Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.69% | — | Danielpopamd Linkedin-ads-mcpAI | 27/8/2026 | 28/8/2026 | A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the component Media Upload. Such manipulation of the argument filePath leads to path traversal. The attack may be performed… | |
| Aplazada | Media (4.3) | 0.24% | — | Company Posts FOR LinkedinAI | 21/3/2026 | 17/6/2026 | The Company Posts for LinkedIn plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.0. This is due to a missing capability check on the `linkedin_company_post_reset_handler()` function hooked to `admin_post_reset_linkedin_company_post`. This makes it possible for… | |
| Aplazada | Media (4.4) | 0.22% | — | Linkedin SCAI | 14/1/2026 | 17/6/2026 | The LinkedIn SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'linkedin_sc_date_format', 'linkedin_sc_api_key', and 'linkedin_sc_secret_key' parameters in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.25% | — | WP TO Linkedin Auto PublishAI | 13/12/2025 | 17/6/2026 | The WP to LinkedIn Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 1.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.1) | 0.14% | — | Linkedin ResumeAI | 4/11/2025 | 17/6/2026 | The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.00. This is due to missing or incorrect nonce validation on the linkedinresume_printAdminPage() function. This makes it possible for unauthenticated attackers to update settings and inject… | |
| Aplazada | Alta (7.1) | 0.14% | — | Era404 LinkedincludeAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ERA404 LinkedInclude linkedinclude allows Stored XSS.This issue affects LinkedInclude: from n/a through <= 3.0.4. | |
| Analizada | Media (5.3) | 0.33% | — | 3/9/2025 | 17/6/2026 | LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link points to a different URL, which can be… | ||
| Aplazada | Alta (8.1) | 1.0% | — | Alex Furr Linkedin-liteAI | 26/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alex Furr LinkedIn Lite linkedin-lite allows PHP Local File Inclusion.This issue affects LinkedIn Lite: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | Robert D Payne RDP Linkedin LoginAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert D Payne RDP Linkedin Login rdp-linkedin-login allows Reflected XSS.This issue affects RDP Linkedin Login: from n/a through <= 1.7.0. | |
| Aplazada | Alta (7.1) | 0.20% | — | Ivobrett Apply With Linkedin ButtonsAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ivobrett Apply with LinkedIn buttons apply-with-linkedin-buttons allows Stored XSS.This issue affects Apply with LinkedIn buttons: from n/a through <= 2.3. | |
| Aplazada | Media (6.5) | 0.37% | — | Ivobrett Apply With Linkedin ButtonsAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ivobrett Apply with LinkedIn buttons apply-with-linkedin-buttons allows DOM-Based XSS.This issue affects Apply with LinkedIn buttons: from n/a through <= 2.3. | |
| Aplazada | Media (5.4) | 0.31% | — | Martin Gibson WP Linkedin Auto PublishAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson WP LinkedIn Auto Publish.This issue affects WP LinkedIn Auto Publish: from n/a through 8.11. | |
| Analizada | Alta (7.5) | 0.57% | — | Linkedin Greykite | 14/3/2024 | 17/6/2026 | greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file. | |
| Modificada | Crítica (9.8) | 46% | — | Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin) | 29/6/2023 | 17/6/2026 | The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.26% | — | Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin) | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin) | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions. | |
| Modificada | Alta (8.8) | 1.1% | — | Linkedin Dustjs | 21/12/2022 | 17/6/2026 | A vulnerability was found in LinkedIn dustjs up to 2.x and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (4.8) | 0.58% | — | Linkedin Company Updates Project Linkedin Company Updates | 17/7/2022 | 17/6/2026 | The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (6.1) | 3.2% | — | Linkedin Oncall | 5/2/2021 | 17/6/2026 | LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar. | |
| Modificada | Media (6.1) | 1.7% | — | Bestwebsoft Linkedin | 21/8/2019 | 17/6/2026 | The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues. | |
| Modificada | Crítica (9.8) | 3.0% | — | Linkedin Clone Project Linkedin Clone | 13/12/2017 | 17/6/2026 | FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Alta (7.5) | 1.8% | — | Linkedin Browser Toolbar | 1/8/2008 | 16/6/2026 | LinkedIn Browser Toolbar 3.0.3.1100 and earlier does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |
| Modificada | Media (6.8) | 8.2% | — | Linkedin Toolbar | 24/7/2007 | 16/6/2026 | Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a long second argument (varBrowser argument) to the search method. NOTE: some of these details are obtained from third party information. |