Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.43% | — | Kaizencoders Short URL | 6/6/2025 | 17/6/2026 | The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers. | |
| Aplazada | Media (5.4) | 0.35% | — | Kaizencoders Short URLAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in KaizenCoders Short URL shorten-url allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Short URL: from n/a through <= 1.6.8. | |
| Aplazada | Media (4.7) | 0.18% | — | Short URLAI | 17/8/2024 | 17/6/2026 | The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. This is due to missing or incorrect nonce validation on the configuration_page function. This makes it possible for unauthenticated attackers to add and import redirects, including comments… | |
| Aplazada | Media (5.3) | 0.34% | — | Jsy-1 Short-urlAI | 26/5/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in jsy-1 short-url 1.0.0. Affected is an unknown function of the file admin.php. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.0.0 is able to address this issue. The name… | |
| Modificada | Media (6.1) | 0.35% | — | Kaizencoders Short URL | 15/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Short URL allows Reflected XSS.This issue affects Short URL: from n/a through 1.6.8. | |
| Modificada | Crítica (9.8) | 0.69% | — | Kaizencoders Short URL | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaizenCoders Short URL allows SQL Injection.This issue affects Short URL: from n/a through 1.6.4. | |
| Modificada | Alta (8.8) | 0.21% | — | Kaizencoders Short URL | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in KaizenCoders Short URL plugin <= 1.6.8 versions. | |
| Modificada | Media (4.8) | 0.50% | — | Kaizencoders Short URL | 31/7/2023 | 17/6/2026 | The Short URL WordPress plugin before 1.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.8) | 0.40% | — | Kaizencoders Short URL | 29/6/2023 | 17/6/2026 | The Short URL plugin for WordPress is vulnerable to stored Cross-Site Scripting via the 'comment' parameter due to insufficient input sanitization and output escaping in versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Modificada | Media (6.8) | 1.4% | — | Phpkobo Short URL | 23/3/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1) url/app/common.inc.php and (2) codelib/cfg/common.inc.php. NOTE: the… | |
| Modificada | Media (6.8) | 1.9% | — | Phpkobo Short URL | 23/3/2010 | 16/6/2026 | Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter. | |
| Modificada | Alta (7.5) | 1.00% | — | Junglescripts Ajax Short URL Script | 18/3/2010 | 16/6/2026 | SQL injection vulnerability in x/login in JungleScripts Ajax Short Url Script allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Alta (7.5) | 2.4% | — | Desiscripts Desi Short URL Script | 28/7/2009 | 16/6/2026 | index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to 1 and the uid cookie to an integer value, as demonstrated by a value of 13. | |
| Modificada | Alta (7.5) | 1.3% | — | Yourfreeworld Short URL AND URL Tracker Script | 21/8/2008 | 16/6/2026 | SQL injection vulnerability in tr.php in YourFreeWorld Short Url & Url Tracker Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (10) | 3.8% | — | Plusphp Short URL Multi-user Script | 28/5/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the _pages_dir parameter. | |
| Modificada | Alta (10) | 2.3% | — | Short URLURL Tracker Script | 11/12/2006 | 16/6/2026 | Yourfreeworld.com Short Url & Url Tracker Script allows remote attackers to obtain sensitive information via an invalid id parameter to login.php, which leaks the path in an error message. NOTE: this issue might be resultant from CVE-2006-2509. | |
| Modificada | Media (6.8) | 1.3% | — | Yourfreeworld Short URL AND URL Tracker Script | 22/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the URL submission form in YourFreeWorld.com Short Url & Url Tracker Script allows remote attackers to inject arbitrary web script or HTML via an unspecified form for submitting URLs. | |
| Modificada | Alta (7.5) | 1.1% | — | Yourfreeworld Short URL AND URL Tracker Script | 22/5/2006 | 16/6/2026 | SQL injection vulnerability in login.php in YourFreeWorld.com Short Url & Url Tracker Script allows remote attackers to execute arbitrary SQL commands via the id parameter. |