Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

46 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8)0.23%—Bulk Password ResetAI10/9/202610/9/2026
The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a…
AplazadaMedia (5.1)0.31%—Milkdown Preset CommonmarkAITennisconnect ComponentsAI24/7/202627/7/2026
Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rendered link. The…
AplazadaMedia (4.3)0.13%—Andy Moyle Emergency Password ResetAI17/6/20261/10/2026
Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0.
AplazadaMedia (6.5)0.15%—Jcaruso001 Flaming-password-resetAI8/1/20265/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jcaruso001 Flaming Password Reset flaming-password-reset allows Stored XSS.This issue affects Flaming Password Reset: from n/a through <= 1.0.3.
AplazadaMedia (5.3)0.31%—Webfactoryltd WP ResetAI7/10/202517/6/2026
The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::log() method when debugging is enabled (default). This makes it possible for unauthenticated attackers to extract sensitive license key and site data.
AplazadaMedia (4.3)0.17%—Andy Moyle Emergency Password ResetAI22/9/202530/9/2026
Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Emergency Password Reset emergency-password-reset allows Cross Site Request Forgery.This issue affects Emergency Password Reset: from n/a through <= 9.3.
AplazadaCrítica (9.8)0.24%—Bedevious Password Reset With Code FOR Wordpress Rest APIAI18/9/202517/6/2026
The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.
AplazadaAlta (7.3)0.34%—Opentext Self Service Password ResetAI29/8/202517/6/2026
Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Authentication Bypass.This issue affects Self Service Password Reset from before 4.8 patch 3.
AplazadaMedia (4.3)0.20%—Liquidthemes Liquid Reset Wordpress BeforeAI28/8/202517/6/2026
Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capability check on the liquid_reset_wordpress_before AJAX in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate all of a site's…
AnalizadaMedia (4.3)0.18%—Gamipress - Reset User15/5/202517/6/2026
The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
AnalizadaMedia (4.3)0.18%—Justintadlock Widgets Reset15/5/202517/6/2026
The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaAlta (8.1)0.22%—Smartzminds Reset18/2/202517/6/2026
The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the reset_db_page() function. This makes it possible for unauthenticated attackers to reset several tables in the database like comments, themes,…
AplazadaAlta (7.1)0.27%—Techdabang User Password ResetAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techdabang User Password Reset user-password-reset allows Reflected XSS.This issue affects User Password Reset: from n/a through <= 1.0.
AnalizadaMedia (6.1)0.32%—Microfocus Netiq Self Service Password Reset21/8/202417/6/2026
Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Cross-Site Scripting (XSS). This issue affects Self Service Password Reset before 4.5.0.2 and 4.4.0.6
AplazadaBaja (2.9)0.15%—HCL Dryice Optibot Reset StationAI14/6/202417/6/2026
HCL DRYiCE Optibot Reset Station is impacted by an Unused Parameter in the web application.
AplazadaBaja (3.7)0.20%—HCL Dryice Optibot Reset StationAI14/6/202417/6/2026
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during redirection.
ModificadaMedia (4.3)0.28%—Webfactoryltd WP Reset8/6/202417/6/2026
The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_ajax function in all versions up to, and including, 2.02. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the value fo the 'License…
AplazadaMedia (6.5)0.15%—HCL Dryice Optibot Reset StationAI28/5/202417/6/2026
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to recover some or all encrypted values.
AplazadaMedia (6.5)0.15%—HCL Dryice Optibot Reset StationAI28/5/202417/6/2026
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker with access to the database to recover some or all encrypted values.
ModificadaMedia (5.9)0.70%—Webfactoryltd WP Reset9/4/202417/6/2026
The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0 via the use of insufficiently random snapshot names. This makes it possible for unauthenticated attackers to extract sensitive data including site backups by…
ModificadaMedia (4.7)0.27%—Webfactoryltd WP Database Reset21/2/202417/6/2026
The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing or incorrect nonce validation on the install_wpr() function. This makes it possible for unauthenticated attackers to install the WP Reset Plugin via a forged request…
ModificadaCrítica (9.8)1.1%—Bedevious Password Reset With Code FOR Wordpress Rest API7/12/202317/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15.
ModificadaAlta (8.8)0.52%—Debian LinuxBabeljs BabelBabeljs Babel-helper-define-polyfill-providerBabeljs Babel-plugin-polyfill-corejs2+512/10/202317/6/2026
Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the…
ModificadaAlta (8.8)1.9%—Bytedeco Javacpp Presets9/6/202317/6/2026
JavaCPP Presets is a project providing Java distributions of native C++ libraries. All the actions in the `bytedeco/javacpp-presets` use the `github.event.head_commit.message​` parameter in an insecure way. For example, the commit message is used in a run statement - resulting in a command injection vulnerability due…
ModificadaMedia (6.1)0.68%—Sigmaplugin Advanced Wordpress Reset1/8/202217/6/2026
The Advanced WordPress Reset WordPress plugin before 1.6 does not escape some generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting