Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.39% | — | Taskingai QR Code GeneratorAI | 2/10/2026 | 2/10/2026 | In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter. | |
| Aplazada | Media (5.9) | 0.16% | — | Devsbrain Flex QR Code GeneratorAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Devsbrain Flex QR Code Generator flex-qr-code-generator allows DOM-Based XSS.This issue affects Flex QR Code Generator: from n/a through <= 1.2.10. | |
| Aplazada | Crítica (9.8) | 0.73% | — | Flex QR Code GeneratorAI | 6/12/2025 | 17/6/2026 | The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_qr_code() function in all versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which… | |
| Aplazada | Crítica (9.8) | 0.92% | — | Flex QR Code GeneratorAI | 15/10/2025 | 17/6/2026 | The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in thesave_qr_code_to_db() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which… | |
| Aplazada | Media (6.5) | 0.37% | — | Luke America WCS QR Code GeneratorAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luke America WCS QR Code Generator wcs-qr-code-generator allows Stored XSS.This issue affects WCS QR Code Generator: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.37% | — | Mobstac QR Code GeneratorAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mobstac QR Code Generator qrcode-wprhe allows DOM-Based XSS.This issue affects QR Code Generator: from n/a through <= 1.2.6. | |
| Modificada | Media (6.1) | 0.51% | — | Code-projects QR Code Generator | 29/12/2023 | 17/6/2026 | A vulnerability was found in code-projects QR Code Generator 1.0. It has been classified as problematic. This affects an unknown part of the file /download.php?file=author.png. The manipulation of the argument file with the input "><iMg src=N onerror=alert(document.domain)> leads to cross site scripting. It is… | |
| Modificada | Media (6.1) | 0.46% | — | Sosidee Dynamic QR Code Generator | 30/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rakib Hasan Dynamic QR Code Generator plugin <= 0.0.5 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Kayastudio Kaya QR Code Generator | 16/8/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kaya Studio Kaya QR Code Generator plugin <= 1.5.2 versions. | |
| Modificada | Alta (7.5) | 1.5% | — | QR Code Generator Project QR Code Generator | 25/7/2022 | 9/7/2026 | A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal. |