Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.43%—Themeton THE Barber ShopAI17/6/202630/9/2026
Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.
AplazadaCrítica (9.8)0.51%—Themeton FinagAI19/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.
AplazadaCrítica (9.8)0.39%—Themeton ZuutAI19/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.
AplazadaCrítica (9.8)0.70%—Themeton Consult AIDAI22/1/202617/6/2026
Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a through <= 1.4.3.
AplazadaAlta (7.1)0.26%—Themeton Seven StarsAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeton Seven Stars allows Stored XSS. This issue affects Seven Stars: from n/a through 1.4.4.
AplazadaCrítica (9.8)0.54%—Themeton SpareAI17/6/202517/6/2026
Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This issue affects Spare: from n/a through 1.7.
AplazadaAlta (7.1)0.28%—Themeton SpareAI9/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeton Spare allows Reflected XSS. This issue affects Spare: from n/a through 1.7.
AplazadaCrítica (9.8)0.59%—Themeton Pressgrid - Frontend Publish Reaction & Multimedia ThemeAI9/6/202517/6/2026
Deserialization of Untrusted Data vulnerability in themeton PressGrid - Frontend Publish Reaction & Multimedia Theme allows Object Injection. This issue affects PressGrid - Frontend Publish Reaction & Multimedia Theme: from n/a through 1.3.1.
AplazadaCrítica (9.8)0.59%—Themeton Pimp - Creative MultipurposeAI9/6/202517/6/2026
Deserialization of Untrusted Data vulnerability in themeton PIMP - Creative MultiPurpose allows Object Injection. This issue affects PIMP - Creative MultiPurpose: from n/a through 1.7.
AplazadaCrítica (9.8)0.59%—Themeton Flap - Business Wordpress ThemeAI9/6/202517/6/2026
Deserialization of Untrusted Data vulnerability in themeton FLAP - Business WordPress Theme allows Object Injection. This issue affects FLAP - Business WordPress Theme: from n/a through 1.5.
AplazadaCrítica (9.8)0.57%—Themeton THE Fashion - Model Agency ONE Page Beauty ThemeAI9/6/202517/6/2026
Deserialization of Untrusted Data vulnerability in themeton The Fashion - Model Agency One Page Beauty Theme nrgfashion allows Object Injection.This issue affects The Fashion - Model Agency One Page Beauty Theme: from n/a through <= 1.4.4.
AplazadaCrítica (9.8)0.59%—Themeton AcerolaAI23/5/202517/6/2026
Deserialization of Untrusted Data vulnerability in themeton Acerola allows Object Injection. This issue affects Acerola: from n/a through 1.6.5.
AplazadaCrítica (9.8)0.59%—Themeton THE BusinessAI23/5/202517/6/2026
Deserialization of Untrusted Data vulnerability in themeton The Business allows Object Injection. This issue affects The Business: from n/a through 1.6.1.
AplazadaCrítica (9.8)0.59%—Themeton Hotstar - Multi-purpose Business ThemeAI23/5/202517/6/2026
Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injection. This issue affects HotStar – Multi-Purpose Business Theme: from n/a through 1.4.
AplazadaCrítica (9.8)0.59%—Themeton DashAI23/5/202517/6/2026
Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.
AplazadaMedia (4.3)0.20%—Themeton SpareAI16/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in themeton Spare allows Cross Site Request Forgery. This issue affects Spare: from n/a through 1.7.
AplazadaMedia (5.3)0.32%—Themeton THE BusinessAI16/5/202517/6/2026
Missing Authorization vulnerability in themeton The Business allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Business: from n/a through 1.6.1.
AplazadaMedia (5.3)0.31%—Themeton Hotstar Multi Purpose Business ThemeAI16/5/202517/6/2026
Missing Authorization vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HotStar – Multi-Purpose Business Theme: from n/a through 1.4.
AplazadaMedia (4.3)0.20%—Themeton Seven StarsAI16/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in themeton Seven Stars allows Cross Site Request Forgery. This issue affects Seven Stars: from n/a through 1.4.4.
AplazadaMedia (5.3)0.41%—Themeton AcerolaAI16/5/202517/6/2026
Missing Authorization vulnerability in themeton Acerola acerola allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Acerola: from n/a through <= 1.6.5.
AplazadaMedia (5.3)0.31%—Themeton RozarioAI16/5/202517/6/2026
Missing Authorization vulnerability in themeton Rozario allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rozario: from n/a through 1.4.
AplazadaCrítica (9.8)1.8%—Daenetip4 MetoAI18/4/202517/6/2026
Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.
AplazadaAlta (7.1)0.25%—Awesometogi Awesome Event BookingAI4/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Reflected XSS.This issue affects Awesome Event Booking: from n/a through <= 2.8.4.
AplazadaMedia (6.5)0.36%—Awesometogi Awesome Event BookingAI27/3/202517/6/2026
Missing Authorization vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Event Booking: from n/a through <= 2.7.2.
AplazadaAlta (7.1)0.14%—Stanko Metodiev Quote-commentsAI7/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Stanko Metodiev Quote Comments quote-comments allows Stored XSS.This issue affects Quote Comments: from n/a through <= 3.0.0.