Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.41% | — | Stylemixthemes MotorsAI | 6/10/2026 | 6/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124. | |
| Aplazada | Baja (3.1) | 0.13% | — | MotorsAI | 2/10/2026 | 2/10/2026 | The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product… | |
| Aplazada | Media (6.8) | 0.24% | — | MotorsAI | 2/10/2026 | 2/10/2026 | The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an… | |
| Aplazada | Alta (7.5) | 0.27% | — | MotorsAI | 30/9/2026 | 30/9/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Media (5.3) | 0.24% | — | MotorsAI | 17/9/2026 | 18/9/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft,… | |
| Aplazada | Media (5.3) | 0.32% | — | MotorsAI | 17/9/2026 | 18/9/2026 | The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying… | |
| Aplazada | Media (6.5) | 0.30% | — | MotorsAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in Motors <= 1.4.113 versions. | |
| Aplazada | Alta (7.2) | 0.43% | — | MotorsAI | 11/7/2026 | 13/7/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.33% | — | MotorsAI | 2/7/2026 | 2/7/2026 | Unauthenticated Broken Access Control in Motors <= 5.6.80 versions. | |
| Aplazada | Media (4.3) | 0.40% | — | MotorsAI | 1/7/2026 | 1/7/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.35% | — | MotorsAI | 25/6/2026 | 25/6/2026 | Unauthenticated Broken Access Control in Motors <= 1.4.109 versions. | |
| Aplazada | Media (4.3) | 0.19% | — | MotordeskAI | 24/6/2026 | 25/6/2026 | The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the motordesk_admin_home function. This makes it possible for unauthenticated attackers to update the plugin's configuration settings,… | |
| Aplazada | Media (5.3) | 0.16% | — | MotorsAI | 22/6/2026 | 22/6/2026 | The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices. | |
| Aplazada | Alta (8.1) | 0.56% | — | Stylemixthemes MotorsAI | 17/6/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Stylemixthemes MotorsAI | 17/6/2026 | 30/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors motors-car-dealership-classified-listings allows Blind SQL Injection.This issue affects Motors: from n/a through 1.4.109. | |
| Aplazada | Media (6.5) | 0.37% | — | MotorsAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Motors < 1.4.107 versions. | |
| Aplazada | Media (4.1) | 0.24% | — | Indian Motorcycle Scout Bobber Tech 2025AI | 29/5/2026 | 21/7/2026 | Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with access to the Wireless Control Module (WCM) wiring harness to bypass the anti-theft shutdown. The WCM signals shutdown to a peer ECU via a falling-edge… | |
| Aplazada | Baja (1) | 0.20% | — | Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAIIndian Motorcycle Wireless Control ModuleAI | 29/5/2026 | 21/7/2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an… | |
| Aplazada | Baja (1) | 0.20% | — | Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAI | 29/5/2026 | 21/7/2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an… | |
| Aplazada | Media (4.1) | 0.27% | — | Indian Motorcycle Scout Bobber Tech 2025AI | 29/5/2026 | 21/7/2026 | Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the motorcycle's anti-theft shutdown by forcing the Wireless Control Module (WCM) into the CAN bus-off state. Using a well-known CAN error-frame injection… | |
| Aplazada | Media (4.1) | 0.25% | — | Indian Motorcycle Scout Bobber WCMAI | 29/5/2026 | 21/7/2026 | Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with write access to the in-vehicle network to permanently immobilize the motorcycle. The WCM enforces a brute-force lockout on the immobilizer… | |
| Aplazada | Media (4.1) | 0.14% | — | Indian Motorcycle Scout Bobber Tech 2025AI | 29/5/2026 | 21/7/2026 | Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the per-vehicle ECM immobilizer secret by passively observing a single… | |
| Aplazada | Media (4.1) | 0.14% | — | Indian Motorcycle Scout Bobber Tech 2025AI | 29/5/2026 | 21/7/2026 | Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN authentication exchange. The Infotainment Digital… | |
| Pendiente de análisis | Alta (8.4) | 0.18% | — | Motorola MotocitAI | 19/5/2026 | 24/7/2026 | An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external storage which could be used by third party apps running on the device to open a TCP server, exposing sensitive… | |
| Aplazada | Alta (8.1) | 0.46% | — | Wptools MotorsAI | 14/5/2026 | 17/6/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo upload flow. The plugin allows any authenticated user to set an arbitrary… |