Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

378 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.1)——Ansar ImportAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Ansar Import – One Click Starter Sites – for Elementor &amp; Themes <= 2.1.2 versions.
RecibidaAlta (7.2)——Codection Import AND Export Users AND CustomersAI6/10/20266/10/2026
Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions.
RecibidaBaja (3.7)0.18%—Smackcoders WP Ultimate CSV ImporterAI3/10/20263/10/2026
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a…
RecibidaBaja (3.5)0.14%—Smackcoders WP Ultimate CSV ImporterAI3/10/20263/10/2026
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite…
AplazadaMedia (5.3)0.20%—Smackcoders WP Ultimate CSV ImporterAI1/10/20261/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate CSV Importer: from n/a through 9.1.
AplazadaAlta (7.5)0.30%—Codection Import AND Export Users AND CustomersAI30/9/202630/9/2026
Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.
AplazadaAlta (8.8)0.33%—Codection Import AND Export Users AND CustomersAI23/9/202624/9/2026
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape…
AplazadaMedia (6.5)0.17%—Podcast ImporterAI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions.
AplazadaMedia (5.3)0.47%—Midnightbsd MportAI21/9/202625/9/2026
mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could redirect temporary metadata extraction to an attacker-controlled…
AplazadaAlta (7.2)0.46%—Codection Import AND Export Users AND CustomersAI20/9/202621/9/2026
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.
AplazadaAlta (7.2)0.46%—Codection Import AND Export Users AND CustomersAI20/9/202621/9/2026
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.
AplazadaMedia (4.1)0.18%—Codection Import AND Export Users AND CustomersAI20/9/202621/9/2026
The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks.
AplazadaMedia (4.3)0.43%—Flex ImportAI19/9/202621/9/2026
The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() and license_deactivate_fleximp() functions, hooked to the wp_ajax_license_activate_fleximp and wp_ajax_license_deactivate_fleximp AJAX actions, lacking…
AplazadaAlta (7.2)0.46%—Vjinfotech WP Import Export LiteAI19/9/202621/9/2026
The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who cannot otherwise manage users, to create…
AplazadaMedia (5.8)0.10%—Midnightbsd MportAI17/9/202617/9/2026
mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local attacker able to modify part of the target installation tree could use dot-dot…
AplazadaMedia (6)0.54%—Midnightbsd MportAI17/9/202617/9/2026
mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malicious or malformed package manifest could therefore direct privileged sample-file…
AplazadaAlta (8.3)0.54%—Midnightbsd MportAI17/9/202617/9/2026
mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index data could place an unsafe value in indexEntry->bundlefile, and the missing…
AplazadaMedia (6)0.55%—Midnightbsd MportAI17/9/202617/9/2026
mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/install_primative.c, and libmport/mport_private.h did not apply…
AplazadaAlta (8.3)0.22%—Midnightbsd MportAI17/9/202617/9/2026
mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failure path did not preserve a fatal result. A network attacker or compromised mirror…
AplazadaMedia (6)0.15%—Midnightbsd MportAI17/9/202621/9/2026
mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without a url_is_https() enforcement check. When a cleartext URL was configured or returned by…
AplazadaAlta (8.3)0.26%—Midnightbsd MportAI17/9/202624/9/2026
mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently propagate those failures to index-fetch callers. A malicious or faulty mirror could supply compressed…
AplazadaBaja (2.3)0.16%—Midnightbsd MportAI17/9/202624/9/2026
mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using a fixed IP-header offset instead of ip_hl. A network attacker able to inject or spoof visible ICMP replies could influence mirror latency…
AplazadaBaja (2)0.11%—Midnightbsd MportAI17/9/202618/9/2026
mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than a newly computed digest. An attacker able to influence an installed file or the…
AplazadaBaja (2)0.16%—Midnightbsd MportAI17/9/202624/9/2026
mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument entry to audit_package(). When an operator or automation used an option such as -r before a package name, stale optind state and the…
AplazadaMedia (5.8)0.10%—Midnightbsd MportAI17/9/202618/9/2026
mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target directory could replace a checked file with a symlink…