Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
2136 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.5) | 0.36% | — | Semperfiwebdesign ALL IN ONE SEOAI | 3/10/2026 | 3/10/2026 | The The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.2 This is due to the software allowing users to execute an action that does not properly… | |
| Aplazada | Media (5.3) | 0.21% | — | Emarketdesign Request A QuoteAI | 2/10/2026 | 2/10/2026 | The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published. | |
| Aplazada | Crítica (9.8) | 0.30% | — | Oauth Single Sign ON SSOAI | 30/9/2026 | 30/9/2026 | Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. | |
| Aplazada | Alta (8.8) | 0.36% | — | DesignsetgoAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions. | |
| Aplazada | Alta (7.2) | 0.40% | — | Kadencewp Kadence Woocommerce Email DesignerAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. | |
| Aplazada | Alta (7.5) | 0.90% | — | Product Designer APPAI | 30/9/2026 | 30/9/2026 | The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The… | |
| Aplazada | Alta (8.8) | 0.29% | — | Innotim Logsign SiemAI | 28/9/2026 | 28/9/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117. | |
| Aplazada | Alta (7.1) | 0.28% | — | Innotim Logsign SiemAI | 28/9/2026 | 28/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Path Traversal. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117. | |
| Aplazada | Crítica (9.8) | 0.27% | — | Innotim Software Telecommunications AND Consultancy Trade Logsign SiemAI | 28/9/2026 | 28/9/2026 | Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117. | |
| Aplazada | Alta (7.2) | 0.27% | — | Radykal Fancy Product DesignerAI | 25/9/2026 | 25/9/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Alta (7.2) | 0.21% | — | Radykal Fancy Product DesignerAI | 25/9/2026 | 25/9/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Alta (7.2) | 0.19% | — | Radykal Fancy Product DesignerAI | 25/9/2026 | 25/9/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (7.6) | 0.35% | — | SignozAI | 24/9/2026 | 24/9/2026 | SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), do not revoke a user's existing login sessions when the user's password is reset with a reset token (UpdatePasswordByResetPasswordToken, reachable via POST… | |
| Aplazada | Crítica (9.2) | 0.41% | — | SignozAI | 24/9/2026 | 24/9/2026 | SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty value, so a deployment that does not configure a secret starts up and both… | |
| Aplazada | Media (6.5) | 0.17% | — | Etoilewebdesign Ultimate FAQAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions. | |
| Aplazada | Alta (8.6) | 3.2% | — | Changing CgservisignAI | 23/9/2026 | 24/9/2026 | CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer. | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | Adobe IndesignAI | 22/9/2026 | 25/9/2026 | InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must… | |
| Pendiente de análisis | Media (5.5) | 0.18% | — | Adobe IndesignAI | 22/9/2026 | 22/9/2026 | InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must… | |
| Aplazada | Crítica (9.8) | 0.55% | — | WEB TO Print Online DesignerAI | 21/9/2026 | 21/9/2026 | The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server. | |
| Aplazada | Media (4.3) | 0.14% | — | Fetchdesigns Sign-up SheetsAI | 20/9/2026 | 21/9/2026 | The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability. | |
| Aplazada | Alta (8.1) | 0.37% | — | Saml Single Sign ONAI | 20/9/2026 | 21/9/2026 | The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a… | |
| Aplazada | Alta (7.5) | 0.94% | — | Printcart WEB TO Print Product DesignerAI | 18/9/2026 | 18/9/2026 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain… | |
| Pendiente de análisis | Alta (8.4) | 0.50% | — | SignozAI | 17/9/2026 | 22/9/2026 | SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and string literals, executing arbitrary… | |
| Pendiente de análisis | Alta (8.4) | 0.40% | — | SignozAI | 17/9/2026 | 22/9/2026 | SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Headless Single Sign ONAI | 17/9/2026 | 17/9/2026 | Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions. |