Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.21% | — | Shortpixel Image OptimizerAI | 30/9/2026 | 30/9/2026 | Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions. | |
| Aplazada | Media (6.5) | 0.18% | — | Ewww Image OptimizerAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions. | |
| Aplazada | Media (4.4) | 0.17% | — | Ewww Image OptimizerAI | 30/9/2026 | 30/9/2026 | The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network,… | |
| Aplazada | Media (6.6) | 0.35% | — | Ewww Image OptimizerAI | 30/9/2026 | 30/9/2026 | The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a… | |
| Aplazada | Media (4.3) | 0.18% | — | Image OptimizerAI | 30/9/2026 | 30/9/2026 | The Image Optimizer WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be restricted to administrators. | |
| Aplazada | Alta (7.5) | 0.22% | — | Robin Image OptimizerAI | 30/9/2026 | 30/9/2026 | The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of… | |
| Aplazada | Media (4.3) | 0.16% | — | Robin Image OptimizerAI | 30/9/2026 | 30/9/2026 | The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer WordPress plugin before 2.0.8 pages and disclose the Robin… | |
| Aplazada | Alta (8.4) | 0.70% | — | Token Optimizer MCPAI | 28/9/2026 | 1/10/2026 | Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call the smart_user tool can execute… | |
| Aplazada | Media (5.3) | 0.45% | — | Token Optimizer MCPAI | 28/9/2026 | 30/9/2026 | Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, the dashboard HTTP server in token-optimizer-mcp exposes /api/session-summary and /api/session-events with no authentication middleware — any… | |
| Aplazada | Media (4.9) | 0.51% | — | WP OptimizerAI | 19/9/2026 | 21/9/2026 | The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is due to an unsafe subquery-detection branch in the Query::parse_key_compare_field() method that, when the user-supplied value matches the regex ^[(\s]*SELECT\s+, wraps the value… | |
| Aplazada | Alta (8.8) | 0.89% | — | Shortpixel Image OptimizerAI | 18/9/2026 | 18/9/2026 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP… | |
| Aplazada | Media (6.8) | 0.43% | — | Ewww Image OptimizerAI | 17/9/2026 | 18/9/2026 | The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views… | |
| Aplazada | Media (5.9) | 0.36% | — | SVG OptimizerAI | 14/9/2026 | 22/9/2026 | The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents. | |
| Aplazada | Alta (7.2) | 0.28% | — | Ewww Image OptimizerAI | 3/9/2026 | 3/9/2026 | Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions. | |
| Aplazada | Alta (8.6) | 3.2% | — | Redport Optimizer Wxa-203AIRedport Optimizer Wxa-213AIRedport Optimizer Wxa-223AI | 31/8/2026 | 1/9/2026 | A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The… | |
| Aplazada | Media (6.4) | 0.42% | — | Ewww Image OptimizerAI | 19/8/2026 | 20/8/2026 | The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.41% | — | Siteground Speed OptimizerAI | 19/8/2026 | 20/8/2026 | The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.35% | — | Siteground Security OptimizerAI | 6/8/2026 | 26/8/2026 | The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to be bypassed so that unauthenticated requests from non-allowlisted IP addresses can reach and use the login form, defeating the access control… | |
| Aplazada | Alta (8.1) | 0.66% | — | Image OptimizerAI | 2/7/2026 | 2/7/2026 | The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file deletion operations without verifying they… | |
| Aplazada | Alta (7.2) | 0.54% | — | Shortpixel Image OptimizerAI | 15/6/2026 | 17/6/2026 | Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions. | |
| Aplazada | Alta (8.8) | 0.45% | — | AutoptimizeAIClearfy CacheAISiteground Speed OptimizerAI | 18/5/2026 | 17/6/2026 | The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular… | |
| Aplazada | Alta (8.1) | 0.36% | — | SqloptimizerAI | 13/5/2026 | 17/6/2026 | Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled. | |
| Pendiente de análisis | Alta (7.3) | 0.15% | — | HP System OptimizerAI | 15/4/2026 | 17/6/2026 | HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate this potential vulnerability. | |
| Aplazada | Media (5.4) | 0.31% | — | Shortpixel Image OptimizerAI | 26/3/2026 | 17/6/2026 | The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to, and including, 6.4.3. This is due to insufficient output escaping in the getEditorPopup() function and its corresponding media-popup.php template. Specifically, the… | |
| Pendiente de análisis | Alta (7.8) | 0.21% | — | Nvidia Model OptimizerAI | 24/3/2026 | 17/6/2026 | NVIDIA Model Optimizer for Windows and Linux contains a vulnerability in the ONNX quantization feature, where a user could cause unsafe deserialization by providing a specially crafted input file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and… |