Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

26 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.86%—Wpmudev UpdatesAI12/8/202626/8/2026
The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to install and execute arbitrary code (remote…
AplazadaMedia (5.3)0.37%—Npm-check-updatesAI10/8/202624/9/2026
npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability that allows an attacker to embed arbitrary terminal control characters in a dependency's package.json homepage or repository URL fields. When a developer runs ncu with the --format homepage or…
AplazadaAlta (7.1)0.16%—Razer RzupdateserviceAI3/8/202612/8/2026
A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to…
AplazadaMedia (6.1)0.35%—Easyupdatesmanager Easy Updates ManagerAI28/5/202617/6/2026
The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in versions up to, and including, 9.0.20 This is due to insufficient input sanitization and output escaping in the pagination() function. This makes it possible for attackers to inject arbitrary web…
AplazadaMedia (4.3)0.13%—Plugin Updates BlockerAI11/9/202517/6/2026
The Plugin updates blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the pub_save action handler. This makes it possible for unauthenticated attackers to disable or enable plugin updates via a…
AplazadaAlta (8.8)0.37%—Aweos Gmbh Email Notifications FOR UpdatesAI15/4/202517/6/2026
Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Privilege Escalation.This issue affects Email Notifications for Updates: from n/a through <= 1.1.6.
AplazadaAlta (7.1)0.42%—Rachel Cherry Lock Your UpdatesAI11/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry Lock Your Updates lock-your-updates allows Reflected XSS.This issue affects Lock Your Updates: from n/a through <= 1.1.
AplazadaAlta (8.8)0.39%—Email Notifications FOR UpdatesAI5/4/202517/6/2026
The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the awun_import_settings() function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers,…
AplazadaAlta (7.1)0.29%—David Wood Latest Custom Post Type UpdatesAI3/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Wood Latest Custom Post Type Updates latest-custom-post-type-updates allows Reflected XSS.This issue affects Latest Custom Post Type Updates: from n/a through <= 1.3.0.
AnalizadaMedia (4.3)0.17%—Exeebit Disable Auto Updates19/2/202517/6/2026
The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'disable-auto-updates' page. This makes it possible for unauthenticated attackers to disable all auto updates via a forged…
AplazadaAlta (7.1)0.26%—Irshad A Khan Services Updates FOR CustomersAI2/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Irshad A.Khan Services updates for customers service-updates-for-customers allows Reflected XSS.This issue affects Services updates for customers: from n/a through <= 1.0.
AplazadaAlta (8.3)0.12%—Intel Seamless Firmware UpdatesAI16/9/202417/6/2026
Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (5.4)0.36%—Ipushpull Live Updates From Excel31/10/202317/6/2026
The Live updates from Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ipushpull_page' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
ModificadaAlta (7.8)0.66%—Microsoft Windows Defender Security Intelligence Updates12/9/202317/6/2026
Windows Defender Attack Surface Reduction Security Feature Bypass
ModificadaAlta (7.8)0.60%—Microsoft Defender Security Intelligence Updates14/2/202319/8/2026
Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
ModificadaCrítica (9.8)0.90%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification27/10/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=.
ModificadaAlta (7.2)1.0%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification16/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=.
ModificadaAlta (7.2)1.0%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification16/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=.
ModificadaAlta (7.2)1.0%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification16/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=.
ModificadaAlta (7.2)0.88%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification8/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/modstudent/index.php?view=edit&id=.
ModificadaAlta (7.2)0.88%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification8/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/autonumber/index.php?view=edit&id=.
ModificadaAlta (7.2)0.88%—School Activity Updates With SMS Notification Project School Activity Updates With SMS Notification8/9/202217/6/2026
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the component /modules/user/index.php?view=edit&id=.
ModificadaMedia (4.8)0.59%—Linkedin Company Updates Project Linkedin Company Updates17/7/202217/6/2026
The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (4.3)0.89%—Easyupdatesmanager Easy Updates Manager27/8/201917/6/2026
The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.
ModificadaAlta (8.1)3.3%—Lenovo Updates10/4/201717/6/2026
Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.
Orbitaley — Vulnerabilidades