Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.25% | — | Ecoal95 EC Stars RatingAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ecoal95 EC Stars Rating ec-stars-rating allows Stored XSS.This issue affects EC Stars Rating: from n/a through <= 1.0.11. | |
| Aplazada | Media (5.3) | 0.44% | — | Dash Labs YET Another Stars RatingAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Dash Labs Yet Another Stars Rating yet-another-stars-rating allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yet Another Stars Rating: from n/a through <= 3.4.3. | |
| Aplazada | Alta (8.5) | 0.40% | — | Saleswonder Team 5 Stars Rating FunnelAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.4.01. | |
| Aplazada | Media (5.3) | 0.30% | — | Saleswonder 5 Stars Rating FunnelAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.2.67. | |
| Aplazada | Alta (7.5) | 0.58% | — | Saleswonder 5 Stars Rating FunnelAI | 10/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.2.67. | |
| Modificada | Alta (8.1) | 0.40% | — | YET Another Stars Rating Project YET Another Stars Rating | 30/11/2023 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rating Plugin for WordPress.This issue affects YASR – Yet Another Star Rating Plugin for WordPress: from n/a through 3.3.8. | |
| Modificada | Media (6.1) | 0.38% | — | Yasr - YET Another Stars Rating Project Yasr - YET Another Stars Rating | 16/3/2023 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in Dario Curvino Yasr – Yet Another Stars Rating plugin <= 3.1.2 versions. | |
| Modificada | Crítica (9.8) | 1.7% | — | 5 Stars Rating Funnel Project 5 Stars Rating Funnel | 25/4/2022 | 17/6/2026 | The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an… | |
| Modificada | Media (6.1) | 0.80% | — | YET Another Stars Rating Project YET Another Stars Rating | 4/2/2022 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability discovered in Yasr – Yet Another Stars Rating WordPress plugin (versions <= 2.9.9), vulnerable at parameter 'source'. | |
| Modificada | Alta (7.5) | 1.6% | — | Stars Rating Project Stars Rating | 3/1/2022 | 17/6/2026 | The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated. | |
| Modificada | Alta (8.8) | 1.9% | — | YET Another Stars Rating Project YET Another Stars Rating | 10/10/2019 | 17/6/2026 | The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via the set_id parameter. |