Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.15% | — | Samsung SettingsAI | 10/7/2026 | 10/7/2026 | Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings. | |
| Analizada | Media (5.3) | 0.18% | — | Pydantic-settings | 6/7/2026 | 27/7/2026 | pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files in a configured secrets_dir. When secrets_nested_subdir=True, a directory entry inside secrets_dir that is a symbolic link pointing outside secrets_dir is followed, so… | |
| Aplazada | Media (6.4) | 0.32% | — | Extra Settings FOR RocketchatAI | 9/6/2026 | 23/7/2026 | The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat' shortcode's 'title' attribute in versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping in the rxstg_shortcode() function, which concatenates the… | |
| Aplazada | Media (6.1) | 0.37% | — | Blog SettingsAI | 5/5/2026 | 17/6/2026 | The Blog Settings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (4.3) | 0.18% | — | Xhanch MY Advanced SettingsAI | 21/3/2026 | 17/6/2026 | The Xhanch - My Advanced Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing nonce validation in the `xms_setting()` function on the settings update handler. This makes it possible for unauthenticated attackers to modify plugin… | |
| Aplazada | Alta (7.2) | 0.70% | — | Easy PHP SettingsAI | 7/3/2026 | 17/6/2026 | The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0.4 via the `update_wp_memory_constants()` method. This is due to insufficient input validation on the `wp_memory_limit` and `wp_max_memory_limit` settings before writing them to `wp-config.php`. The… | |
| Aplazada | Crítica (9.1) | 0.42% | — | Helmut Wandl Advanced SettingsAI | 6/11/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Upload a Web Shell to a Web Server.This issue affects Advanced Settings: from n/a through <= 3.1.1. | |
| Aplazada | Media (4.3) | 0.12% | — | Helmut Wandl Advanced SettingsAI | 9/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Request Forgery.This issue affects Advanced Settings: from n/a through <= 3.1.1. | |
| Aplazada | Media (6.9) | 0.10% | — | Android TvsettingsAI | 31/7/2025 | 17/6/2026 | There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied activity in Settings’ context, i.e. system-uid context, thus lead to launchAnyWhere. The core idea is to utilize the time window between the check of Intent and the use to Intent to change the target… | |
| Aplazada | Alta (7.1) | 0.13% | — | Esselink.nu SettingsAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Esselink.nu Esselink.nu Settings esselinknu-settings allows Reflected XSS.This issue affects Esselink.nu Settings: from n/a through <= 4.5. | |
| Aplazada | Media (4.3) | 0.14% | — | Helmut Wandl Advanced SettingsAI | 17/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Request Forgery.This issue affects Advanced Settings: from n/a through <= 3.0.1. | |
| Aplazada | Alta (7.1) | 0.26% | — | Fures Xtra-settingsAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fures XTRA Settings xtra-settings allows Reflected XSS.This issue affects XTRA Settings: from n/a through <= 2.1.8. | |
| Aplazada | Alta (8.8) | 0.56% | — | Knowhalim KH Easy User SettingsAI | 16/12/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Knowhalim KH Easy User Settings kh-easy-user-settings allows Privilege Escalation.This issue affects KH Easy User Settings: from n/a through <= 1.0.0. | |
| Analizada | Media (6.6) | 0.75% | — | Geomywp GEO MY WordpressGeomywp GEO MY Wordpress Premium Settings | 22/11/2024 | 17/6/2026 | The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server. | |
| Aplazada | Alta (8.8) | 0.23% | — | Skipstorm SK WP Settings BackupAI | 16/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object Injection.This issue affects SK WP Settings Backup: from n/a through <= 1.0. | |
| Analizada | Media (5.4) | 0.26% | — | Miguelmello Aggregator Advanced Settings | 4/10/2024 | 17/6/2026 | The Aggregator Advanced Settings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Aplazada | Alta (7.5) | 0.38% | — | Promokit PK ThemesettingsAIPrestashopAI | 24/6/2024 | 17/6/2026 | In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. Due to a lack of permissions control, a guest can access the txt file which collect email when maintenance is enable which can lead to leak of personal… | |
| Modificada | Crítica (9.8) | 0.56% | — | Promokit PK Themesettings | 19/6/2024 | 17/6/2026 | In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Aplazada | Media (4.3) | 0.32% | — | Gnome Settings DaemonAILinux KernelAI | 16/6/2024 | 17/6/2026 | Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem… | |
| Aplazada | Alta (7.2) | 0.17% | — | B&R Industrial Automation Scene ViewerAIB&R Industrial Automation Mapp VisionAIB&R Industrial Automation Mapp ViewAIB&R Industrial Automation Mapp CockpitAI+21 | 14/5/2024 | 17/6/2026 | An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation… | |
| Modificada | Media (5.4) | 0.43% | — | Porternovelli Widget Settings Importer/exporter | 23/12/2023 | 17/6/2026 | The Widget Settings Importer/Exporter Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp_ajax_import_widget_dataparameter AJAX action in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with… | |
| Modificada | Media (4.3) | 0.46% | — | Brainstormforce Import / Export Customizer Settings | 1/7/2023 | 17/6/2026 | The Import / Export Customizer Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the astra_admin_errors() function. This makes it possible for unauthenticated attackers to display an import status… | |
| Modificada | Media (4.8) | 0.37% | — | Upload File Type Settings Plugin Project Upload File Type Settings Plugin | 26/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sebastian Krysmanski Upload File Type Settings plugin <= 1.1 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Wordpress Custom Settings Project Wordpress Custom Settings | 23/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Davinder Singh Custom Settings plugin <= 1.0 versions. | |
| Modificada | Alta (7.8) | 0.17% | — | NEC PC Settings Tool | 15/2/2023 | 17/6/2026 | PC settings tool Ver10.1.26.0 and earlier, PC settings tool Ver11.0.22.0 and earlier allows a attacker to write to the registry as administrator privileges with standard user privileges. |