Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.41% | — | Afrfq Request A Quote FOR WoocommerceAI | 26/9/2026 | 28/9/2026 | The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied… | |
| Aplazada | Media (6.5) | 0.28% | — | Yith Woocommerce Request A QuoteAI | 23/9/2026 | 23/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n/a before 4.46.1. | |
| Aplazada | Baja (3.7) | 0.22% | — | NP Quote RequestAI | 23/9/2026 | 23/9/2026 | The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key. | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Request-filtering-agentAI | 22/9/2026 | 25/9/2026 | request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rejecting a literal private-IP host such as 169.254.169.254 or 127.0.0.1. Because… | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | Jenkins Bitbucket Push AND Pull RequestAI | 16/9/2026 | 18/9/2026 | Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload. | |
| Aplazada | Alta (8.6) | 0.40% | — | Elex Woocommerce Request A QuoteAI | 9/9/2026 | 9/9/2026 | The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary data from the database. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Yith Request A Quote FOR WoocommerceAI | 3/9/2026 | 7/9/2026 | Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | Piweb Cancel Order Refund RequestAI | 9/8/2026 | 26/8/2026 | The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previous order to the cart, allowing unauthenticated users to disclose the contents of other customers' orders, as well as to clear and repopulate a… | |
| Aplazada | Media (5.3) | 0.40% | — | Klubraum Membership RequestAI | 29/7/2026 | 30/7/2026 | The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `kr_mr_store_settings()` function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update the plugin's settings, including… | |
| Analizada | Crítica (9.1) | 0.41% | — | Bestpractical Request Tracker | 20/7/2026 | 7/8/2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to… | |
| Analizada | Media (6.1) | 0.26% | — | Bestpractical Request Tracker | 20/7/2026 | 7/8/2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT user to visit a crafted URL can execute… | |
| Analizada | Media (5.4) | 0.24% | — | Bestpractical Request Tracker | 20/7/2026 | 18/8/2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include… | |
| Analizada | Media (5.4) | 0.26% | — | Bestpractical Request Tracker | 20/7/2026 | 7/8/2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML escaping. An authenticated user with permission to set the relevant data can inject… | |
| Analizada | Media (6.1) | 0.26% | — | Bestpractical Request Tracker | 20/7/2026 | 7/8/2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session.… | |
| Aplazada | Alta (7.5) | 0.56% | — | Emarketdesign Request A QuoteAI | 2/7/2026 | 2/7/2026 | The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the emd_delete_file AJAX action. This is due to the emd_delete_file() handler deriving a PHP function name from the attacker-controlled $_POST['path'] parameter and invoking it dynamically via the… | |
| Analizada | Media (4.8) | 0.16% | — | Jenkins Bitbucket Push AND Pull Request | 24/6/2026 | 26/6/2026 | Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token. | |
| Analizada | Media (5.1) | 0.40% | — | Bestpractical Request Tracker | 21/5/2026 | 23/7/2026 | Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victim’s browser. This vulnerability affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up… | |
| Aplazada | Media (6.5) | 0.39% | — | Requests-hardenedAI | 12/5/2026 | 17/6/2026 | requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security features. Prior to , the SSRF protection in requests-hardened fails to block IP addresses within the RFC 6598 Shared Address Space (100.64.0.0/10). An attacker who can supply arbitrary URLs to… | |
| Analizada | Media (5.5) | 0.18% | — | Python Requests | 25/3/2026 | 17/6/2026 | Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write… | |
| Aplazada | Media (6.4) | 0.34% | — | Dealia Request A QuoteAI | 19/2/2026 | 17/6/2026 | The Dealia – Request a Quote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gutenberg block attributes in all versions up to, and including, 1.0.8. This is due to the use of `wp_kses()` for output escaping within HTML attribute contexts where `esc_attr()` is required. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.22% | — | Dealia Request A QuoteAI | 19/2/2026 | 17/6/2026 | The Dealia – Request a quote plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on multiple AJAX handlers in all versions up to, and including, 1.0.7. The admin nonce (DEALIA_ADMIN_NONCE) is exposed to all users with edit_posts capability (Contributor+) via… | |
| Aplazada | Media (5.3) | 0.22% | — | Yithemes Yith Woocommerce Request A QuoteAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in YITHEMES YITH WooCommerce Request A Quote yith-woocommerce-request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Request A Quote: from n/a through <= 2.46.0. | |
| Aplazada | Baja (2.6) | 0.22% | — | Bestpractical Request TrackerAI | 16/1/2026 | 17/6/2026 | Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used. | |
| Aplazada | Media (4.3) | 0.22% | — | Emarketdesign Request A QuoteAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in emarket-design Request a Quote request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Request a Quote: from n/a through <= 2.5.3. | |
| Aplazada | Alta (8.7) | 0.35% | — | Request Serious Play Media PlayerAI | 5/12/2025 | 17/6/2026 | ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files from local resources. |