Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.37% | — | Patrickjuchli Basic-ftpAI | 30/9/2026 | 30/9/2026 | basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long… | |
| Aplazada | Alta (7.5) | 0.25% | — | Tipsandtricks-hq WP Express CheckoutAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions. | |
| Aplazada | Media (6.5) | 0.16% | — | Jetimpex INC JettricksAI | 23/9/2026 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. This issue affects JetTricks: from n/a through 2.0.1. | |
| Aplazada | Media (5.3) | 0.16% | — | Tipsandtricks-hq WP Express CheckoutAI | 9/9/2026 | 9/9/2026 | The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying. | |
| Aplazada | Media (5.3) | 0.16% | — | Tipsandtricks-hq WP Express CheckoutAI | 2/9/2026 | 3/9/2026 | The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying. | |
| Aplazada | Media (6.9) | 0.54% | — | Nasa TrickAI | 30/8/2026 | 31/8/2026 | A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This manipulation causes stack-based buffer overflow. The attack is… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Tipsandtricks-hq WP EmemberAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in WP eMember < v10.9.4 versions. | |
| Aplazada | Media (5.3) | 0.33% | — | Tips AND Tricks HQ WP EmemberAI | 4/6/2026 | 22/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2. | |
| Aplazada | Alta (7.5) | 0.54% | — | Patrickjuchli Basic-ftpAI | 12/5/2026 | 17/6/2026 | basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authentication. The client… | |
| Analizada | Alta (7.5) | 0.49% | — | Patrickjuchli Basic-ftp | 24/4/2026 | 17/6/2026 | basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings from a remote FTP server. A malicious or compromised server can send an extremely large or never-ending listing response to `Client.list()`, causing… | |
| Modificada | Alta (8.6) | 2.8% | — | Patrickjuchli Basic-ftp | 9/4/2026 | 15/7/2026 | basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(), downloadTo(), list(), and removeDir(). The library's protectWhitespace() helper only handles… | |
| Aplazada | Alta (7.1) | 0.25% | — | Tips AND Tricks HQ WP EmemberAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tricks HQ WP eMember allows Reflected XSS.This issue affects WP eMember: from n/a through v10.2.2. | |
| Aplazada | Media (5.3) | 0.31% | — | Tips AND Tricks HQ WP EmemberAI | 19/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP eMember: from n/a through v10.2.2. | |
| Analizada | Crítica (9.8) | 1.0% | — | Patrickjuchli Basic-ftp | 25/2/2026 | 17/6/2026 | The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended… | |
| Aplazada | Alta (7.8) | 0.51% | — | Tencent PatrickstarAI | 23/12/2025 | 17/6/2026 | Tencent PatrickStar merge_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent PatrickStar. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Aplazada | Media (6.4) | 0.39% | — | Patrickposner QyrrAI | 30/9/2025 | 17/6/2026 | The Qyrr – simply and modern QR-Code creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the blob_to_file() function in all versions up to, and including, 2.0.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (6.5) | 0.34% | — | Crocoblock JettricksAI | 20/8/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetTricks jet-tricks allows Retrieve Embedded Sensitive Data.This issue affects JetTricks: from n/a through <= 1.5.4.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Crocoblock JettricksAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTricks jet-tricks allows Stored XSS.This issue affects JetTricks: from n/a through <= 1.5.4.1. | |
| Analizada | Media (5.4) | 0.28% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 1/5/2025 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' shortcode in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.3) | 0.36% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 1/5/2025 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 via the 'process_payment_data' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the quantity of a… | |
| Analizada | Media (6.5) | 0.41% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 1/5/2025 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 due to lack of randomization of a user controlled key. This makes it possible for unauthenticated attackers to access customer shopping carts and edit product links, add… | |
| Aplazada | Alta (7.5) | 0.36% | — | Crocoblock JettricksAI | 15/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Crocoblock JetTricks jet-tricks allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetTricks: from n/a through <= 1.5.1. | |
| Aplazada | Alta (7.1) | 0.19% | — | Css-tricks Chat2AI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Chat2 Chat2 chat2 allows Cross Site Request Forgery.This issue affects Chat2: from n/a through <= 4.0. | |
| Analizada | Media (5.4) | 0.34% | — | Patrickpelayo Responsive Iframe | 1/2/2025 | 17/6/2026 | The Responsive iframe WordPress plugin through 1.2.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (6.4) | 0.30% | — | Tipsandtricks-hq Compact WP Audio PlayerAI | 7/1/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in mra13 Compact WP Audio Player compact-wp-audio-player allows Server Side Request Forgery.This issue affects Compact WP Audio Player: from n/a through <= 1.9.14. |