Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Netweblogic Login With AjaxAI | 2/9/2026 | 3/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: from n/a through 4.5.1. | |
| Aplazada | Media (6.5) | 0.22% | — | Netweblogic Login With AjaxAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. | |
| Aplazada | Alta (7.1) | 0.21% | — | Navdeep WP Login With AjaxAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Navdeep Wp Login with Ajax wp-login-with-ajax allows Stored XSS.This issue affects Wp Login with Ajax: from n/a through <= 0.6. | |
| Aplazada | Media (4.3) | 0.43% | — | Netweblogic Login With AjaxAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Marcus (aka @msykes) Login With Ajax login-with-ajax allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login With Ajax: from n/a through <= 4.1. | |
| Aplazada | Media (4.3) | 0.20% | — | Pixelite Login With AjaxAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Login With Ajax.This issue affects Login With Ajax: from n/a through 4.1. | |
| Modificada | Media (6.8) | 0.97% | — | Netweblogic Login With Ajax | 10/5/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Login With Ajax plugin before 3.1 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings. | |
| Modificada | Media (4.3) | 2.1% | — | Netweblogic Login With Ajax | 13/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Login With Ajax plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter. | |
| Modificada | Media (4.3) | 2.1% | — | Netweblogic Login With Ajax | 22/5/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login-with-ajax.php in the Login With Ajax (aka login-with-ajax) plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter in a lostpassword action to wp-login.php. |