Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2888▼ 169 respecto a la semana anterior
Críticas / altas1285▼ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.29% | — | Linethemes NanocareAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects NanoCare: from n/a before 1.2.2. | |
| Aplazada | Media (5.4) | 0.23% | — | Linethemes SmartfixAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in linethemes SmartFix smartfix allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SmartFix: from n/a through < 1.2.4. | |
| Aplazada | Media (5.4) | 0.29% | — | Linethemes NanosoftAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in linethemes Nanosoft nanosoft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nanosoft: from n/a through < 1.3.2. | |
| Aplazada | Media (5.4) | 0.23% | — | Linethemes GLBAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in linethemes GLB glb allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GLB: from n/a through <= 1.2.2. | |
| Modificada | Media (5.4) | 0.50% | — | Secondlinethemes Podcast Subscribe Buttons | 20/10/2023 | 17/6/2026 | The Podcast Subscribe Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'podcast_subscribe' shortcode in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (8.8) | 0.26% | — | Secondlinethemes Auto Youtube Importer | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SecondLineThemes Auto YouTube Importer plugin <= 1.0.3 versions. | |
| Modificada | Alta (7.2) | 1.5% | — | Secondlinethemes Podcast Importer Secondline | 11/4/2022 | 17/6/2026 | The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file | |
| Modificada | Media (5.4) | 0.62% | — | Secondlinethemes Podcast Subscribe Buttons | 18/10/2021 | 17/6/2026 | The Podcast Subscribe Buttons WordPress plugin before 1.4.2 allows users with any role capable of editing or adding posts to perform stored XSS. |