Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
–

203 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Andreamarinucci Notification FOR TelegramAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
AplazadaCrítica (9.8)0.67%—Miniorange OTP Login Verification SMS NotificationsAI26/9/202628/9/2026
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the…
AplazadaAlta (7.6)0.38%—Devitems Hashbar Wordpress Notification BARAI22/9/202622/9/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3.
AplazadaAlta (8.6)0.60%—Behavioral Technology Group PavlokAIApple Notification Center ServiceAI10/9/202610/9/2026
A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local…
AplazadaMedia (5.3)0.19%—Notification BARAI2/9/20263/9/2026
The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.
AnalizadaBaja (3.3)0.21%—Content Moderation Notifications Project Content Moderation Notifications2/9/202624/9/2026
Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
AplazadaMedia (5.4)0.23%—BuddypressAIPush Notification FOR PostAI27/8/202628/8/2026
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
AplazadaAlta (7.5)0.43%—Notification MasterAI24/8/202624/8/2026
Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More <= 1.7.1 versions.
AplazadaCrítica (9.8)0.71%—Automation WEB Platform Notifications AND OTP FOR WoocommerceAI21/8/202624/8/2026
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly…
AplazadaAlta (7.1)0.25%—Notificationx PROAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
AplazadaAlta (8.8)0.20%—Devitems Hashbar Wordpress Notification BARAI18/8/202620/8/2026
Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.
AplazadaCrítica (9.8)0.48%—Cozyvision SMS Alert Order NotificationsAI13/8/202614/8/2026
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
AplazadaMedia (6.9)0.47%—Website NotificationsAI10/8/202626/8/2026
The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses after DNS resolution. IPv6 transition addresses (NAT64 `64:ff9b::/96`, 6to4 `2002::/16`, Teredo `2001:0000::/32`) are classified as globally routable by IANA, so `is_global` returns `True` even when the…
Pendiente de análisisMedia (4.3)0.27%—Jenkins Google Chat NotificationAI5/8/202631/8/2026
Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.
AplazadaAlta (8.1)0.38%—Chat ON Desk Order NotificationsAI1/8/202626/8/2026
The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS…
AplazadaMedia (4.4)0.52%—SMS Alert SMS OTP FOR Woocommerce Order Notifications Abandoned Cart RecoveryAI28/7/202628/7/2026
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack…
AnalizadaCrítica (9.3)0.75%—Equifax Victim Information Notification Exchange23/7/202626/8/2026
The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database.
AplazadaCrítica (9.8)0.48%—Cozyvision SMS Alert Order NotificationsAI23/7/202623/7/2026
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
AplazadaMedia (6.4)0.33%—Webpushr Push NotificationsAI23/7/202623/7/2026
The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, 4.39.0. This is due to insufficient input sanitization in the save_send_notification_flag() function and…
AplazadaCrítica (10)0.89%—Nocobase Plugin Notification IN APP MessageAI15/7/202620/7/2026
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal()…
AplazadaMedia (4.3)0.47%—Andreamarinucci Notification FOR TelegramAI11/7/202613/7/2026
The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaCrítica (9.8)1.1%—Miniorange OTP Login Verification AND SMS NotificationsAI9/7/20269/7/2026
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_password_process_hook()` function performing no server-side verification that the…
AplazadaAlta (7.5)0.48%—Notifications FOR Forms AND Wordpress ActionsAI6/7/20266/7/2026
The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and execute arbitrary local PHP files on the server.
AplazadaAlta (7.5)0.48%—Cozyvision SMS Alert Order NotificationsAI17/6/202617/6/2026
Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
AplazadaAlta (7.1)0.25%—Andreamarinucci Notification FOR TelegramAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5 versions.