Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.67%—Miniorange OTP Login Verification SMS NotificationsAI26/9/202628/9/2026
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the…
AnalizadaBaja (3.3)0.21%—Content Moderation Notifications Project Content Moderation Notifications2/9/202624/9/2026
Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
AplazadaCrítica (9.8)0.71%—Automation WEB Platform Notifications AND OTP FOR WoocommerceAI21/8/202624/8/2026
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly…
AplazadaCrítica (9.8)0.48%—Cozyvision SMS Alert Order NotificationsAI13/8/202614/8/2026
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
AplazadaMedia (6.9)0.47%—Website NotificationsAI10/8/202626/8/2026
The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses after DNS resolution. IPv6 transition addresses (NAT64 `64:ff9b::/96`, 6to4 `2002::/16`, Teredo `2001:0000::/32`) are classified as globally routable by IANA, so `is_global` returns `True` even when the…
AplazadaAlta (8.1)0.38%—Chat ON Desk Order NotificationsAI1/8/202626/8/2026
The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS…
AplazadaMedia (4.4)0.52%—SMS Alert SMS OTP FOR Woocommerce Order Notifications Abandoned Cart RecoveryAI28/7/202628/7/2026
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack…
AplazadaCrítica (9.8)0.48%—Cozyvision SMS Alert Order NotificationsAI23/7/202623/7/2026
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
AplazadaMedia (6.4)0.33%—Webpushr Push NotificationsAI23/7/202623/7/2026
The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, 4.39.0. This is due to insufficient input sanitization in the save_send_notification_flag() function and…
AplazadaCrítica (9.8)1.1%—Miniorange OTP Login Verification AND SMS NotificationsAI9/7/20269/7/2026
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_password_process_hook()` function performing no server-side verification that the…
AplazadaAlta (7.5)0.48%—Notifications FOR Forms AND Wordpress ActionsAI6/7/20266/7/2026
The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to build a server-side file inclusion path, allowing authenticated users with subscriber-level access and above to include and execute arbitrary local PHP files on the server.
AplazadaAlta (7.5)0.48%—Cozyvision SMS Alert Order NotificationsAI17/6/202617/6/2026
Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
AplazadaMedia (5.4)0.29%—Cozyvision SMS Alert Order NotificationsAI13/3/202617/6/2026
Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.9.0.
AplazadaMedia (4.3)0.13%—Disable Admin Notices Hide Dashboard NotificationsAI25/2/202617/6/2026
The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing nonce validation in the `showPageContent()` function. This makes it possible for unauthenticated attackers to add arbitrary URLs…
AnalizadaMedia (6)0.19%—Tanium End-user Notifications9/2/202617/6/2026
Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.
AplazadaMedia (5.3)0.34%—Webpushr-web-push-notificationsAI23/1/202617/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in webpushr Webpushr webpushr-web-push-notifications allows Retrieve Embedded Sensitive Data.This issue affects Webpushr: from n/a through <= 4.38.0.
AplazadaMedia (4.3)0.24%—Gravitec.net WEB Push NotificationsAI9/12/202517/6/2026
Missing Authorization vulnerability in Gravitec.net - Web Push Notifications Gravitec.net – Web Push Notifications gravitec-net-web-push-notifications allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gravitec.net – Web Push Notifications: from n/a through <= 2.9.17.
AplazadaMedia (5.3)0.21%—Cozyvision SMS Alert Order NotificationsAI21/11/202517/6/2026
Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.8.
AplazadaMedia (4.3)0.25%—Clicksend SMS Contact Form 7 NotificationsAI27/10/202517/6/2026
Missing Authorization vulnerability in clicksend SMS Contact Form 7 Notifications by ClickSend clicksend-contactform7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Contact Form 7 Notifications by ClickSend: from n/a through <= 1.4.0.
AplazadaCrítica (9.3)0.49%—Cozyvision SMS Alert Order NotificationsAI22/10/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.5.
AplazadaMedia (5.9)0.22%—Proof Factor LLC Proof Factor Social Proof NotificationsAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proof Factor LLC Proof Factor – Social Proof Notifications proof-factor-social-proof-notifications allows Stored XSS.This issue affects Proof Factor – Social Proof Notifications: from n/a through <= 1.0.5.
AplazadaMedia (6.5)0.21%—Buddydev Buddypress Notifications WidgetAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev BuddyPress Notification Widget buddypress-notifications-widget allows Stored XSS.This issue affects BuddyPress Notification Widget: from n/a through <= 1.3.3.
AplazadaMedia (6.5)0.25%—Codesolz Ultimate Push NotificationsAI16/7/202517/6/2026
Missing Authorization vulnerability in CodeSolz Ultimate Push Notifications ultimate-push-notifications allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Push Notifications: from n/a through <= 1.2.0.
AplazadaCrítica (9.1)0.36%—Mediawiki DiscordnotificationsAI10/7/202517/6/2026
DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel. DiscordNotifications allows sending requests via curl and file_get_contents to arbitrary URLs set via $wgDiscordIncomingWebhookUrl and $wgDiscordAdditionalIncomingWebhookUrls. This allows for DOS…
AplazadaMedia (4.3)0.37%—Slack Notifications BY DorzkiAI6/6/202517/6/2026
Missing Authorization vulnerability in Dor Zuberi Slack Notifications by dorzki dorzki-notifications-to-slack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slack Notifications by dorzki: from n/a through <= 2.0.7.