Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.6) | 0.43% | — | ShuffleAI | 16/9/2026 | 24/9/2026 | Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations. Attackers with admin privileges in one organization can supply arbitrary user IDs to generate… | |
| Aplazada | Alta (8.1) | 0.47% | — | ShuffleAI | 20/8/2026 | 5/10/2026 | Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. | |
| Aplazada | Media (5.4) | 0.14% | — | Shufflehound LemmonyAI | 13/3/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in shufflehound Lemmony lemmony allows Cross Site Request Forgery.This issue affects Lemmony: from n/a through < 1.7.1. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Wpshuffle Subscribe TO DownloadAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in wpshuffle Subscribe to Download subscribe-to-download allows Object Injection.This issue affects Subscribe to Download: from n/a through <= 2.0.9. | |
| Aplazada | Media (4.3) | 0.19% | — | Wpshuffle WP Subscription Forms PROAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in wpshuffle WP Subscription Forms PRO wp-subscription-forms-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Subscription Forms PRO: from n/a through <= 2.0.5. | |
| Aplazada | Alta (7.5) | 0.48% | — | Wpshuffle Subscribe TO UnlockAI | 26/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpshuffle Subscribe To Unlock subscribe-to-unlock allows PHP Local File Inclusion.This issue affects Subscribe To Unlock: from n/a through <= 1.1.5. | |
| Aplazada | Media (4.3) | 0.24% | — | Wpshuffle Subscribe TO UnlockAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in wpshuffle Subscribe To Unlock subscribe-to-unlock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe To Unlock: from n/a through <= 1.1.5. | |
| Aplazada | Alta (7.5) | 0.48% | — | Wpshuffle Subscribe TO DownloadAI | 26/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpshuffle Subscribe to Download subscribe-to-download allows PHP Local File Inclusion.This issue affects Subscribe to Download: from n/a through <= 2.0.9. | |
| Aplazada | Media (4.3) | 0.24% | — | Wpshuffle Subscribe TO DownloadAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in wpshuffle Subscribe to Download subscribe-to-download allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe to Download: from n/a through <= 2.0.9. | |
| Aplazada | Media (5.4) | 0.39% | — | Wpshuffle WP Subscription FormsAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Shuffle WP Subscription Forms wp-subscription-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Subscription Forms: from n/a through <= 1.2.3. | |
| Aplazada | Alta (7.5) | 0.89% | — | Wpshuffle WP Subscription FormsAI | 9/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle WP Subscription Forms wp-subscription-forms allows PHP Local File Inclusion.This issue affects WP Subscription Forms: from n/a through <= 1.2.4. | |
| Aplazada | Alta (7.5) | 0.83% | — | WP Shuffle Subscribe TO Download LiteAI | 1/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Download Lite subscribe-to-download-lite allows PHP Local File Inclusion.This issue affects Subscribe to Download Lite: from n/a through <= 1.2.9. | |
| Aplazada | Alta (7.5) | 1.0% | — | Wpshuffle Subscribe TO Download LiteAI | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Download Lite subscribe-to-download-lite allows PHP Local File Inclusion.This issue affects Subscribe to Download Lite: from n/a through <= 1.2.9. | |
| Aplazada | Alta (8.5) | 0.46% | — | Wpshuffle WP Subscription FormsAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Shuffle WP Subscription Forms wp-subscription-forms allows SQL Injection.This issue affects WP Subscription Forms: from n/a through <= 1.2.3. | |
| Aplazada | Alta (8.5) | 0.55% | — | Scott Taylor ShuffleAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Scott Taylor Shuffle shuffle allows Blind SQL Injection.This issue affects Shuffle: from n/a through <= 0.5. | |
| Analizada | Media (4.3) | 0.32% | — | Wpshuffle Frontend Post Submission Manager | 6/9/2024 | 17/6/2026 | The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_global_settings and process_form_edit functions in all versions up to, and including, 1.2.2. This makes it possible for… |