Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2765▼ 50 respecto a la semana anterior
Críticas / altas1432▲ 200 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)95▼ 405 respecto a la semana anterior
3406 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.2) | — | — | Cusrev Customer Reviews FOR WoocommerceAI | 2/10/2026 | 2/10/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Recibida | Media (5.5) | — | — | Sourcecodester Online Reviewer Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be… | |
| Aplazada | Media (6.5) | — | — | Radiustheme Review SchemaAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Schema: 3.1.0. | |
| Aplazada | Alta (7.5) | — | — | Photo Reviews FOR WoocommerceAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions. | |
| Aplazada | Media (5.3) | — | — | Geminilabs Site ReviewsAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2. | |
| Aplazada | Alta (7.1) | — | — | Five Star Restaurant ReviewsAI | 1/10/2026 | 1/10/2026 | The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in… | |
| Aplazada | Alta (8.7) | 0.79% | — | IdocviewAI | 30/9/2026 | 1/10/2026 | iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file://… | |
| Aplazada | Media (5.3) | 0.29% | — | Radiustheme Review SchemaAI | 30/9/2026 | 30/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Cusrev Customer Reviews FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Geminilabs Site ReviewsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | CF7 ViewsAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions. | |
| Aplazada | Alta (7.2) | 0.25% | — | Post Views Stats CounterAI | 30/9/2026 | 30/9/2026 | The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (5.3) | 0.21% | — | YayreviewsAI | 30/9/2026 | 30/9/2026 | The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content. | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Online Reviewer Management SystemAI | 30/9/2026 | 30/9/2026 | A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Online Reviewer Management SystemAI | 30/9/2026 | 30/9/2026 | A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument access_code leads to sql injection. The attack can be initiated remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Online Reviewer Management SystemAI | 30/9/2026 | 30/9/2026 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/examproper/questions-view.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack… | |
| Pendiente de análisis | Alta (7.5) | 0.16% | — | Wikimedia UserpageviewtrackerAI | 29/9/2026 | 1/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection. This issue affects Mediawiki - UserPageViewTracker Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Aplazada | Alta (7) | 0.10% | — | TeamviewerAI | 29/9/2026 | 30/9/2026 | TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in… | |
| Aplazada | Alta (8.8) | 0.38% | — | TeamviewerAI | 29/9/2026 | 30/9/2026 | An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an… | |
| Aplazada | Alta (7.3) | 0.09% | — | TeamviewerAI | 29/9/2026 | 30/9/2026 | TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in… | |
| Aplazada | Alta (7.8) | 0.14% | — | TeamviewerAI | 29/9/2026 | 30/9/2026 | TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially… | |
| Aplazada | Alta (7.8) | 0.13% | — | TeamviewerAI | 29/9/2026 | 30/9/2026 | Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the… | |
| Pendiente de análisis | Media (4.3) | 0.17% | — | HPE OneviewAI | 29/9/2026 | 29/9/2026 | A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect. | |
| Pendiente de análisis | Alta (8.2) | 0.18% | — | HPE OneviewAI | 29/9/2026 | 29/9/2026 | A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions. | |
| Pendiente de análisis | Alta (8.2) | 0.24% | — | HPE OneviewAI | 29/9/2026 | 29/9/2026 | A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions. |