Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2561▼ 316 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.40% | — | Calmar-webmedia Total DonationsAI | 19/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Calmar-webmedia Total DonationsAI | 19/8/2026 | 20/8/2026 | Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | |
| Aplazada | Alta (7.1) | 0.22% | — | Calmar-webmedia Total DonationsAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in binti76 Total Donations total-donations allows Reflected XSS.This issue affects Total Donations: from n/a through <= 3.0.8. | |
| Modificada | Crítica (9.8) | 26% | — | Calmar-webmedia Total Donations | 27/1/2019 | 17/6/2026 | Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the… |