Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.35% | — | PodsAI | 5/9/2026 | 8/9/2026 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'not_found' Shortcode Attribute in all versions up to, and including, 3.3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.8) | 0.40% | — | PodsAI | 4/9/2026 | 8/9/2026 | The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted display-callback mode are affected, which is the… | |
| Aplazada | Alta (7.2) | 0.66% | — | PodsAI | 26/8/2026 | 26/8/2026 | The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked functions, allowing users with the author role and above to execute arbitrary code on the server. Only sites using the restricted display-callback mode are affected, which is the automatic default on… | |
| Pendiente de análisis | Baja (3.5) | 0.29% | — | Jfrog ArtifactoryAICocoapodsAI | 25/8/2026 | 28/8/2026 | Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency. | |
| Aplazada | Crítica (9.8) | 3.5% | — | PodsAI | 15/8/2026 | 20/8/2026 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login… | |
| Aplazada | Alta (7.1) | 0.25% | — | PodsAI | 16/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Coding Panda Panda Pods Repeater FieldAI | 8/4/2026 | 20/7/2026 | Missing Authorization vulnerability in Coding Panda Panda Pods Repeater Field panda-pods-repeater-field allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panda Pods Repeater Field: from n/a through <= 1.5.12. | |
| Aplazada | Alta (7.1) | 0.39% | — | Podspod AppreviewAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in podspod AppReview appreview allows Reflected XSS.This issue affects AppReview: from n/a through <= 0.2.9. | |
| Analizada | Crítica (9.8) | 0.41% | — | Podsfoundation Pods | 23/3/2025 | 17/6/2026 | The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | |
| Analizada | Media (6.1) | 0.32% | — | Podsfoundation Pods | 6/1/2025 | 17/6/2026 | The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.37% | — | Podsfoundation Pods | 5/11/2024 | 17/6/2026 | The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Crítica (9.3) | 15% | — | Trunk.cocoapods.org | 1/7/2024 | 17/6/2026 | trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk. If the pods had never been claimed then it was still possible to do so. It was also possible to have all owners removed from a… | |
| Modificada | Crítica (9.6) | 11% | — | Trunk.cocoapods.org | 1/7/2024 | 17/6/2026 | trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66f49cedab449af9a56a21ab40697b9f7b97, the trunk sessions verification step could be manipulated for owner session hijacking Compromising a victim’s session will result in a full takeover of the CocoaPods trunk… | |
| Modificada | Crítica (10) | 18% | — | Trunk.cocoapods.org | 1/7/2024 | 17/6/2026 | trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has a real email address on signup used a rfc-822 library which executes a shell command to validate the email domain MX records validity. It works via an DNS MX. This lookup could be… | |
| Modificada | Media (4.3) | 0.84% | — | Apple Airpods FirmwareApple Powerbeats FirmwareApple Airpods PRO FirmwareApple Beats FIT PRO Firmware+1 | 26/6/2024 | 17/6/2026 | An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be… | |
| Aplazada | Media (5.4) | 0.44% | — | PodsAI | 14/5/2024 | 17/6/2026 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod Form widget in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Alta (8.8) | 1.3% | — | Podsfoundation Pods | 9/4/2024 | 17/6/2026 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possible for authenticated attackers, with contributor level access or higher, to… | |
| Modificada | Alta (8.8) | 0.82% | — | Podsfoundation Pods | 9/4/2024 | 17/6/2026 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Modificada | Media (4.3) | 0.55% | — | Podsfoundation Pods | 9/4/2024 | 17/6/2026 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the use of a file inclusion feature via shortcode. This makes it… | |
| Modificada | Media (5.4) | 8.2% | — | Apple Airpods Firmware | 23/6/2023 | 17/6/2026 | An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 5E133. When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to… | |
| Modificada | Alta (8.8) | 0.26% | — | Podsfoundation Pods | 3/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods – Custom Content Types and Fields plugin <= 2.9.10.2 versions. | |
| Modificada | Media (5.4) | 0.84% | — | Panda Pods Repeater Field Project Panda Pods Repeater Field | 30/1/2023 | 17/6/2026 | The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission. | |
| Modificada | Media (6.3) | 3.1% | — | Snyk CLISnyk Cocoapods CLISnyk Docker CLISnyk Gradle CLI+4 | 30/11/2022 | 17/6/2026 | The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-python-plugin before 1.24.2; the package snyk-docker-plugin before 5.6.5; the… | |
| Modificada | Crítica (9.8) | 2.6% | — | Cocoapods-downloader | 1/4/2022 | 17/6/2026 | The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional… | |
| Modificada | Crítica (9.8) | 1.7% | — | Cocoapods-downloader | 1/4/2022 | 17/6/2026 | The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to… |