Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.15% | — | John James Jacoby WP Term OrderAI | 23/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in John James Jacoby WP Term Order wp-term-order allows Cross Site Request Forgery.This issue affects WP Term Order: from n/a through <= 2.1.0. | |
| Analizada | Media (5.5) | 0.46% | — | Jameschz Hush | 20/11/2025 | 17/6/2026 | A weakness has been identified in jameschz Hush Framework 2.0. The impacted element is an unknown function of the file Hush\hush-lib\hush\Util.php of the component HTTP Host Header Handler. This manipulation of the argument $_SERVER['HOST'] causes improper neutralization of http headers for scripting syntax. The… | |
| Aplazada | Media (4.3) | 0.14% | — | John James Jacoby WP Media CategoriesAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in John James Jacoby WP Media Categories wp-media-categories allows Cross Site Request Forgery.This issue affects WP Media Categories: from n/a through <= 2.1.0. | |
| Aplazada | Alta (7.1) | 0.22% | — | Dylan James Zephyr Project ManagerAI | 28/8/2025 | 25/9/2026 | Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zephyr Project Manager: from n/a through <= 3.3.201. | |
| Aplazada | Media (4.9) | 0.53% | — | James Laforge Infocob CRM FormsAI | 23/5/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in James Laforge Infocob CRM Forms infocob-crm-forms allows Path Traversal.This issue affects Infocob CRM Forms: from n/a through <= 2.4.0. | |
| Aplazada | Media (6.5) | 0.21% | — | Jamesdbruner WP VegasAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jamesdbruner WP Vegas vegas-fullscreen-background-slider allows Stored XSS.This issue affects WP Vegas: from n/a through <= 2.2. | |
| Aplazada | Media (5.4) | 0.35% | — | Dylan James Zephyr Project ManagerAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zephyr Project Manager: from n/a through <= 3.3.200. | |
| Analizada | Media (5.1) | 0.41% | — | Jameszbl Db-hospital-drug | 14/4/2025 | 17/6/2026 | A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0. It has been classified as problematic. This affects the function Save of the file ContentController.java. The manipulation of the argument content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.45% | — | Jameszbl Db-hospital-drug | 14/4/2025 | 17/6/2026 | A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ShiroConfig.java. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Alta (8.8) | 0.39% | — | John James Jacoby WP User ProfilesAI | 10/4/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in John James Jacoby WP User Profiles wp-users-profiles allows Privilege Escalation.This issue affects WP User Profiles: from n/a through <= 2.6.2. | |
| Analizada | Alta (7.5) | 0.80% | — | Apache James Server | 6/2/2025 | 17/6/2026 | Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service. Users are recommended to upgrade to version 3.7.6 and 3.8.2, which fix this issue. | |
| Analizada | Alta (7.5) | 0.89% | — | Apache James Server | 6/2/2025 | 17/6/2026 | Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version 3.7.6 and 3.8.2 restrict such illegitimate use of IMAP literals. | |
| Aplazada | Alta (7.1) | 0.13% | — | James Andrews Full CircleAI | 31/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in James Andrews Full Circle full-circle allows Stored XSS.This issue affects Full Circle: from n/a through <= 0.5.7.8. | |
| Aplazada | Alta (7.1) | 0.15% | — | Dylan James Zephyr Modern Admin ThemeAI | 9/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Admin Theme zephyr-modern-admin-theme allows Cross Site Request Forgery.This issue affects Zephyr Admin Theme: from n/a through <= 1.4.1. | |
| Aplazada | Alta (7.1) | 0.27% | — | Jamesdbruner WP Mmenu LiteAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jamesdbruner WP MMenu Lite wp-mmenu-lite allows Reflected XSS.This issue affects WP MMenu Lite: from n/a through <= 1.0.0. | |
| Aplazada | Crítica (9.9) | 1.2% | — | James-eggers PortfolleoAI | 23/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in james-eggers Portfolleo portfolleo allows Upload a Web Shell to a Web Server.This issue affects Portfolleo: from n/a through <= 1.2. | |
| Aplazada | Alta (8.6) | 0.59% | — | Jamespark Analyse UploadsAI | 16/10/2024 | 17/6/2026 | Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through <= 0.5. | |
| Aplazada | Alta (7.1) | 0.32% | — | Jamesward WP Mail CatcherAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JWardee WP Mail Catcher wp-mail-catcher allows Reflected XSS.This issue affects WP Mail Catcher: from n/a through <= 2.1.9. | |
| Aplazada | Media (4.9) | 0.56% | — | Jamesdlow CSS JS FilesAI | 5/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in jamesdlow CSS JS Files css-js-files allows Path Traversal.This issue affects CSS JS Files: from n/a through <= 1.5.0. | |
| Aplazada | Media (4.3) | 0.21% | — | Jamesward WP Mail CatcherAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in James Ward WP Mail Catcher.This issue affects WP Mail Catcher: from n/a through 2.1.6. | |
| Analizada | Media (6.1) | 0.50% | — | Lynchjames Obsidian Mind MAP | 29/2/2024 | 17/6/2026 | Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document. | |
| Modificada | Media (5.3) | 1.1% | — | Apache James Mime4j | 27/2/2024 | 17/6/2026 | Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. This can be exploited by an attacker to add unintended headers to MIME messages. | |
| Analizada | Alta (7.1) | 1.0% | — | Apache James | 27/2/2024 | 17/6/2026 | Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks. The… | |
| Analizada | Crítica (9.8) | 1.2% | — | Apache James | 27/2/2024 | 17/6/2026 | Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Given a deserialisation gadjet, this could be leveraged as part of an exploit chain that could result in privilege escalation. Note that by default JMX endpoint is only… | |
| Modificada | Media (5.4) | 0.33% | — | Kerryjames Posts TO Page | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Posts to Page Kerry James allows Stored XSS.This issue affects Kerry James: from n/a through 1.7. |