Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.73%—Uncannyowl Uncanny AutomatorAI28/7/202628/7/2026
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and…
AplazadaAlta (7.6)0.38%—Uncannyowl Uncanny AutomatorAI23/7/202623/7/2026
Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
AplazadaAlta (8.1)1.0%—Uncannyowl Uncanny AutomatorAI16/7/202617/7/2026
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to…
AplazadaCrítica (9.8)0.55%—Uncanny Automator PROAI7/7/20267/7/2026
The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites…
AplazadaCrítica (9.8)0.56%—Uncanny Automator PROAI26/6/202626/6/2026
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
AplazadaAlta (8.1)0.44%—Uncannyowl Uncanny AutomatorAI26/6/202626/6/2026
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
AplazadaAlta (7.2)0.67%—Uncannyowl Uncanny AutomatorAI3/3/202617/6/2026
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.0.3 via the download_url() function. This makes it possible for authenticated attackers, with Administrator-level access…
AplazadaMedia (6.4)0.29%—Uncannyowl Uncanny AutomatorAI23/1/202617/6/2026
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automator_discord_user_mapping shortcode in all versions up to, and including, 6.10.0.2 due to insufficient input sanitization and output escaping on the…
AplazadaMedia (4.3)0.26%—Uncannyowl Uncanny AutomatorAI21/11/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Retrieve Embedded Sensitive Data.This issue affects Uncanny Automator: from n/a through < 6.10.0.
AplazadaMedia (4.3)0.20%—Uncannyowl Uncanny AutomatorAI27/8/202517/6/2026
Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through <= 6.7.0.1.
ModificadaCrítica (9.8)0.31%—Uncannyowl Uncanny Automator5/6/202517/6/2026
Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through <= 6.4.0.2.
AnalizadaMedia (4.3)0.28%—Uncannyowl Uncanny Automator14/5/202517/6/2026
The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.
AnalizadaCrítica (9.1)0.83%—Uncannyowl Uncanny Automator14/5/202517/6/2026
The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automator_api_decode_message() function. This makes it possible for unauthenticated to inject a PHP Object. The additional presence of a POP chain…
AnalizadaAlta (8.8)2.7%—Uncannyowl Uncanny Automator4/4/202517/6/2026
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.0.2. This is due to add_role() and user_role() functions missing proper capability checks performed through the validate_rest_call()…
AnalizadaBaja (3.8)0.30%—Uncannyowl Uncanny Automator12/3/202517/6/2026
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.2 via the 'call_webhook' method of the Automator_Send_Webhook class This makes it possible for authenticated attackers, with…
AnalizadaCrítica (9.8)0.55%—Uncannyowl Uncanny Automator1/11/202417/6/2026
Missing Authorization vulnerability in Uncanny Owl Uncanny Automator Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator Pro: from n/a through 5.3.0.0.
ModificadaMedia (6.1)0.33%—Uncannyowl Uncanny Automator22/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Automator Pro allows Reflected XSS.This issue affects Uncanny Automator Pro: from n/a through 5.3.
ModificadaAlta (8.8)0.20%—Uncannyowl Uncanny Automator21/6/202417/6/2026
Cross Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Automator Pro.This issue affects Uncanny Automator Pro: from n/a through 5.3.
ModificadaMedia (5.3)0.44%—Uncannyowl Uncanny Automator5/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Uncanny Automator, Uncanny Owl Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin.This issue affects Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin: from…