Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

57 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.25%—Nokri JOB BoardAI5/9/20268/9/2026
The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access…
AplazadaMedia (5.9)0.32%—Themeglow Jobboard JOB ListingAIThemeglow Job-board-lightAI20/2/202617/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in themeglow JobBoard Job listing job-board-light allows Retrieve Embedded Sensitive Data.This issue affects JobBoard Job listing: from n/a through <= 1.2.8.
AplazadaMedia (5.9)0.21%—Brownbagmarketing Greenhouse JOB BoardAI24/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brownbagmarketing Greenhouse Job Board greenhouse-job-board allows DOM-Based XSS.This issue affects Greenhouse Job Board: from n/a through <= 2.7.3.
AplazadaMedia (6.1)0.26%—Bestwebsoft JOB BoardAI25/11/202517/6/2026
The Job Board by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.1. This is due to the plugin storing the entire unsanitized `$_GET` superglobal array directly into the database via `update_user_meta()` when users save search results, and later…
AplazadaAlta (7.5)0.39%—Presstigers Simple JOB BoardAI22/10/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in PressTigers Simple Job Board simple-job-board allows Retrieve Embedded Sensitive Data.This issue affects Simple Job Board: from n/a through <= 2.13.7.
AplazadaMedia (6.5)0.22%—Pickplugins JOB Board ManagerAI26/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager job-board-manager allows DOM-Based XSS.This issue affects Job Board Manager: from n/a through <= 2.1.61.
AplazadaBaja (3.8)0.25%—Pickplugins JOB Board ManagerAI5/9/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61.
AplazadaAlta (8.8)0.18%—Dexignzone Jobzilla - JOB Board Wordpress ThemeAI20/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in DexignZone JobZilla - Job Board WordPress Theme jobzilla allows Privilege Escalation.This issue affects JobZilla - Job Board WordPress Theme: from n/a through <= 2.0.
AplazadaMedia (5.3)0.32%—Pickplugins JOB Board ManagerAI6/6/202517/6/2026
Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.60.
AnalizadaBaja (3.7)0.40%—Presstigers Simple JOB Board15/5/202517/6/2026
The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthenticated users to access and download uploaded resumes
AnalizadaMedia (6.1)0.36%—Presstigers Simple JOB Board15/5/202517/6/2026
In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor
AplazadaAlta (8.1)0.51%—Eyecix Jobsearch WP JOB BoardAI25/4/202517/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for unauthenticated…
AplazadaAlta (8.8)1.0%—Pickplugins JOB Board ManagerAI11/4/202517/6/2026
Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager job-board-manager allows Object Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61.
AplazadaMedia (5.3)0.34%—Pickplugins JOB Board ManagerAI1/4/202517/6/2026
Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.61.
AplazadaMedia (4.9)0.56%—Themeglow JOB Board LightAI1/4/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in themeglow JobBoard Job listing job-board-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoard Job listing: from n/a through <= 1.2.8.
AplazadaAlta (7.1)0.32%—Pickplugins JOB Board ManagerAI3/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager job-board-manager allows Reflected XSS.This issue affects Job Board Manager: from n/a through <= 2.1.61.
AplazadaMedia (5.4)0.19%—Pickplugins JOB Board ManagerAI24/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Job Board Manager job-board-manager allows Cross Site Request Forgery.This issue affects Job Board Manager: from n/a through <= 2.1.59.
AplazadaCrítica (10)0.53%—Themeglow Job-board-lightAI7/1/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in themeglow JobBoard Job listing job-board-light allows Upload a Web Shell to a Web Server.This issue affects JobBoard Job listing: from n/a through <= 1.2.6.
ModificadaCrítica (9.8)0.44%—Presstigers Simple JOB Board2/1/202517/6/2026
Missing Authorization vulnerability in PressTigers Simple Job Board simple-job-board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Job Board: from n/a through <= 2.10.5.
AplazadaMedia (5.3)0.55%—Pickplugins JOB Board ManagerAI16/12/202417/6/2026
Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.61.
AplazadaCrítica (9.8)0.65%—Eyecix Jobsearch WP JOB BoardAI28/11/202417/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticated…
AnalizadaCrítica (9.8)0.86%—Eyecix Jobsearch WP JOB Board6/11/202417/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the…
AnalizadaAlta (8.8)0.79%—Eyecix Jobsearch WP JOB Board6/11/202417/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload…
AnalizadaCrítica (9.8)0.43%—Eyecix Jobsearch WP JOB Board1/11/202417/6/2026
Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4.
AnalizadaAlta (8.8)0.38%—Eyecix Jobsearch WP JOB Board1/11/202417/6/2026
Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4.