 0.21% | — | Favethemes HouzezAI | 26/11/2025 | 17/6/2026 | The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping in the houzez_property_img_upload() and houzez_property_attachment_upload() functions. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.23% | — | Favethemes Houzez Theme FunctionalityAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-functionality.This issue affects Houzez Theme - Functionality: from n/a through < 4.2.0. | |
| Aplazada | Alta (8.1) | 0.40% | — | Favethemes HouzezAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez houzez.This issue affects Houzez: from n/a through < 4.2.0. | |
| Aplazada | Media (6.5) | 0.18% | — | Favethemes Houzez ThemeAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-functionality.This issue affects Houzez Theme - Functionality: from n/a through < 4.2.0. | |
| Aplazada | Alta (7.5) | 0.42% | — | Favethemes Houzez ThemeAIPHPAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-functionality.This issue affects Houzez Theme - Functionality: from n/a through <= 4.1.8. | |
| Aplazada | Media (6.5) | 0.43% | — | Favethemes HouzezAI | 22/10/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in favethemes Houzez houzez allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Houzez: from n/a through <= 4.2.5. | |
| Aplazada | Alta (8.8) | 0.44% | — | Favethemes HouzezAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS. This issue affects Houzez: from n/a through 4.1.1. | |
| Aplazada | Media (4.3) | 0.27% | — | Favethemes HouzezAI | 28/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Favethemes Houzez allows PHP Local File Inclusion.This issue affects Houzez: from n/a before 4.1.4. | |
| Aplazada | Alta (8.1) | 0.66% | — | Favethemes HouzezAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez houzez allows PHP Local File Inclusion.This issue affects Houzez: from n/a through <= 4.0.4. | |
| Aplazada | Alta (8.5) | 0.34% | — | Favethemes HouzezAI | 20/8/2025 | 17/6/2026 | Missing Authorization vulnerability in favethemes Houzez allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Houzez: from n/a through 4.1.1. | |
| Aplazada | Media (4.3) | 0.26% | — | Favethemes HouzezAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in favethemes Houzez houzez allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Houzez: from n/a through <= 4.0.4. | |
| Aplazada | Alta (7.5) | 0.60% | — | Wp-property-hive Houzez Property FeedAI | 1/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Property Hive Houzez Property Feed houzez-property-feed allows Path Traversal.This issue affects Houzez Property Feed: from n/a through <= 2.5.4. | |
| Analizada | Media (5.4) | 0.16% | — | Wp-property-hive Houzez Property Feed | 12/2/2025 | 17/6/2026 | The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due to missing or incorrect nonce validation on the "deleteexport" action. This makes it possible for unauthenticated attackers to delete property feed exports via a forged… | |
| Aplazada | Media (5.3) | 0.27% | — | Favethemes HouzezAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in favethemes Houzez houzez.This issue affects Houzez: from n/a through <= 3.4.0. | |
| Aplazada | Media (4.3) | 0.24% | — | Favethemes HouzezAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in favethemes Houzez houzez.This issue affects Houzez: from n/a through <= 3.4.0. | |
| Aplazada | Alta (8.8) | 0.44% | — | Favethemes HouzezAI | 17/9/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4. | |
| Aplazada | Alta (8.8) | 0.44% | — | Favethemes Houzez Login RegisterAI | 17/9/2024 | 17/6/2026 | Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5. | |
| Aplazada | Alta (7.1) | 0.27% | — | Favethemes HouzezAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS.This issue affects Houzez: from n/a through 3.2.4. | |
| Aplazada | Alta (8.8) | 0.45% | — | Favethemes HouzezAI | 10/7/2024 | 17/6/2026 | The Houzez CRM plugin for WordPress is vulnerable to time-based SQL Injection via the notes ‘belong_to’ parameter in all versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.45% | — | Houzez Theme FunctionalityAI | 9/7/2024 | 17/6/2026 | The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter in all versions up to, and including, 3.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… |