Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.51%—Eyecix Jobsearch WP JOB BoardAI25/4/202517/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for unauthenticated…
AplazadaCrítica (9.8)0.65%—Eyecix Jobsearch WP JOB BoardAI28/11/202417/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticated…
AnalizadaCrítica (9.8)0.86%—Eyecix Jobsearch WP JOB Board6/11/202417/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the…
AnalizadaAlta (8.8)0.79%—Eyecix Jobsearch WP JOB Board6/11/202417/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload…
AnalizadaCrítica (9.8)0.43%—Eyecix Jobsearch WP JOB Board1/11/202417/6/2026
Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4.
AnalizadaAlta (8.8)0.38%—Eyecix Jobsearch WP JOB Board1/11/202417/6/2026
Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4.
ModificadaCrítica (9.8)0.55%—Eyecix Jobsearch WP JOB Board10/10/202417/6/2026
Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: from n/a through <= 2.5.9.
AnalizadaCrítica (9.8)0.52%—Eyecix Jobsearch WP JOB Board29/8/202417/6/2026
Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.
AnalizadaAlta (7.5)0.60%—Eyecix Jobsearch WP JOB Board27/2/202417/6/2026
The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server
AnalizadaAlta (7.5)0.55%—Eyecix Jobsearch WP JOB Board27/2/202417/6/2026
The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.
ModificadaMedia (4.3)0.70%—Eyecix Jobsearch WP JOB Board7/6/202317/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls.
ModificadaAlta (8.8)1.2%—Eyecix Jobsearch WP JOB Board7/6/202317/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site.
ModificadaMedia (5.3)0.85%—Eyecix Jobsearch WP JOB Board7/6/202317/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.
ModificadaMedia (6.1)1.8%💥 ExploitEyecix Jobsearch WP JOB Board4/4/202217/6/2026
There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1.
ModificadaMedia (5.4)0.63%—Eyecix Jobsearch WP JOB Board12/7/202117/6/2026
The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue
Orbitaley — Vulnerabilidades