Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▲ 26 respecto a la semana anterior
Críticas / altas1468▲ 333 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.33% | — | Stilleshan ServerstatusAI | 13/9/2026 | 14/9/2026 | A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/main.cpp of the component Stats Generation. Performing a manipulation of the argument custom results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public… | |
| Aplazada | Media (5.3) | 0.40% | — | Openstatushq OpenstatusAI | 12/9/2026 | 15/9/2026 | A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts. The manipulation leads to server-side request forgery. The attack may be… | |
| Aplazada | Media (6.8) | 0.43% | — | Status301 CoolclockAI | 11/9/2026 | 11/9/2026 | The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed. | |
| Aplazada | Media (6.8) | 0.43% | — | Status301 CoolclockAI | 11/9/2026 | 11/9/2026 | The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes when the content is viewed. | |
| Aplazada | Media (4.8) | 0.24% | — | Ifeelweb Post Status Notifier LiteAI | 23/7/2026 | 23/7/2026 | The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are… | |
| Aplazada | Alta (7.5) | 0.46% | — | WOS Http Status ModuleAI | 27/5/2026 | 17/6/2026 | When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule function in the dll would be called to set up a "module" object for that module. However, WOSHttpStatusModule.dll is not present in the… | |
| Aplazada | Media (5.3) | 0.49% | — | OpenstatusAI | 8/4/2026 | 24/7/2026 | A vulnerability was detected in openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c. This impacts an unknown function of the file apps/dashboard/src/app/(dashboard)/onboarding/client.tsx of the component Onboarding Endpoint. The manipulation of the argument callbackURL results in cross site… | |
| Aplazada | Alta (8.5) | 0.18% | — | Epson Status MonitorAI | 28/1/2026 | 17/6/2026 | EPSON 1.124 contains an unquoted service path vulnerability in the SENADB service that allows local attackers to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\ to inject malicious executables that will run with… | |
| Aplazada | Alta (8.5) | 0.18% | — | Epson Status Monitor 3AI | 27/1/2026 | 17/6/2026 | EPSON Status Monitor 3 version 8.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can leverage the unquoted path in 'C:\Program Files\Common Files\EPSON\EPW!3SSRP\E_S60RPB.EXE' to inject malicious… | |
| Aplazada | Media (4.3) | 0.15% | — | WP Status NotifierAI | 7/1/2026 | 17/6/2026 | The WP Status Notifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin settings via a forged… | |
| Aplazada | Alta (7.1) | 0.11% | — | Page-carbajal Custom-post-statusAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in page-carbajal Custom Post Status custom-post-status allows Stored XSS.This issue affects Custom Post Status: from n/a through <= 1.1.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Weboccult Technologies PVT LTD Email Attachment BY Order Status ProductsAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weboccult Technologies Pvt Ltd Email Attachment by Order Status & Products email-attachment-by-order-status-products allows Reflected XSS.This issue affects Email Attachment by Order Status & Products: from n/a… | |
| Analizada | Media (6.1) | 0.36% | — | Rems Link Status Checker | 8/10/2025 | 17/6/2026 | Sourcecodester Link Status Checker 1.0 is vulnerable to a Cross-Site Scripting (XSS) in the Enter URLs to check input field. This allows a remote attacker to execute arbitrary code. | |
| Analizada | Baja (2.1) | 0.39% | — | Rems Link Status Checker | 14/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Link Status Checker 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument proxy leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Crítica (9.8) | 51% | — | Kunbus Revpi Status | 6/6/2025 | 17/6/2026 | An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device | |
| Aplazada | Media (4.7) | 0.46% | — | Wpfactory Scheduled Automatic Order Status Controller FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPFactory Scheduled & Automatic Order Status Controller for WooCommerce order-status-rules-for-woocommerce allows Phishing.This issue affects Scheduled & Automatic Order Status Controller for WooCommerce: from n/a through <= 3.7.1. | |
| Aplazada | Alta (7.5) | 0.44% | — | Shah Alom Delete Comments BY StatusAI | 3/3/2025 | 17/6/2026 | Relative Path Traversal vulnerability in Shah Alom Delete Comments By Status delete-comments-by-status allows Path Traversal.This issue affects Delete Comments By Status: from n/a through <= 2.1.1. | |
| Aplazada | Alta (7.1) | 0.29% | — | Devu Status UpdaterAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devu Status Updater fb-status-updater allows Reflected XSS.This issue affects Status Updater: from n/a through <= 1.9.2. | |
| Aplazada | Media (5.4) | 0.34% | — | Felixwelberg Extended Post StatusAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Felix Welberg Extended Post Status allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extended Post Status: from n/a through 1.0.19. | |
| Aplazada | Media (6.1) | 0.28% | — | Additional Custom Order Status FOR WoocommerceAI | 4/12/2024 | 17/6/2026 | The Additional Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wfwp_wcos_delete_finished, wfwp_wcos_delete_fallback_finished, wfwp_wcos_delete_fallback_orders_updated, and wfwp_wcos_delete_fallback_status parameters in all versions up to, and including,… | |
| Aplazada | Media (6.4) | 0.41% | — | Streamweasels Online Status BARAI | 21/11/2024 | 17/6/2026 | The StreamWeasels Online Status Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-status-bar' shortcode in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.1) | 0.30% | — | Post Status NotifierAI | 29/10/2024 | 17/6/2026 | The Post Status Notifier Lite and Premium plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.11.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.4) | 0.46% | — | Ultimate 410 Gone Status CodeAI | 2/5/2024 | 17/6/2026 | The Ultimate 410 Gone Status Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 410 entries in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Alta (7.3) | 0.78% | — | Nokia C200AINokia C100AITracfone TfstatusAI | 22/4/2024 | 17/6/2026 | Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a package name of com.tracfone.tfstatus (versionCode='31', versionName='12') that allows local third-party apps to execute arbitrary AT commands in its context (radio user) via AT command injection… | |
| Aplazada | Media (4.3) | 0.46% | — | Nuggethon Custom Order Statuses FOR WoocommerceAI | 17/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Custom Order Statuses for WooCommerce: from n/a through 1.5.2. |