Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.67%💥 PoCMiniorange OTP Login Verification SMS NotificationsAI26/9/202628/9/2026
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the…
AplazadaCrítica (9.8)1.1%—Miniorange OTP Login Verification AND SMS NotificationsAI9/7/20269/7/2026
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_password_process_hook()` function performing no server-side verification that the…
AplazadaMedia (5.3)0.27%—Miniorange OTP Verification SMS NotificationAI10/1/202617/6/2026
The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `enable_wc_sms_notification` AJAX action in all versions up to, and including, 4.3.8. This makes it possible for unauthenticated…
AplazadaCrítica (9.3)0.40%—Sslplugins SSL Wireless SMS NotificationAI7/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sslplugins SSL Wireless SMS Notification ssl-wireless-sms-notification allows SQL Injection.This issue affects SSL Wireless SMS Notification: from n/a through <= 3.5.0.
AplazadaCrítica (9.8)0.47%—Sslplugins SSL Wireless SMS NotificationAI31/12/202417/6/2026
Incorrect Privilege Assignment vulnerability in sslplugins SSL Wireless SMS Notification ssl-wireless-sms-notification allows Privilege Escalation.This issue affects SSL Wireless SMS Notification: from n/a through <= 3.6.0.
ModificadaCrítica (9.8)0.90%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification27/10/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=.
ModificadaAlta (7.2)1.0%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification16/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=.
ModificadaAlta (7.2)1.0%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification16/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=.
ModificadaAlta (7.2)1.0%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification16/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=.
ModificadaAlta (7.2)0.88%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification8/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/modstudent/index.php?view=edit&id=.
ModificadaAlta (7.2)0.88%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification8/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/autonumber/index.php?view=edit&id=.
ModificadaAlta (7.2)0.88%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification8/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/user/index.php?view=edit&id=.
ModificadaAlta (8)0.91%—Ultimatesmsnotifications Ultimate SMS Notifications FOR Woocommerce6/9/202217/6/2026
The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the 'Export Utility' functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First…
ModificadaBaja (3.3)0.34%—Jenkins SMS Notification8/10/202017/6/2026
Jenkins SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Orbitaley — Vulnerabilidades