Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.73% | — | Craftcms Vcard PluginAI | 3/2/2026 | 17/6/2026 | CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard download functionality with a… | |
| Aplazada | Media (5.3) | 0.35% | — | Contact Form Vcard GeneratorAI | 9/1/2026 | 17/6/2026 | The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wp_gvccf_check_download_request' function in all versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to export sensitive Contact Form 7… | |
| Aplazada | Alta (7.1) | 0.29% | — | Ashish Ajani Contact-form-vcard-generatorAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani Contact Form vCard Generator contact-form-vcard-generator allows Reflected XSS.This issue affects Contact Form vCard Generator: from n/a through <= 2.4. | |
| Aplazada | Alta (7.1) | 0.29% | — | Ashish Ajani Contact Form Vcard GeneratorAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani Contact Form vCard Generator contact-form-vcard-generator allows Stored XSS.This issue affects Contact Form vCard Generator: from n/a through <= 2.4. | |
| Aplazada | Media (4.3) | 0.47% | — | Stanislav Kuznetsov QR Code Mecard Vcard GeneratorAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Stanislav Kuznetsov QR code MeCard/vCard generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects QR code MeCard/vCard generator: from n/a through 1.6.0. | |
| Modificada | Crítica (9.8) | 0.50% | — | Bylancer Quickvcard | 16/7/2023 | 17/6/2026 | A vulnerability was found in Bylancer QuickVCard 2.1. It has been rated as critical. This issue affects some unknown processing of the file /blog of the component GET Parameter Handler. The manipulation of the argument s leads to sql injection. The attack may be initiated remotely. The identifier VDB-234233 was… | |
| Modificada | Media (4.3) | 1.3% | — | Stefan Auditor Vcard | 26/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in vCard 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the addition of the theme_vcard function to a theme and the use of default content. | |
| Modificada | Media (6.8) | 1.8% | — | Belchior Foundry Vcard PRO | 4/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gbrowse.php in Belchior Foundry vCard PRO allows remote attackers to inject arbitrary web script or HTML via the sortby parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Belchior Foundry Vcard | 10/7/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Belchior Foundry vCard PRO allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to (a) gbrowse.php, (2) card_id parameter to (b) rating.php and (c) create.php, and the (3) event_id parameter to (d) search.php. | |
| Modificada | Media (6.8) | 1.6% | — | Belchior Foundry Vcard | 5/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Belchior Foundry vCard 2.9 allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) toprated.php and (2) newcards.php. NOTE: the card_id vector is already covered by CVE-2006-1230. | |
| Modificada | Media (4.3) | 2.6% | — | Belchior Foundry Vcard | 14/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (4) card_color parameter. NOTE: the card_id vector was later reported to affect vCard 2.9, and the uploaded vector for… | |
| Modificada | Alta (7.5) | 1.1% | — | Belchior Foundry Vcard PROAI | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in addrbook.php in Belchior Foundry vCard PRO 3.1 allows remote attackers to execute arbitrary SQL commands via the addr_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.3% | — | Belchior Foundry Vcard | 27/10/2005 | 16/6/2026 | PHP remote file include vulnerability in admin/define.inc.php in Belchior Foundry vCard 2.9 allows remote attackers to execute arbitrary PHP code via the match parameter. | |
| Modificada | Media (5) | 2.4% | — | Belchior Foundry Vcard | 31/12/2004 | 16/6/2026 | Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php. | |
| Modificada | Media (4.3) | 1.2% | — | Vcard4j | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the VCard4J Toolkit allows remote attackers to inject arbitrary web script or HTML via the NICKNAME tag in a vCard. |