Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.27% | — | Supsystic Ultimate MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Supsystic Ultimate MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Supsystic Easy Google MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions. | |
| Aplazada | Alta (7.5) | 0.75% | — | Weplugins WP MapsAI | 25/9/2026 | 25/9/2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Aplazada | Media (6.4) | 0.33% | — | Weplugins WP MapsAI | 25/9/2026 | 25/9/2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapes_values Parameter in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.46% | — | Mapster WP MapsAI | 18/9/2026 | 19/9/2026 | The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no capability check, and no allowlist validation on the meta key supplied via the… | |
| Pendiente de análisis | Media (5.3) | 0.50% | — | MapserverAI | 17/9/2026 | 30/9/2026 | MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value received as HTTP_X_FORWARDED_HOST through msBuildOnlineResource(), processLine(),… | |
| Pendiente de análisis | Alta (8.2) | 0.68% | — | MapserverAIPostgresqlAIPostgisAI | 17/9/2026 | 24/9/2026 | MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as gml_<item>_type=Integer are configured, but it does… | |
| Aplazada | Alta (7.6) | 0.38% | — | Weplugins WP MapsAI | 17/9/2026 | 17/9/2026 | Administrator SQL Injection in WP Maps <= 4.9.9 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Supsystic Ultimate MapsAI | 3/9/2026 | 5/9/2026 | Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3. | |
| Analizada | Media (5.3) | 0.56% | — | Elastic Maps Server | 2/9/2026 | 8/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the contents of files outside its intended… | |
| Aplazada | Media (5.3) | 0.40% | — | WP GO MapsAI | 2/9/2026 | 4/9/2026 | Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Interactive GEO MapsAI | 2/9/2026 | 2/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions. | |
| Aplazada | Media (5.4) | 0.22% | — | MapsvgAI | 31/8/2026 | 2/9/2026 | Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions. | |
| Pendiente de análisis | Alta (7) | 0.28% | — | Element Maps-ngAI | 27/8/2026 | 28/8/2026 | A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Maps Marker PROAI | 19/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | Weplugins WP MapsAI | 19/8/2026 | 26/8/2026 | The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request. | |
| Aplazada | Alta (8.6) | 0.58% | — | Mediawiki MapsAI | 18/8/2026 | 9/9/2026 | Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a… | |
| Aplazada | Alta (7.5) | 0.35% | — | Supsystic Ultimate MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Supsystic Ultimate MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Supsystic Ultimate MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. | |
| Aplazada | Alta (7.2) | 0.33% | — | Supsystic Easy Google MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Supsystic Easy Google MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mapsteps UG Ultimate Dashboard PROAI | 18/8/2026 | 25/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG Ultimate Dashboard Pro allows DOM-Based XSS. This issue affects Ultimate Dashboard Pro: from n/a through 3.11.2. | |
| Aplazada | Media (6.5) | 0.34% | — | WP Maps PROAI | 9/8/2026 | 26/8/2026 | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary… |