Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.32% | — | Email Encoder Protect Email Addresses AND Phone NumbersAI | 16/4/2026 | 17/6/2026 | The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.30% | — | Tychesoftwares Custom Order Numbers FOR WoocommerceAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in tychesoftwares Custom Order Numbers for WooCommerce custom-order-numbers-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Order Numbers for WooCommerce: from n/a through <= 1.11.0. | |
| Analizada | Media (5.5) | 0.46% | — | Textit Phonenumbers | 27/9/2025 | 17/6/2026 | Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause a panic by providing crafted input causing a "runtime error: slice bounds out of range". | |
| Aplazada | Media (4.3) | 0.16% | — | Berocket Sequential Order Numbers FOR WoocommerceAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BeRocket Sequential Order Numbers for WooCommerce sequential-order-numbers-for-woocommerce allows Cross Site Request Forgery.This issue affects Sequential Order Numbers for WooCommerce: from n/a through <= 3.6.2. | |
| Aplazada | Media (5.4) | 0.41% | — | Opentools Woocommerce Basic OrdernumbersAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Open Tools WooCommerce Basic Ordernumbers woocommerce-basic-ordernumbers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Basic Ordernumbers: from n/a through <= 1.4.4. | |
| Modificada | Alta (8.8) | 0.30% | — | Jenst WP Page Numbers | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jens Törnell WP Page Numbers plugin <= 0.5 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Pluginever WC Serial Numbers | 21/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PluginEver WC Serial Numbers plugin <= 1.6.3 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Tychesoftwares Custom Order Numbers FOR Woocommerce | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Custom Order Numbers for WooCommerce plugin <= 1.4.0 versions. | |
| Modificada | Media (6.5) | 0.30% | — | Metagauss Themeflection Numbers | 17/4/2023 | 17/6/2026 | Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the options to be updated belong to the plugin. As a result, it could allow any authenticated users, such as subscriber, to update arbitrary blog options, such as enabling… | |
| Modificada | Media (5.3) | 0.96% | — | Apple KeynoteApple NumbersApple Pages | 2/4/2017 | 17/6/2026 | An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue involves the "Export" component. It allows users to bypass iWork PDF password protection by leveraging… | |
| Modificada | Media (6.8) | 2.9% | — | Apple NumbersApple PagesApple KeynoteApple Iwork | 18/10/2015 | 17/6/2026 | The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document. | |
| Modificada | Media (4.3) | 2.0% | — | Apple NumbersApple IworkApple PagesApple Keynote | 18/10/2015 | 17/6/2026 | The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain sensitive information via a crafted document. | |
| Modificada | Media (5) | 2.5% | — | Apple MAC OS XApple Iphone OSApple NumbersApple Keynote+2 | 16/8/2015 | 17/6/2026 | Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (5.4) | 0.27% | — | Ilearnwith Numbers & Addition! Math Games | 9/9/2014 | 17/6/2026 | The Numbers & Addition! Math games (aka air.com.tribalnova.ilearnwith.ipad.App2En) application 1.4.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |