Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.13% | — | VM Menu ReorderAI | 27/9/2025 | 17/6/2026 | The VM Menu Reorder plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the vm_set_to_default function. This makes it possible for unauthenticated attackers to reset all menu reordering settings via… | |
| Aplazada | Media (6.1) | 0.18% | — | Advanced Reorder Image Text SliderAI | 3/5/2025 | 17/6/2026 | The Advanced Reorder Image Text Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'reorder-simple-image-text-slider-setting' page. This makes it possible for unauthenticated attackers to update… | |
| Aplazada | Media (4.3) | 0.24% | — | Vagonic Woocommerce Products Reorder Drag Drop Multiple SortAI | 10/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Vagonic Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic vagonic-sortable.This issue affects Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic: from n/a through <= 1.9. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Fmemodules PreorderandnoticationAI | 29/4/2024 | 17/6/2026 | SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbitrary SQL commands via the PreorderModel::getIdProductAttributesByIdAttributes() method. | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Cancel Order Request / Return Order / Repeat Order / Reorder FOR Woocommerce | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Cancel order request / Return order / Repeat Order / Reorder for WooCommerce plugin <= 1.3.2 versions. | |
| Modificada | Alta (7.3) | 0.90% | — | Reorder Project Reorder | 1/4/2021 | 17/6/2026 | An issue was discovered in the reorder crate through 2021-02-24 for Rust. swap_index can return uninitialized values if an iterator returns a len() that is too large. | |
| Modificada | Alta (7.3) | 0.90% | — | Reorder Project Reorder | 1/4/2021 | 17/6/2026 | An issue was discovered in the reorder crate through 2021-02-24 for Rust. swap_index has an out-of-bounds write if an iterator returns a len() that is too small. | |
| Modificada | Media (6.8) | 0.98% | — | Commerceguys Commerce Reorder | 31/8/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that add items to the shopping cart. |