Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.31%—SC Internet Vivoo WP RentalsAI4/9/20264/9/2026
Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Rentals: from n/a before 3.16.0.
RechazadaSin puntuar——6storage RentalsAI24/8/202624/8/2026
Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability in the 6Storage Rentals WordPress plugin. All CVE users should reference CVE-2026-15303 instead of this ID.
AplazadaCrítica (9.8)0.84%—6storage RentalsAI15/8/202620/8/2026
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification,…
AplazadaAlta (7.5)0.67%—6storage RentalsAI9/6/202623/7/2026
The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.0 via the `userId` parameter of the `six_storage_get_user_info` and `six_storage_update_profile` AJAX actions. This is due to the `six_storage_getUserInfo()` and…
AplazadaMedia (5.4)0.19%—6storage RentalsAI24/12/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Request Forgery.This issue affects 6Storage Rentals: from n/a through <= 2.22.0.
AplazadaMedia (4.3)0.13%—Wprentals WP RentalsAI29/10/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WpEstate WP Rentals wprentals allows Cross Site Request Forgery.This issue affects WP Rentals: from n/a through <= 3.13.1.
AplazadaMedia (6.5)0.21%—Wpestate WP RentalsAI14/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpEstate WP Rentals wprentals allows Stored XSS.This issue affects WP Rentals: from n/a through <= 3.16.1.
AplazadaMedia (4.3)0.28%—6storage RentalsAI6/6/202517/6/2026
Missing Authorization vulnerability in 6Storage 6Storage Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects 6Storage Rentals: from n/a through 2.19.5.
AplazadaMedia (6.5)0.38%—6storage RentalsAI23/5/202517/6/2026
Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Path Traversal.This issue affects 6Storage Rentals: from n/a through <= 2.20.2.
AplazadaMedia (5.4)0.49%—6storage RentalsAI4/4/202517/6/2026
Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 6Storage Rentals: from n/a through <= 2.20.2.
ModificadaCrítica (9.8)0.91%—About-rentals Project About-rentals6/9/202217/6/2026
Missing Access Control vulnerability in About Rentals. Inc. About Rentals plugin <= 1.5 at WordPress.
ModificadaAlta (7.5)1.1%—Miningrigrentalstoken Project Miningrigrentalstoken5/7/201817/6/2026
The mintToken function of a smart contract implementation for MiningRigRentals Token (MRR), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.0%—Commodityrentals DVD Rentals Script23/3/201116/6/2026
SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.
ModificadaAlta (7.5)1.0%—Hotwebscripts Hotweb Rentals16/2/201116/6/2026
SQL injection vulnerability in resorts.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropResort parameter.
ModificadaAlta (7.5)1.1%—Hotwebscripts Hotweb Rentals20/1/201116/6/2026
SQL injection vulnerability in default.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PageId parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)0.96%—Commodityrentals Vacation Rental Software2/3/201016/6/2026
SQL injection vulnerability in index.php in CommodityRentals Vacation Rental Software allows remote attackers to execute arbitrary SQL commands via the rental_id parameter in a CalendarView action.
ModificadaAlta (7.5)1.2%—Commodityrentals CD Rental Software2/3/201016/6/2026
SQL injection vulnerability in index.php in CommodityRentals CD Rental Software allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.
ModificadaAlta (7.5)1.2%—Commodityrentals Books/ebooks Rentals Script2/3/201016/6/2026
SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a gamecatalog action.
ModificadaAlta (7.5)1.0%—Commodityrentals Trade Manager Script23/2/201016/6/2026
SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaAlta (7.5)1.0%—Commodityrentals Video Games Rentals23/2/201016/6/2026
SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbitrary SQL commands via the pfid parameter in a catalog action.
ModificadaAlta (7.5)0.93%—Hotwebscripts Hotweb Rentals24/9/200916/6/2026
SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropId parameter.
ModificadaAlta (7.5)0.97%—Vacation Rentals Vacation Rental Script12/8/200816/6/2026
SQL injection vulnerability in index.php in Vacation Rental Script 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a sections action.
ModificadaBaja (2.6)1.3%—Vacation Rentals Vacation Rental Script30/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Vacation Rental Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the obj parameter.
ModificadaAlta (7.5)1.2%—Commodityrentals30/11/200516/6/2026
SQL injection vulnerability in usersession in CommodityRentals 2.0 Online Rental Business Creator script allows remote attackers to execute arbitrary SQL commands via the user_id parameter.