Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2636▼ 212 respecto a la semana anterior
Críticas / altas1386▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.22%—Miniorange Malware ScannerAI3/9/202517/6/2026
Missing Authorization vulnerability in Malcure Web Security Malcure Malware Scanner wp-malware-removal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Malcure Malware Scanner: from n/a through <= 16.8.
AplazadaBaja (3.8)0.27%—Quttera WEB Malware ScannerAI15/8/202517/6/2026
The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.1.41 via the 'RunExternalScan' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations…
AplazadaMedia (6.5)0.32%—Malcure Malware ScannerAI18/7/202517/6/2026
The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 16.8 via the wpmr_inspect_file() function due to a missing capability check. This makes it possible for authenticated attackers, with subscriber-level…
AplazadaAlta (8.1)0.58%—Malcure Malware ScannerAI16/7/202517/6/2026
The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Deletion due to a missing capability check on the wpmr_delete_file() function in all versions up to, and including, 17.0. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaMedia (5.3)0.40%—Miniorange Malware ScannerAI4/6/202417/6/2026
Authentication Bypass by Spoofing vulnerability in miniorange Malware Scanner allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Malware Scanner: from n/a through 4.7.1.
AplazadaCrítica (9.8)1.7%—Miniorange Malware ScannerAIMiniorange WEB Application FirewallAI13/3/202417/6/2026
The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This…
ModificadaAlta (7.2)0.54%—Miniorange Malware Scanner28/2/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects Malware Scanner: from n/a through 4.7.2.
ModificadaAlta (7.2)1.1%—Quttera WEB Malware Scanner18/12/202317/6/2026
IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks
ModificadaMedia (5.3)19%—Quttera WEB Malware Scanner18/12/202317/6/2026
The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code
ModificadaMedia (4.8)0.58%—Miniorange Malware Scanner27/6/202217/6/2026
The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)