Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2637▼ 209 respecto a la semana anterior
Críticas / altas1378▲ 149 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.24% | — | Masterstickies Master SliderAI | 20/9/2026 | 21/9/2026 | The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outputting them in an inline script context, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when the affected post is viewed.… | |
| Pendiente de análisis | Media (4.8) | 0.25% | — | CookiesAIKoajs KOAAI | 10/9/2026 | 10/9/2026 | cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator, but the domain and path options are checked only against a permissive RFC 7230… | |
| Aplazada | Baja (1.8) | 0.26% | — | Backdrop Gdpr CookiesAI | 26/5/2026 | 24/7/2026 | The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission… | |
| Aplazada | Media (5.3) | 0.40% | — | Followmedarling Cookies AND Content Security PolicyAI | 22/1/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Johan Jonk Stenström Cookies and Content Security Policy cookies-and-content-security-policy allows Retrieve Embedded Sensitive Data.This issue affects Cookies and Content Security Policy: from n/a through <= 2.34. | |
| Aplazada | Media (6) | 0.47% | — | Python Http.cookiesAI | 20/1/2026 | 17/6/2026 | When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters. | |
| Modificada | Media (5.3) | 0.44% | — | Followmedarling Cookies AND Content Security Policy | 19/8/2025 | 5/7/2026 | Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unlimited database write operations to the wp_ajax_nopriv_cacsp_insert_consent_data… | |
| Analizada | Alta (7.6) | 0.29% | — | Cookies Consent Management Project Cookies Consent Management | 15/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.16. | |
| Analizada | Baja (2.1) | 0.28% | — | Jerryshensjf Jpacookieshop | 27/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f615a3fed2ec1cefb999. This affects an unknown part of the file AdminTypeCustController.java. The manipulation leads to cross-site request forgery. It is possible to initiate the attack… | |
| Analizada | Baja (2) | 0.36% | — | Jerryshensjf Jpacookieshop | 27/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f615a3fed2ec1cefb999. Affected by this issue is some unknown functionality of the file GoodsController.java. The manipulation leads to cross site scripting. The attack may be launched… | |
| Analizada | Baja (2.1) | 0.49% | — | Jerryshensjf Jpacookieshop | 27/7/2025 | 17/6/2026 | A vulnerability classified as problematic was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f615a3fed2ec1cefb999. Affected by this vulnerability is the function goodsSearch of the file GoodsCustController.java. The manipulation of the argument keyword leads to cross site scripting. The attack… | |
| Analizada | Media (5.3) | 0.40% | — | Jerryshensjf Jpacookieshop | 21/7/2025 | 17/6/2026 | A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0. It has been classified as critical. Affected is the function addGoods of the file GoodsController.java. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. | |
| Analizada | Baja (2.1) | 0.37% | — | Jerryshensjf Jpacookieshop | 21/7/2025 | 17/6/2026 | A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 and classified as critical. This issue affects the function updateGoods of the file GoodsController.java. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.1) | 0.23% | — | Cookies Addons Project Cookies Addons | 21/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookies Addons allows Cross-Site Scripting (XSS).This issue affects Cookies Addons: from 1.0.0 before 1.2.4. | |
| Analizada | Alta (8.6) | 0.33% | — | Drupal Cookies Consent Management | 13/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15. | |
| Analizada | Alta (8.6) | 0.33% | — | Drupal Cookies Consent Management | 13/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15. | |
| Analizada | Media (6.1) | 0.23% | — | Cookies Consent Manager Project Cookies Coonsent Manager | 14/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.14. | |
| Aplazada | Media (4.3) | 0.17% | — | Illow Cookies ConsentAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in illow illow – Cookies Consent lgpd-compliant-cookie-banner allows Cross Site Request Forgery.This issue affects illow – Cookies Consent: from n/a through <= 0.2.0. | |
| Aplazada | Media (4.3) | 0.20% | — | Wpdesk Flexible CookiesAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible Cookies flexible-cookies allows Cross Site Request Forgery.This issue affects Flexible Cookies: from n/a through <= 1.1.8. | |
| Aplazada | Alta (7.1) | 0.39% | — | Pixelpro Cookies PROAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelpro Cookies Pro cookies-pro allows Reflected XSS.This issue affects Cookies Pro: from n/a through <= 1.0. | |
| Analizada | Crítica (9.8) | 0.61% | — | Wpguru Show ME THE Cookies | 22/2/2025 | 17/6/2026 | The The Show Me The Cookies plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.1) | 0.20% | — | Aleapp WP Cookies AlertAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in aleapp WP Cookies Alert wp-cookies-alert allows Cross Site Request Forgery.This issue affects WP Cookies Alert: from n/a through <= 1.1.1. | |
| Aplazada | Alta (8) | 0.24% | — | BD Diagnostic SolutionsAIBD Synapsys Informatics SolutionAIBD Kiestra SCUAI | 17/12/2024 | 17/6/2026 | Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive information such as protected health information (PHI) and personally identifiable information (PII). Exploitation of this vulnerability may… | |
| Aplazada | Alta (7.5) | 0.71% | — | Filippo Bodei WP Cookies EnablerAI | 16/12/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Filippo Bodei WP Cookies Enabler wp-cookies-enabler allows PHP Local File Inclusion.This issue affects WP Cookies Enabler: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.31% | — | Karl Kiesinger Gwp-histatsAI | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Karl Kiesinger GWP-Histats allows Stored XSS.This issue affects GWP-Histats: from n/a through 1.0. | |
| Modificada | Alta (7.5) | 0.67% | — | Followmedarling Cookies AND Content Security Policy | 30/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jonk @ Follow me Darling Cookies and Content Security Policy.This issue affects Cookies and Content Security Policy: from n/a through 2.15. |