Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.38% | — | Steve Burge Simple-tagsAITaxopressAI | 29/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind SQL Injection.This issue affects TaxoPress: from n/a through <= 3.44.0. | |
| Analizada | Media (5.7) | 0.28% | — | Steve-community Steve | 26/2/2026 | 17/6/2026 | SteVe is an open-source EV charging station management system. In versions up to and including 3.11.0, when a charger sends a StopTransaction message, SteVe looks up the transaction solely by transactionId (a sequential integer starting from 1) without verifying that the requesting charger matches the charger that… | |
| Aplazada | Media (6.5) | 0.23% | — | Steve Truman Woocommerce Email Inquiry Cart OptionsAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Truman Email Inquiry & Cart Options for WooCommerce woocommerce-email-inquiry-cart-options allows DOM-Based XSS.This issue affects Email Inquiry & Cart Options for WooCommerce: from n/a through <= 3.5.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Steve Truman WP Email TemplateAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Steve Truman WP Email Template wp-email-template allows Cross Site Request Forgery.This issue affects WP Email Template: from n/a through <= 2.8.5. | |
| Aplazada | Media (4.3) | 0.23% | — | Steve Burge Simple-tagsAITaxopressAI | 14/8/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Steve Burge TaxoPress simple-tags allows Retrieve Embedded Sensitive Data.This issue affects TaxoPress: from n/a through <= 3.37.2. | |
| Aplazada | Alta (8.5) | 0.27% | — | Steve Truman Contact US Page Contact People LiteAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Contact Us page - Contact people LITE contact-us-page-contact-people allows SQL Injection.This issue affects Contact Us page - Contact people LITE: from n/a through <= 3.7.4. | |
| Aplazada | Media (6.5) | 0.20% | — | Steve Puddick WP Notes WidgetAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Puddick WP Notes Widget wp-notes-widget allows DOM-Based XSS.This issue affects WP Notes Widget: from n/a through <= 1.0.6. | |
| Analizada | Media (5.9) | 0.44% | — | Steve-community Steve | 15/4/2025 | 17/6/2026 | An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests. | |
| Aplazada | Alta (7.1) | 0.15% | — | Steveorevo Domain ThemeAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Steveorevo Domain Theme domain-theme allows Stored XSS.This issue affects Domain Theme: from n/a through <= 1.3. | |
| Aplazada | Alta (7.1) | 0.39% | — | Steve Canalplan CanalplanAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Canalplan canalplan-ac allows Reflected XSS.This issue affects Canalplan: from n/a through <= 5.31. | |
| Aplazada | Media (6.5) | 0.37% | — | Steve Soehl Wp-revive AdserverAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SteveSoehl WP-Revive Adserver wp-revive-adserver allows Stored XSS.This issue affects WP-Revive Adserver: from n/a through <= 2.2.1. | |
| Aplazada | Media (6.5) | 0.36% | — | Steven Nolles Bonway Static Block EditorAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steven Nolles Bonway Static Block Editor bonway-static-block-editor allows DOM-Based XSS.This issue affects Bonway Static Block Editor: from n/a through <= 1.1.0. | |
| Analizada | Alta (7.8) | 0.19% | — | Steveklabnik Request Store | 23/8/2024 | 17/6/2026 | RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users to execute arbitrary code. This version was published in 2017, and most production environments do not allow access for… | |
| Analizada | Media (6.1) | 0.40% | — | Steve-community Steve | 12/8/2024 | 17/6/2026 | SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe… | |
| Analizada | Crítica (9.8) | 0.95% | — | Steve228uk Candycms | 8/4/2024 | 17/6/2026 | An issue was discovered in CandyCMS version 1.0.0, allows remote attackers to execute arbitrary code via the install.php component. | |
| Modificada | Alta (7.5) | 0.56% | — | Steve-community Steve | 13/2/2024 | 17/6/2026 | SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions. | |
| Modificada | Alta (7.5) | 0.62% | — | Steve-community Ocpp-jaxb | 26/12/2023 | 17/6/2026 | SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL exception in applications, and may undermine… | |
| Modificada | Media (5.4) | 0.54% | — | Stevenhenty Drop Shadow Boxes | 22/11/2023 | 17/6/2026 | The Drop Shadow Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dropshadowbox' shortcode in versions up to, and including, 1.7.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Crítica (9.8) | 0.50% | — | Steven Ellis Easy2map Photos | 6/10/2023 | 17/6/2026 | A vulnerability classified as critical was found in Easy2Map Photos Plugin 1.0.1 on WordPress. This vulnerability affects unknown code. The manipulation leads to sql injection. The attack can be initiated remotely. Upgrading to version 1.1.0 is able to address this issue. The patch is identified as… | |
| Modificada | Media (4.3) | 2.2% | — | Steve Souza Java Application Monitor | 31/1/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java Application Monitor) 2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listenertype or (2) currentlistener parameter to mondetail.jsp or ArraySQL parameter to (3) mondetail.jsp, (4) jamonadmin.jsp, (5) sql.jsp,… | |
| Modificada | Media (6.8) | 1.5% | — | Steven Jones Context | 7/12/2013 | 16/6/2026 | The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support the json_decode function, allows remote attackers to execute arbitrary PHP code via unspecified vectors related to Ajax… | |
| Modificada | Media (4.9) | 1.6% | — | Steven Jones Context | 7/12/2013 | 16/6/2026 | The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which makes it easier for remote authenticated users to guess the access token for a block by leveraging the token from a block to which the user… | |
| Modificada | Media (5) | 1.7% | — | Steven Jones Context | 3/1/2013 | 16/6/2026 | The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access to block content, which allows remote attackers to obtain sensitive information via a crafted request. | |
| Modificada | Media (6.8) | 10.0% | — | Steve J Baker Plib | 18/11/2012 | 16/6/2026 | Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3d model file that triggers a long error message, as demonstrated by a .ase file. | |
| Modificada | Media (6.8) | 1.1% | — | Wilson Steven Mangosweb Enhanced | 9/10/2012 | 16/6/2026 | SQL injection vulnerability in MangosWeb Enhanced 3.0.3 allows remote attackers to execute arbitrary SQL commands via the login parameter in a login action to index.php. |