Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.24% | — | Http Requests ManagerAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager <= 1.3.11 versions. | |
| Aplazada | Media (5.4) | 0.33% | — | Pear Http Request2AI | 17/4/2025 | 17/6/2026 | In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS. | |
| Modificada | Media (6.1) | 0.70% | — | Facetwp LOG Http Requests | 28/10/2022 | 17/6/2026 | The Log HTTP Requests plugin for WordPress is vulnerable to Stored Cross-Site Scripting via logged HTTP requests in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers who can trick a site's administrator into performing… | |
| Modificada | Media (6.5) | 0.84% | — | Jenkins Http Request | 27/7/2022 | 17/6/2026 | Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Alta (7.4) | 0.91% | — | Em-http-request Project Em-http-requestFedoraproject Fedora | 25/5/2020 | 17/6/2026 | EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified. | |
| Modificada | Media (5.9) | 0.57% | — | Http Request Project Http Request | 23/7/2019 | 17/6/2026 | OSS Http Request (Apache Cordova Plugin) 6 is affected by: Missing SSL certificate validation. The impact is: certificate spoofing. The component is: use this library when https communication. The attack vector is: certificate spoofing. |