Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.24% | — | Solace ExtraAI | 30/9/2026 | 30/9/2026 | The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve. | |
| Aplazada | Media (5.3) | 0.24% | — | Solace ExtraAI | 2/9/2026 | 3/9/2026 | The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to read the content of non-published (draft, pending, private, and trashed) Site Builder parts that WordPress would otherwise not serve. | |
| Aplazada | Crítica (9.1) | 0.60% | — | Solace ExtraAI | 16/8/2026 | 20/8/2026 | The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies… | |
| Aplazada | Alta (7.1) | 0.32% | — | Solace ExtraAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions. | |
| Aplazada | Media (4.3) | 0.14% | — | Solace ExtraAI | 9/8/2026 | 26/8/2026 | The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates. | |
| Aplazada | Alta (8.1) | 0.38% | — | Solace ExtraAI | 8/8/2026 | 26/8/2026 | The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported… | |
| Aplazada | Media (5.3) | 0.47% | — | Solace ExtraAI | 11/7/2026 | 13/7/2026 | The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete all content previously… | |
| Aplazada | Media (6.5) | 0.35% | — | Solacewp SolaceAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in solacewp Solace solace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Solace: from n/a through <= 2.1.16. | |
| Aplazada | Media (4.4) | 0.16% | — | Solacewp Solace ExtraAI | 27/8/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in solacewp Solace Extra solace-extra allows Server Side Request Forgery.This issue affects Solace Extra: from n/a through <= 1.3.2. | |
| Aplazada | Media (4.9) | 0.22% | — | Solacewp Solace ExtraAI | 7/5/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in solacewp Solace Extra solace-extra allows Server Side Request Forgery.This issue affects Solace Extra: from n/a through <= 1.3.1. | |
| Aplazada | Crítica (9.9) | 0.43% | — | Solacewp Solace ExtraAI | 17/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in solacewp Solace Extra solace-extra allows Using Malicious Files.This issue affects Solace Extra: from n/a through <= 1.3.1. | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. |