Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.52%—Vibesurf-ai VibesurfAI4/8/202612/8/2026
A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation Handler. The manipulation leads to code injection. Remote exploitation of the attack is possible. This product follows a rolling…
AplazadaAlta (7.1)0.25%—Form Vibes Database Manager FOR FormsAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
AplazadaAlta (7.2)0.40%—Wpvibes Form VibesAI11/7/202613/7/2026
The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
AplazadaAlta (7.1)0.27%—Wpvibes WP Mail LOGAI11/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: from n/a through 1.0.2.
AplazadaMedia (6.5)0.39%—Wpvibes Elementor Addon ElementsAI26/2/202617/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder allows Retrieve Embedded Sensitive Data.This issue affects Elementor Addon Elements: from n/a through <= 1.14.4.
AplazadaMedia (4.9)0.32%—Wpvibes Form VibesAI6/1/202617/6/2026
The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to SQL Injection via the 'params' parameter in all versions up to, and including, 1.4.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (4.3)0.18%—Wpvibes Anywhere Elementor PROAI5/1/202630/9/2026
Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through 2.29.
AnalizadaMedia (5.3)0.22%—Salesforce Agentforce Vibes4/11/202517/6/2026
Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.3.0.
AnalizadaMedia (5.3)0.24%—Salesforce Agentforce Vibes4/11/202517/6/2026
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.3.0.
AnalizadaMedia (6.5)0.21%—Salesforce Agentforce Vibes4/11/202517/6/2026
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affects Agentforce Vibes Extension: before 3.2.0.
AplazadaAlta (7.5)0.43%—VibesAI26/8/202517/6/2026
The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the ‘resource’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated…
AplazadaMedia (4.3)0.32%—Wpvibes Anywhere ElementorAI5/12/202417/6/2026
The AnyWhere Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.11 via the 'INSERT_ELEMENTOR' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and…
ModificadaMedia (5.4)0.29%—Wpvibes Form Vibes5/9/202417/6/2026
The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the fv_export_csv, reset_settings, save_settings, save_columns_settings, get_analytics_data, get_event_logs_data, delete_submissions, and…
ModificadaMedia (6.5)0.48%—Wpvibes Form Vibes12/7/202417/6/2026
The Form Vibes plugin for WordPress is vulnerable to SQL Injection via the ‘fv_export_data’ parameter in all versions up to, and including, 1.4.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
ModificadaAlta (7.2)0.98%—Wpvibes Form Vibes16/1/202417/6/2026
The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.
ModificadaAlta (8.8)0.61%—Wpvibes WP Mail LOG29/12/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WPVibes WP Mail Log.This issue affects WP Mail Log: from n/a through 1.1.2.
ModificadaAlta (8.8)11%—Wpvibes WP Mail LOG26/12/202317/6/2026
The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.
ModificadaAlta (8.8)1.1%—Wpvibes WP Mail LOG26/12/202317/6/2026
The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to remote code execution.
ModificadaMedia (6.5)0.71%—Wpvibes WP Mail LOG26/12/202317/6/2026
The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attacker to leak the contents of arbitrary files.
ModificadaAlta (8.8)0.72%—Wpvibes WP Mail LOG26/12/202317/6/2026
The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.
ModificadaAlta (7.6)0.50%—Wpvibes WP Mail LOG26/12/202317/6/2026
The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.
ModificadaAlta (7.2)0.73%—Wpvibes Redirect 404 Error Page TO Homepage OR Custom Page With Logs18/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPVibes Redirect 404 Error Page to Homepage or Custom Page with Logs allows SQL Injection.This issue affects Redirect 404 Error Page to Homepage or Custom Page with Logs: from n/a through 1.8.7.
ModificadaMedia (6.1)0.46%—Wpvibes WP Mail LOG12/7/202317/6/2026
The WP Mail Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
ModificadaMedia (5.3)0.62%—Wpvibes Anywhere Elementor30/5/202317/6/2026
The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. Such key has been revoked.
ModificadaAlta (8.8)0.26%—Wpvibes WP Mail LOG2/2/202317/6/2026
Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions.