Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.7) | 0.23% | — | Modern Tribe THE Events CalendarAI | 23/9/2026 | 23/9/2026 | The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review. | |
| Aplazada | Alta (7.5) | 0.43% | — | Adtribes Product Feed PROAI | 15/8/2026 | 26/8/2026 | The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy. | |
| Aplazada | Media (5.3) | 0.33% | — | Thetechtribe THE TribalAI | 8/4/2026 | 24/7/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in thetechtribe The Tribal the-tech-tribe allows Retrieve Embedded Sensitive Data.This issue affects The Tribal: from n/a through <= 1.3.4. | |
| Aplazada | Alta (8.8) | 0.21% | — | Adtribes Product Feed PROAI | 8/4/2026 | 24/7/2026 | The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 13.4.6 through 13.5.2.1. This is due to missing or incorrect nonce validation on the ajax_migrate_to_custom_post_type,… | |
| Aplazada | Alta (8.1) | 0.54% | — | Launchandsell TribeAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LaunchandSell Tribe tribe allows PHP Local File Inclusion.This issue affects Tribe: from n/a through <= 1.7.3. | |
| Aplazada | Media (5.4) | 0.42% | — | Moderntribe THE Events CalendarAI | 25/2/2026 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (5.9) | 0.22% | — | Thetechtribe THE TribalAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thetechtribe The Tribal the-tech-tribe allows Stored XSS.This issue affects The Tribal: from n/a through <= 1.3.3. | |
| Aplazada | Media (5.3) | 0.31% | — | Thetechtribe THE TribalAI | 26/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in thetechtribe The Tribal the-tech-tribe allows Retrieve Embedded Sensitive Data.This issue affects The Tribal: from n/a through <= 1.3.3. | |
| Analizada | Media (5.3) | 0.55% | — | Gotribe | 24/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Go-Tribe gotribe up to cd3ccd32cd77852c9ea73f986eaf8c301cfb6310. Affected is the function Sign of the file pkg/token/token.go. The manipulation of the argument config.key leads to hard-coded credentials. Continious delivery with rolling releases is used by this… | |
| Analizada | Media (5.1) | 0.83% | — | Gotribe-admin | 20/8/2024 | 17/6/2026 | A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the function InitRoutes of the file internal/app/routes/routes.go of the component Log Handler. The manipulation leads to deserialization. The patch is identified as… | |
| Aplazada | Media (5.3) | 0.44% | — | Adtribes Product Feed PRO FOR WoocommerceAI | 17/4/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in AdTribes.Io Product Feed PRO for WooCommerce.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.3.1. | |
| Modificada | Alta (7.2) | 0.57% | — | Adtribes Product Feed PRO FOR Woocommerce | 15/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExportFeed.Com Product Feed on WooCommerce for Google.This issue affects Product Feed on WooCommerce for Google: from n/a through 3.5.7. | |
| Aplazada | Alta (7.1) | 0.39% | — | Adtribes Product Feed PRO FOR WoocommerceAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AdTribes.Io Product Feed PRO for WooCommerce allows Reflected XSS.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.2.5. | |
| Modificada | Alta (7.8) | 0.18% | — | CheckmkTribe29 Checkmk | 12/1/2024 | 17/6/2026 | Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges | |
| Modificada | Alta (7.8) | 0.28% | — | CheckmkTribe29 Checkmk | 12/1/2024 | 17/6/2026 | Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges | |
| Modificada | Media (6.5) | 0.51% | — | CheckmkTribe29 Checkmk | 12/1/2024 | 17/6/2026 | Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials | |
| Modificada | Alta (8.8) | 0.25% | — | Madebytribe Caddy | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tribe Interactive Caddy – Smart Side Cart for WooCommerce.This issue affects Caddy – Smart Side Cart for WooCommerce: from n/a through 1.9.7. | |
| Modificada | Media (5.5) | 0.24% | — | Tribe29 Checkmk Appliance Firmware | 27/11/2023 | 17/6/2026 | Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files. | |
| Modificada | Media (4.8) | 0.32% | — | Triberr | 27/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Triberr plugin <= 4.1.1 versions. | |
| Modificada | Alta (8.8) | 1.1% | — | CheckmkTribe29 Checkmk | 10/8/2023 | 17/6/2026 | Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users. | |
| Modificada | Media (4.3) | 0.59% | — | CheckmkTribe29 Checkmk | 17/5/2023 | 17/6/2026 | Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs. | |
| Modificada | Alta (8.8) | 0.97% | — | CheckmkTribe29 Checkmk | 17/5/2023 | 17/6/2026 | Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users. | |
| Modificada | Alta (7.5) | 0.54% | — | Tribe29 Checkmk Appliance Firmware | 15/5/2023 | 17/6/2026 | Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5. | |
| Modificada | Media (6.1) | 0.41% | — | Tribe29 Checkmk Appliance Firmware | 20/4/2023 | 17/6/2026 | Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4. | |
| Modificada | Media (5.5) | 0.22% | — | Tribe29 Checkmk Appliance Firmware | 18/4/2023 | 17/6/2026 | Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files. |