Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.31% | — | SC Internet Vivoo WP RentalsAI | 4/9/2026 | 4/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Rentals: from n/a before 3.16.0. | |
| Rechazada | Sin puntuar | — | — | 6storage RentalsAI | 24/8/2026 | 24/8/2026 | Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability in the 6Storage Rentals WordPress plugin. All CVE users should reference CVE-2026-15303 instead of this ID. | |
| Aplazada | Crítica (9.8) | 0.84% | — | 6storage RentalsAI | 15/8/2026 | 20/8/2026 | The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification,… | |
| Aplazada | Alta (7.5) | 0.67% | — | 6storage RentalsAI | 9/6/2026 | 23/7/2026 | The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.22.0 via the `userId` parameter of the `six_storage_get_user_info` and `six_storage_update_profile` AJAX actions. This is due to the `six_storage_getUserInfo()` and… | |
| Aplazada | Media (5.4) | 0.19% | — | 6storage RentalsAI | 24/12/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Request Forgery.This issue affects 6Storage Rentals: from n/a through <= 2.22.0. | |
| Aplazada | Media (4.3) | 0.13% | — | Wprentals WP RentalsAI | 29/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WpEstate WP Rentals wprentals allows Cross Site Request Forgery.This issue affects WP Rentals: from n/a through <= 3.13.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Wpestate WP RentalsAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpEstate WP Rentals wprentals allows Stored XSS.This issue affects WP Rentals: from n/a through <= 3.16.1. | |
| Aplazada | Media (4.3) | 0.28% | — | 6storage RentalsAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in 6Storage 6Storage Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects 6Storage Rentals: from n/a through 2.19.5. | |
| Aplazada | Media (6.5) | 0.38% | — | 6storage RentalsAI | 23/5/2025 | 17/6/2026 | Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Path Traversal.This issue affects 6Storage Rentals: from n/a through <= 2.20.2. | |
| Aplazada | Media (5.4) | 0.49% | — | 6storage RentalsAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 6Storage Rentals: from n/a through <= 2.20.2. | |
| Modificada | Crítica (9.8) | 0.91% | — | About-rentals Project About-rentals | 6/9/2022 | 17/6/2026 | Missing Access Control vulnerability in About Rentals. Inc. About Rentals plugin <= 1.5 at WordPress. | |
| Modificada | Alta (7.5) | 1.1% | — | Miningrigrentalstoken Project Miningrigrentalstoken | 5/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for MiningRigRentals Token (MRR), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.0% | — | Commodityrentals DVD Rentals Script | 23/3/2011 | 16/6/2026 | SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action. | |
| Modificada | Alta (7.5) | 1.0% | — | Hotwebscripts Hotweb Rentals | 16/2/2011 | 16/6/2026 | SQL injection vulnerability in resorts.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropResort parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Hotwebscripts Hotweb Rentals | 20/1/2011 | 16/6/2026 | SQL injection vulnerability in default.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PageId parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.96% | — | Commodityrentals Vacation Rental Software | 2/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in CommodityRentals Vacation Rental Software allows remote attackers to execute arbitrary SQL commands via the rental_id parameter in a CalendarView action. | |
| Modificada | Alta (7.5) | 1.2% | — | Commodityrentals CD Rental Software | 2/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in CommodityRentals CD Rental Software allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action. | |
| Modificada | Alta (7.5) | 1.2% | — | Commodityrentals Books/ebooks Rentals Script | 2/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a gamecatalog action. | |
| Modificada | Alta (7.5) | 1.0% | — | Commodityrentals Trade Manager Script | 23/2/2010 | 16/6/2026 | SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Commodityrentals Video Games Rentals | 23/2/2010 | 16/6/2026 | SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbitrary SQL commands via the pfid parameter in a catalog action. | |
| Modificada | Alta (7.5) | 0.93% | — | Hotwebscripts Hotweb Rentals | 24/9/2009 | 16/6/2026 | SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropId parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Vacation Rentals Vacation Rental Script | 12/8/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Vacation Rental Script 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a sections action. | |
| Modificada | Baja (2.6) | 1.3% | — | Vacation Rentals Vacation Rental Script | 30/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Vacation Rental Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the obj parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Commodityrentals | 30/11/2005 | 16/6/2026 | SQL injection vulnerability in usersession in CommodityRentals 2.0 Online Rental Business Creator script allows remote attackers to execute arbitrary SQL commands via the user_id parameter. |