Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

195 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.41%—Stylemixthemes MotorsAI6/10/20266/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124.
AplazadaBaja (3.1)0.13%—MotorsAI2/10/20262/10/2026
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product…
AplazadaMedia (6.8)0.24%—MotorsAI2/10/20262/10/2026
The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an…
AplazadaAlta (7.5)0.27%—MotorsAI30/9/202630/9/2026
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
AplazadaMedia (5.3)0.24%—MotorsAI17/9/202618/9/2026
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft,…
AplazadaMedia (5.3)0.32%—MotorsAI17/9/202618/9/2026
The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying…
AplazadaMedia (6.5)0.30%—MotorsAI13/8/202614/8/2026
Subscriber Broken Access Control in Motors <= 1.4.113 versions.
AplazadaAlta (7.2)0.43%—MotorsAI11/7/202613/7/2026
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaMedia (6.5)0.33%—MotorsAI2/7/20262/7/2026
Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
AplazadaMedia (4.3)0.40%—MotorsAI1/7/20261/7/2026
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.5)0.35%—MotorsAI25/6/202625/6/2026
Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.
AplazadaMedia (4.3)0.19%—MotordeskAI24/6/202625/6/2026
The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the motordesk_admin_home function. This makes it possible for unauthenticated attackers to update the plugin's configuration settings,…
AplazadaMedia (5.3)0.16%—MotorsAI22/6/202622/6/2026
The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices.
AplazadaAlta (8.1)0.56%—Stylemixthemes MotorsAI17/6/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.
AplazadaCrítica (9.3)0.40%—Stylemixthemes MotorsAI17/6/202630/9/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors motors-car-dealership-classified-listings allows Blind SQL Injection.This issue affects Motors: from n/a through 1.4.109.
AplazadaMedia (6.5)0.37%—MotorsAI15/6/202617/6/2026
Subscriber Broken Access Control in Motors < 1.4.107 versions.
AplazadaMedia (4.1)0.24%—Indian Motorcycle Scout Bobber Tech 2025AI29/5/202621/7/2026
Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with access to the Wireless Control Module (WCM) wiring harness to bypass the anti-theft shutdown. The WCM signals shutdown to a peer ECU via a falling-edge…
AplazadaBaja (1)0.20%—Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAIIndian Motorcycle Wireless Control ModuleAI29/5/202621/7/2026
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an…
AplazadaBaja (1)0.20%—Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAI29/5/202621/7/2026
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an…
AplazadaMedia (4.1)0.27%—Indian Motorcycle Scout Bobber Tech 2025AI29/5/202621/7/2026
Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the motorcycle's anti-theft shutdown by forcing the Wireless Control Module (WCM) into the CAN bus-off state. Using a well-known CAN error-frame injection…
AplazadaMedia (4.1)0.25%—Indian Motorcycle Scout Bobber WCMAI29/5/202621/7/2026
Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with write access to the in-vehicle network to permanently immobilize the motorcycle. The WCM enforces a brute-force lockout on the immobilizer…
AplazadaMedia (4.1)0.14%—Indian Motorcycle Scout Bobber Tech 2025AI29/5/202621/7/2026
Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the per-vehicle ECM immobilizer secret by passively observing a single…
AplazadaMedia (4.1)0.14%—Indian Motorcycle Scout Bobber Tech 2025AI29/5/202621/7/2026
Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN authentication exchange. The Infotainment Digital…
Pendiente de análisisAlta (8.4)0.18%—Motorola MotocitAI19/5/202624/7/2026
An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external storage which could be used by third party apps running on the device to open a TCP server, exposing sensitive…
AplazadaAlta (8.1)0.46%—Wptools MotorsAI14/5/202617/6/2026
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo upload flow. The plugin allows any authenticated user to set an arbitrary…
Orbitaley — Vulnerabilidades