Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.22% | — | Mozilla FocusMozilla Klar | 9/6/2026 | 23/7/2026 | UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1. | |
| Aplazada | Media (6.6) | 0.27% | — | Klarna Order Management FOR WoocommerceAI | 3/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Debugging Code vulnerability in Klarna Klarna Order Management for WooCommerce klarna-order-management-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Klarna Order Management for WooCommerce: from n/a through <= 1.9.8. | |
| Analizada | Media (4.3) | 0.26% | — | Klaro Cookie & Consent Management Project Klaro Cookie & Consent Management | 26/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cookie & Consent Management allows Cross-Site Scripting (XSS).This issue affects Klaro Cookie & Consent Management: from 0.0.0 before 3.0.7. | |
| Analizada | Media (5) | 0.22% | — | 1xinternet Simple Klaro | 13/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0. | |
| Analizada | Alta (8.8) | 0.26% | — | 1xinternet Simple Klaro | 13/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0. | |
| Analizada | Media (4.8) | 0.31% | — | Klarned Auto Prune Posts | 15/5/2025 | 17/6/2026 | The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (6.1) | 0.23% | — | Klaro Cookie & Consent Management Project Klaro Cookie & Consent Management | 14/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cookie & Consent Management allows Cross-Site Scripting (XSS).This issue affects Klaro Cookie & Consent Management: from 0.0.0 before 3.0.5. | |
| Analizada | Alta (7.5) | 0.50% | — | Klarna Checkout FOR Woocommerce | 17/4/2025 | 17/6/2026 | The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result in rapid consumption of disk space, potentially filling the… | |
| Modificada | Crítica (9.8) | 1.0% | — | Web-shop-host Startklar Elmentor Addons | 6/6/2024 | 17/6/2026 | The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.15 via the 'dropzone_hash' parameter. This makes it possible for unauthenticated attackers to copy the contents of arbitrary files on the server, which can contain sensitive information,… | |
| Aplazada | Crítica (9.1) | 1.5% | — | Startklar Elementor AddonsAI | 7/5/2024 | 17/6/2026 | The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.7.13. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files,… | |
| Aplazada | Crítica (9.8) | 1.4% | — | Startklar Elementor AddonsAI | 7/5/2024 | 17/6/2026 | The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process' function in the 'startklarDropZoneUploadProcess' class in versions up to, and including, 1.7.13. This makes it possible for unauthenticated attackers to upload arbitrary… | |
| Modificada | Crítica (9.8) | 0.48% | — | Klarna FOR Woocommerce | 29/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Klarna Klarna Payments for WooCommerce.This issue affects Klarna Payments for WooCommerce: from n/a through 3.2.4. | |
| Modificada | Alta (7.5) | 1.5% | — | Varnish-cache Varnish-modulesVarnish-cache Varnish-modules KlarlackFedoraproject Fedora | 16/3/2021 | 17/6/2026 | Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is common to install both Varnish Cache and varnish-modules. Specifically, an assertion failure… | |
| Modificada | Alta (8.8) | 1.7% | — | Jenkins Klaros-testmanagement | 4/4/2019 | 17/6/2026 | Jenkins Klaros-Testmanagement Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. |