Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

3356 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.2)0.24%—SeopressAI3/10/20263/10/2026
The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
RecibidaMedia (4.9)0.24%—SeopressAI3/10/20263/10/2026
The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'seopress_google_analytics_matomo_id' parameter in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
RecibidaMedia (6.4)0.20%—Wpdeveloper EmbedpressAI3/10/20263/10/2026
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slidesShow' Block Attribute in all versions up to, and including, 4.6.6 due to insufficient input sanitization and output escaping. This…
RecibidaMedia (6.1)0.22%—ProfilepressAI3/10/20263/10/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input…
RecibidaMedia (6.1)0.21%—Thimpress LearnpressAI3/10/20263/10/2026
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'orderby' parameter in all versions up to, and including, 4.4.7 due to insufficient input sanitization and output escaping. This makes it possible for…
RecibidaAlta (8.8)0.63%—ProfilepressAI3/10/20263/10/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated…
AplazadaMedia (4.3)0.15%—Thimpress LearnpressAI2/10/20262/10/2026
Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.4.9.1.
AplazadaMedia (5.4)0.18%—Publishpress SeriesAI2/10/20262/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Series: from n/a through 3.1.3.
AplazadaMedia (5.3)0.20%—Thimpress LearnpressAI2/10/20262/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LearnPress: from n/a through 4.4.9.
AplazadaMedia (6.1)0.15%—Giveaways AND Contests BY RafflepressAI2/10/20262/10/2026
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary…
AplazadaMedia (5.3)0.20%—Giveaways AND Contests BY RafflepressAI2/10/20262/10/2026
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.
AplazadaCrítica (9.3)0.24%—Wordpress File UploadAI1/10/20261/10/2026
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
AplazadaAlta (7.5)0.36%—Thimpress LearnpressAI1/10/20261/10/2026
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items() callback exposed on the public lp-ajax-handle (load_content_via_ajax) endpoint.…
AplazadaCrítica (10)0.31%—Backupsheep Wordpress Backup PluginAI1/10/20261/10/2026
The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files…
AplazadaAlta (7.5)0.29%—Wordpress Backup MigrationAI30/9/202630/9/2026
Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.
AplazadaAlta (7.5)0.25%—Tipsandtricks-hq WP Express CheckoutAI30/9/202630/9/2026
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.
AplazadaAlta (8.5)0.26%—GamipressAI30/9/202630/9/2026
Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.
AplazadaAlta (7.1)0.18%—Wordpress Persistent Login Persistent LoginAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
AplazadaMedia (6.4)0.19%—ReactpressAI30/9/202630/9/2026
The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.8)0.24%—Wpdeveloper EmbedpressAI30/9/202630/9/2026
The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.
Pendiente de análisisMedia (6.3)0.16%—Expresslogic Netx Secure TLSAI29/9/202629/9/2026
NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is…
Pendiente de análisisMedia (6.9)0.25%—Expresslogic Netx DUOAI29/9/202629/9/2026
A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose…
Pendiente de análisisMedia (5.3)0.15%—Expresslogic Netx DUOAI29/9/202629/9/2026
A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of the received message. The option walk keeps a pointer and an offset in step, and the only bound check uses the offset: ```c /* addons/dhcp/nxd_dhcp_client.c:7538, 7572 */ while (i < length - 1)…
Pendiente de análisisAlta (8.7)0.31%—Expresslogic Netx DUOAI29/9/202629/9/2026
hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNMP packet with a multibyte OID length larger than the available buffer, causing the…
Pendiente de análisisAlta (7.1)0.15%—Expresslogic Netx DUOAI29/9/202629/9/2026
Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table stores each name in a slot rounded up to a multiple of four: ```c /* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */ ... len = *((USHORT*)(p - 2)); /* slot size, not string length */ if ((len…