Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▲ 26 respecto a la semana anterior
Críticas / altas1468▲ 333 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.25% | — | Obfuscate Project Obfuscate | 19/5/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate allows Cross-Site Scripting (XSS). This issue affects Obfuscate: from 0.0.0 before 2.0.2. | |
| Aplazada | Media (6.4) | 0.25% | — | Aawp ObfuscatorAI | 8/4/2025 | 17/6/2026 | The AAWP Obfuscator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-aawp-web' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Analizada | Media (5.4) | 0.23% | — | Drupal Obfuscate | 2/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate allows Stored XSS.This issue affects Obfuscate: from 0.0.0 before 2.0.1. | |
| Aplazada | Media (6.5) | 0.28% | — | Nicholaswilson Graceful-email-obfuscationAI | 7/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicholaswilson Graceful Email Obfuscation graceful-email-obfuscation allows Stored XSS.This issue affects Graceful Email Obfuscation: from n/a through <= 0.2.2. | |
| Aplazada | Media (6.4) | 0.33% | — | Email Address ObfuscationAI | 4/12/2024 | 17/6/2026 | The Email Address Obfuscation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Analizada | Media (5.4) | 0.31% | — | Khromov Email Obfuscate Shortcode | 13/9/2024 | 17/6/2026 | The Email Obfuscate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email-obfuscate' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.48% | — | Obfuscate EmailAI | 12/8/2024 | 17/6/2026 | The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web… | |
| Analizada | Alta (7.8) | 0.35% | — | Deobfuscate Javascript Deobfuscator | 31/5/2024 | 17/6/2026 | javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targeting expression simplification can lead to code execution. This issue has been patched in version 1.1.0. Users are advised to update. Users unable to upgrade should disable the expression simplification… | |
| Modificada | Media (5.4) | 0.44% | — | Uscat Project Uscat | 25/1/2022 | 17/6/2026 | uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via "close registration information" input box. | |
| Modificada | Media (5.4) | 0.44% | — | Uscat Project Uscat | 25/1/2022 | 17/6/2026 | uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via the input box of the statistical code. | |
| Modificada | Media (5) | 7.3% | — | Brightstation Muscat Empower | 2/6/2001 | 16/6/2026 | Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter. |