Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.7)0.23%—Modern Tribe THE Events CalendarAI23/9/202623/9/2026
The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review.
AplazadaAlta (7.5)0.43%—Adtribes Product Feed PROAI15/8/202626/8/2026
The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read routes, allowing unauthenticated users to disclose a store's feed configuration (rules, filters and field mapping) and to enumerate the full product category taxonomy.
AplazadaMedia (5.3)0.33%—Thetechtribe THE TribalAI8/4/202624/7/2026
Insertion of Sensitive Information Into Sent Data vulnerability in thetechtribe The Tribal the-tech-tribe allows Retrieve Embedded Sensitive Data.This issue affects The Tribal: from n/a through <= 1.3.4.
AplazadaAlta (8.8)0.21%—Adtribes Product Feed PROAI8/4/202624/7/2026
The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 13.4.6 through 13.5.2.1. This is due to missing or incorrect nonce validation on the ajax_migrate_to_custom_post_type,…
AplazadaAlta (8.1)0.54%—Launchandsell TribeAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LaunchandSell Tribe tribe allows PHP Local File Inclusion.This issue affects Tribe: from n/a through <= 1.7.3.
AplazadaMedia (5.4)0.42%—Moderntribe THE Events CalendarAI25/2/202617/6/2026
The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level…
AplazadaMedia (5.9)0.22%—Thetechtribe THE TribalAI26/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thetechtribe The Tribal the-tech-tribe allows Stored XSS.This issue affects The Tribal: from n/a through <= 1.3.3.
AplazadaMedia (5.3)0.31%—Thetechtribe THE TribalAI26/9/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in thetechtribe The Tribal the-tech-tribe allows Retrieve Embedded Sensitive Data.This issue affects The Tribal: from n/a through <= 1.3.3.
AnalizadaMedia (5.3)0.55%—Gotribe24/8/202417/6/2026
A vulnerability classified as critical has been found in Go-Tribe gotribe up to cd3ccd32cd77852c9ea73f986eaf8c301cfb6310. Affected is the function Sign of the file pkg/token/token.go. The manipulation of the argument config.key leads to hard-coded credentials. Continious delivery with rolling releases is used by this…
AnalizadaMedia (5.1)0.83%—Gotribe-admin20/8/202417/6/2026
A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the function InitRoutes of the file internal/app/routes/routes.go of the component Log Handler. The manipulation leads to deserialization. The patch is identified as…
AplazadaMedia (5.3)0.44%—Adtribes Product Feed PRO FOR WoocommerceAI17/4/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in AdTribes.Io Product Feed PRO for WooCommerce.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.3.1.
ModificadaAlta (7.2)0.57%—Adtribes Product Feed PRO FOR Woocommerce15/4/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExportFeed.Com Product Feed on WooCommerce for Google.This issue affects Product Feed on WooCommerce for Google: from n/a through 3.5.7.
AplazadaAlta (7.1)0.39%—Adtribes Product Feed PRO FOR WoocommerceAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AdTribes.Io Product Feed PRO for WooCommerce allows Reflected XSS.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.2.5.
ModificadaAlta (7.8)0.18%—CheckmkTribe29 Checkmk12/1/202417/6/2026
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
ModificadaAlta (7.8)0.28%—CheckmkTribe29 Checkmk12/1/202417/6/2026
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
ModificadaMedia (6.5)0.51%—CheckmkTribe29 Checkmk12/1/202417/6/2026
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
ModificadaAlta (8.8)0.25%—Madebytribe Caddy18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tribe Interactive Caddy – Smart Side Cart for WooCommerce.This issue affects Caddy – Smart Side Cart for WooCommerce: from n/a through 1.9.7.
ModificadaMedia (5.5)0.24%—Tribe29 Checkmk Appliance Firmware27/11/202317/6/2026
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files.
ModificadaMedia (4.8)0.32%—Triberr27/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Triberr plugin <= 4.1.1 versions.
ModificadaAlta (8.8)1.1%—CheckmkTribe29 Checkmk10/8/202317/6/2026
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.
ModificadaMedia (4.3)0.59%—CheckmkTribe29 Checkmk17/5/202317/6/2026
Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.
ModificadaAlta (8.8)0.97%—CheckmkTribe29 Checkmk17/5/202317/6/2026
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
ModificadaAlta (7.5)0.54%—Tribe29 Checkmk Appliance Firmware15/5/202317/6/2026
Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5.
ModificadaMedia (6.1)0.41%—Tribe29 Checkmk Appliance Firmware20/4/202317/6/2026
Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4.
ModificadaMedia (5.5)0.22%—Tribe29 Checkmk Appliance Firmware18/4/202317/6/2026
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.