Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Andreamarinucci Notification FOR TelegramAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions. | |
| Aplazada | Crítica (9.8) | 0.67% | — | Miniorange OTP Login Verification SMS NotificationsAI | 26/9/2026 | 28/9/2026 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the… | |
| Aplazada | Alta (7.6) | 0.38% | — | Devitems Hashbar Wordpress Notification BARAI | 22/9/2026 | 22/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3. | |
| Aplazada | Alta (8.6) | 0.60% | — | Behavioral Technology Group PavlokAIApple Notification Center ServiceAI | 10/9/2026 | 10/9/2026 | A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local… | |
| Aplazada | Media (5.3) | 0.19% | — | Notification BARAI | 2/9/2026 | 3/9/2026 | The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails. | |
| Analizada | Baja (3.3) | 0.21% | — | Content Moderation Notifications Project Content Moderation Notifications | 2/9/2026 | 24/9/2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0. | |
| Aplazada | Media (5.4) | 0.23% | — | BuddypressAIPush Notification FOR PostAI | 27/8/2026 | 28/8/2026 | Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Notification MasterAI | 24/8/2026 | 24/8/2026 | Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions. | |
| Aplazada | Crítica (9.8) | 0.71% | — | Automation WEB Platform Notifications AND OTP FOR WoocommerceAI | 21/8/2026 | 24/8/2026 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly… | |
| Aplazada | Alta (7.1) | 0.25% | — | Notificationx PROAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. | |
| Aplazada | Alta (8.8) | 0.20% | — | Devitems Hashbar Wordpress Notification BARAI | 18/8/2026 | 20/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Cozyvision SMS Alert Order NotificationsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | |
| Aplazada | Media (6.9) | 0.47% | — | Website NotificationsAI | 10/8/2026 | 26/8/2026 | The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses after DNS resolution. IPv6 transition addresses (NAT64 `64:ff9b::/96`, 6to4 `2002::/16`, Teredo `2001:0000::/32`) are classified as globally routable by IANA, so `is_global` returns `True` even when the… | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins Google Chat NotificationAI | 5/8/2026 | 31/8/2026 | Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use. | |
| Aplazada | Alta (8.1) | 0.38% | — | Chat ON Desk Order NotificationsAI | 1/8/2026 | 26/8/2026 | The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS… | |
| Aplazada | Media (4.4) | 0.52% | — | SMS Alert SMS OTP FOR Woocommerce Order Notifications Abandoned Cart RecoveryAI | 28/7/2026 | 28/7/2026 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack… | |
| Analizada | Crítica (9.3) | 0.75% | — | Equifax Victim Information Notification Exchange | 23/7/2026 | 26/8/2026 | The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Cozyvision SMS Alert Order NotificationsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. | |
| Aplazada | Media (6.4) | 0.33% | — | Webpushr Push NotificationsAI | 23/7/2026 | 23/7/2026 | The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, 4.39.0. This is due to insufficient input sanitization in the save_send_notification_flag() function and… | |
| Aplazada | Crítica (10) | 0.89% | — | Nocobase Plugin Notification IN APP MessageAI | 15/7/2026 | 20/7/2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal()… | |
| Aplazada | Media (4.3) | 0.47% | — | Andreamarinucci Notification FOR TelegramAI | 11/7/2026 | 13/7/2026 | The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Miniorange OTP Login Verification AND SMS NotificationsAI | 9/7/2026 | 9/7/2026 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_password_process_hook()` function performing no server-side verification that the… | |
| Aplazada | Alta (7.5) | 0.48% | — | Notifications FOR Forms AND Wordpress ActionsAI | 6/7/2026 | 6/7/2026 | The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and execute arbitrary local PHP files on the server. | |
| Aplazada | Alta (7.5) | 0.48% | — | Cozyvision SMS Alert Order NotificationsAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Andreamarinucci Notification FOR TelegramAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5 versions. |