Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

298 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.27%—Supsystic Ultimate MapsAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.
AplazadaAlta (7.1)0.25%—Supsystic Ultimate MapsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
AplazadaAlta (7.1)0.25%—Supsystic Easy Google MapsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
AplazadaAlta (7.5)0.75%—Weplugins WP MapsAI25/9/202625/9/2026
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above,…
AplazadaMedia (6.4)0.33%—Weplugins WP MapsAI25/9/202625/9/2026
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapes_values Parameter in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (8.8)0.46%—Mapster WP MapsAI18/9/202619/9/2026
The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no capability check, and no allowlist validation on the meta key supplied via the…
Pendiente de análisisMedia (5.3)0.50%—MapserverAI17/9/202630/9/2026
MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value received as HTTP_X_FORWARDED_HOST through msBuildOnlineResource(), processLine(),…
Pendiente de análisisAlta (8.2)0.68%—MapserverAIPostgresqlAIPostgisAI17/9/202624/9/2026
MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml_<item>_type=Integer are configured, but it does…
AplazadaAlta (7.6)0.38%—Weplugins WP MapsAI17/9/202617/9/2026
Administrator SQL Injection in WP Maps <= 4.9.9 versions.
AplazadaMedia (5.3)0.29%—Supsystic Ultimate MapsAI3/9/20265/9/2026
Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3.
AnalizadaMedia (5.3)0.56%—Elastic Maps Server2/9/20268/9/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the contents of files outside its intended…
AplazadaMedia (5.3)0.40%—WP GO MapsAI2/9/20264/9/2026
Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
AplazadaAlta (7.1)0.25%—Interactive GEO MapsAI2/9/20262/9/2026
Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.
AplazadaMedia (5.4)0.22%—MapsvgAI31/8/20262/9/2026
Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.
Pendiente de análisisAlta (7)0.28%—Element Maps-ngAI27/8/202628/8/2026
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label…
AplazadaCrítica (9.3)0.40%—Maps Marker PROAI19/8/202620/8/2026
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
AplazadaMedia (5.4)0.29%—Weplugins WP MapsAI19/8/202626/8/2026
The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request.
AplazadaAlta (8.6)0.58%—Mediawiki MapsAI18/8/20269/9/2026
Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a…
AplazadaAlta (7.5)0.35%—Supsystic Ultimate MapsAI18/8/202620/8/2026
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
AplazadaCrítica (9.8)0.56%—Supsystic Ultimate MapsAI18/8/202620/8/2026
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
AplazadaAlta (7.1)0.25%—Supsystic Ultimate MapsAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
AplazadaAlta (7.2)0.33%—Supsystic Easy Google MapsAI18/8/202620/8/2026
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
AplazadaCrítica (9.8)0.56%—Supsystic Easy Google MapsAI18/8/202620/8/2026
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
AplazadaAlta (7.1)0.25%—Mapsteps UG Ultimate Dashboard PROAI18/8/202625/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG Ultimate Dashboard Pro allows DOM-Based XSS. This issue affects Ultimate Dashboard Pro: from n/a through 3.11.2.
AplazadaMedia (6.5)0.34%—WP Maps PROAI9/8/202626/8/2026
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary…