Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.73% | — | Uncannyowl Uncanny AutomatorAI | 28/7/2026 | 28/7/2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and… | |
| Aplazada | Alta (7.6) | 0.38% | — | Uncannyowl Uncanny AutomatorAI | 23/7/2026 | 23/7/2026 | Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions. | |
| Aplazada | Alta (8.1) | 1.0% | — | Uncannyowl Uncanny AutomatorAI | 16/7/2026 | 17/7/2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Uncanny Automator PROAI | 7/7/2026 | 7/7/2026 | The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Uncanny Automator PROAI | 26/6/2026 | 26/6/2026 | Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions. | |
| Aplazada | Alta (8.1) | 0.44% | — | Uncannyowl Uncanny AutomatorAI | 26/6/2026 | 26/6/2026 | Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions. | |
| Aplazada | Alta (7.2) | 0.67% | — | Uncannyowl Uncanny AutomatorAI | 3/3/2026 | 17/6/2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.0.3 via the download_url() function. This makes it possible for authenticated attackers, with Administrator-level access… | |
| Aplazada | Media (6.4) | 0.29% | — | Uncannyowl Uncanny AutomatorAI | 23/1/2026 | 17/6/2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automator_discord_user_mapping shortcode in all versions up to, and including, 6.10.0.2 due to insufficient input sanitization and output escaping on the… | |
| Aplazada | Media (4.3) | 0.26% | — | Uncannyowl Uncanny AutomatorAI | 21/11/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Retrieve Embedded Sensitive Data.This issue affects Uncanny Automator: from n/a through < 6.10.0. | |
| Aplazada | Media (4.3) | 0.20% | — | Uncannyowl Uncanny AutomatorAI | 27/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through <= 6.7.0.1. | |
| Modificada | Crítica (9.8) | 0.31% | — | Uncannyowl Uncanny Automator | 5/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through <= 6.4.0.2. | |
| Analizada | Media (4.3) | 0.28% | — | Uncannyowl Uncanny Automator | 14/5/2025 | 17/6/2026 | The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings. | |
| Analizada | Crítica (9.1) | 0.83% | — | Uncannyowl Uncanny Automator | 14/5/2025 | 17/6/2026 | The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automator_api_decode_message() function. This makes it possible for unauthenticated to inject a PHP Object. The additional presence of a POP chain… | |
| Analizada | Alta (8.8) | 2.7% | — | Uncannyowl Uncanny Automator | 4/4/2025 | 17/6/2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.0.2. This is due to add_role() and user_role() functions missing proper capability checks performed through the validate_rest_call()… | |
| Analizada | Baja (3.8) | 0.30% | — | Uncannyowl Uncanny Automator | 12/3/2025 | 17/6/2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.2 via the 'call_webhook' method of the Automator_Send_Webhook class This makes it possible for authenticated attackers, with… | |
| Analizada | Crítica (9.8) | 0.55% | — | Uncannyowl Uncanny Automator | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Uncanny Owl Uncanny Automator Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator Pro: from n/a through 5.3.0.0. | |
| Modificada | Media (6.1) | 0.33% | — | Uncannyowl Uncanny Automator | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Automator Pro allows Reflected XSS.This issue affects Uncanny Automator Pro: from n/a through 5.3. | |
| Modificada | Alta (8.8) | 0.20% | — | Uncannyowl Uncanny Automator | 21/6/2024 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Automator Pro.This issue affects Uncanny Automator Pro: from n/a through 5.3. | |
| Modificada | Media (5.3) | 0.44% | — | Uncannyowl Uncanny Automator | 5/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Uncanny Automator, Uncanny Owl Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin.This issue affects Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin: from… |