Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 212 respecto a la semana anterior
Críticas / altas1386▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.22% | — | Miniorange Malware ScannerAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Malcure Web Security Malcure Malware Scanner wp-malware-removal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Malcure Malware Scanner: from n/a through <= 16.8. | |
| Aplazada | Baja (3.8) | 0.27% | — | Quttera WEB Malware ScannerAI | 15/8/2025 | 17/6/2026 | The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.1.41 via the 'RunExternalScan' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations… | |
| Aplazada | Media (6.5) | 0.32% | — | Malcure Malware ScannerAI | 18/7/2025 | 17/6/2026 | The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 16.8 via the wpmr_inspect_file() function due to a missing capability check. This makes it possible for authenticated attackers, with subscriber-level… | |
| Aplazada | Alta (8.1) | 0.58% | — | Malcure Malware ScannerAI | 16/7/2025 | 17/6/2026 | The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Deletion due to a missing capability check on the wpmr_delete_file() function in all versions up to, and including, 17.0. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (5.3) | 0.40% | — | Miniorange Malware ScannerAI | 4/6/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in miniorange Malware Scanner allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Malware Scanner: from n/a through 4.7.1. | |
| Aplazada | Crítica (9.8) | 1.7% | — | Miniorange Malware ScannerAIMiniorange WEB Application FirewallAI | 13/3/2024 | 17/6/2026 | The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This… | |
| Modificada | Alta (7.2) | 0.54% | — | Miniorange Malware Scanner | 28/2/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects Malware Scanner: from n/a through 4.7.2. | |
| Modificada | Alta (7.2) | 1.1% | — | Quttera WEB Malware Scanner | 18/12/2023 | 17/6/2026 | IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks | |
| Modificada | Media (5.3) | 19% | — | Quttera WEB Malware Scanner | 18/12/2023 | 17/6/2026 | The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code | |
| Modificada | Media (4.8) | 0.58% | — | Miniorange Malware Scanner | 27/6/2022 | 17/6/2026 | The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup) |