Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 331 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.42% | — | Siteleads Lead Generation Contact Widget AND AI ChatbotAI | 24/8/2026 | 26/8/2026 | Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Thrive LeadsAI | 27/7/2026 | 27/7/2026 | Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions. | |
| Aplazada | Crítica (9) | 0.42% | — | Doleads IntegratorAIWp2epubAI | 7/7/2026 | 7/7/2026 | The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are added adding to a blog, for example using a vulnerability where unclosed extensions from wordpress.org can be installed by unauthorized users. | |
| Aplazada | Media (5.3) | 0.14% | — | Helloleads CRM Form ShortcodeAI | 14/12/2025 | 17/6/2026 | The HelloLeads CRM Form Shortcode WordPress plugin through 1.0 does not have authorisation and CSRF check when resetting its settings, allowing unauthenticated users to reset them | |
| Analizada | Media (6.5) | 0.15% | — | Rems Leads Manager Tool | 7/11/2025 | 17/6/2026 | The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unauthorized state-changing operations. The application lacks CSRF protection mechanisms such as anti-CSRF tokens or same-origin verification for critical endpoints. | |
| Aplazada | Alta (8.7) | 0.55% | — | Leadsec SSL VPNAI | 26/6/2025 | 17/6/2026 | A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing unauthenticated attackers to read arbitrary files on the underlying system via the ostype parameter in the /vpn/user/download/client endpoint. This flaw arises from insufficient input sanitation, enabling traversal… | |
| Aplazada | Alta (7.1) | 0.34% | — | Saleswonder Team Wp2leadsAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Reflected XSS.This issue affects WP2LEADS: from n/a through <= 3.5.0. | |
| Aplazada | Alta (7.1) | 0.14% | — | Wp2leadsAI | 15/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Stored XSS.This issue affects WP2LEADS: from n/a through <= 3.5.0. | |
| Aplazada | Alta (7.1) | 0.31% | — | Saleswonder Team Wp2leadsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Reflected XSS.This issue affects WP2LEADS: from n/a through <= 3.4.5. | |
| Aplazada | Alta (7.1) | 0.13% | — | Omnileads-scripts-and-tags-managerAI | 28/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in danielmuldernl OmniLeads Scripts and Tags Manager omnileads-scripts-and-tags-manager allows Stored XSS.This issue affects OmniLeads Scripts and Tags Manager: from n/a through <= 1.3. | |
| Aplazada | Alta (8.5) | 0.45% | — | Smackcoders INC Wp-leads-builder-any-crmAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allows Blind SQL Injection.This issue affects Lead Form Data Collection to CRM: from n/a through <= 3.0.1. | |
| Analizada | Media (6.1) | 0.44% | — | Wpmaspik Lenix Leads Collector | 20/2/2025 | 17/6/2026 | The Lenix Elementor Leads addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a URL form field in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Alta (7.1) | 0.25% | — | Tobias Wp2leads Wp2leadsAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Reflected XSS.This issue affects WP2LEADS: from n/a through <= 3.3.3. | |
| Aplazada | Alta (7.1) | 0.26% | — | Saleswonder Team Wp2leadsAI | 13/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Reflected XSS.This issue affects WP2LEADS: from n/a through <= 3.4.2. | |
| Aplazada | Alta (7.1) | 0.26% | — | Bizswoop Leads CRMAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bizswoop Leads CRM leads-crm allows Reflected XSS.This issue affects Leads CRM: from n/a through <= 2.0.13. | |
| Analizada | Media (5.3) | 0.41% | — | Rems Leads Manager Tool | 20/8/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Leads Manager Tool 1.0 and classified as problematic. This vulnerability affects unknown code of the file update-leads.php. The manipulation of the argument phone_number leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed… | |
| Modificada | Media (5.3) | 0.69% | — | Rems Leads Manager Tool | 12/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Leads Manager Tool 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-leads.php of the component Add Leads Handler. The manipulation of the argument leads_name/phone_number leads to cross site scripting. It is possible to… | |
| Analizada | Media (5.3) | 0.89% | — | Rems Leads Manager Tool | 12/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Leads Manager Tool 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /endpoint/delete-leads.php of the component Delete Leads Handler. The manipulation of the argument leads leads to sql injection. The attack may be launched… | |
| Aplazada | Media (5.4) | 0.39% | — | Saleswonder Wp2leadsAI | 8/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads.This issue affects WP2LEADS: from n/a through <= 3.2.7. | |
| Modificada | Alta (8.8) | 0.28% | — | Youngtechleads Change Table Prefix | 29/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix change-table-prefix allows Cross Site Request Forgery.This issue affects Change Table Prefix: from n/a through <= 2.0. | |
| Modificada | Crítica (9.8) | 0.75% | — | Leadshop | 19/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Hecheng Leadshop up to 1.4.20. Affected is an unknown function of the file /web/leadshop.php. The manipulation of the argument install leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 0.63% | — | Leadscloud Empirecms | 14/12/2023 | 17/6/2026 | EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php. | |
| Modificada | Alta (8.8) | 0.26% | — | Leadster | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Leadster plugin <= 1.1.2 versions. | |
| Modificada | Media (4.8) | 0.41% | — | Leadsquared Suite | 25/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in LeadSquared Suite plugin <= 0.7.4 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Leadsquared Suite | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions. |