Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2634▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.27% | — | WOW Viral SignupsAI | 9/6/2026 | 21/7/2026 | Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payloads in the 'idsignup'… | |
| Aplazada | Media (4.3) | 0.13% | — | Ultimate Viral QuizAI | 3/10/2025 | 17/6/2026 | The Ultimate Viral Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on thesave_options() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged… | |
| Aplazada | Alta (7.1) | 0.12% | — | Looks Awesome Onionbuzz Viral QuizAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Looks Awesome OnionBuzz onionbuzz-viral-quiz allows Stored XSS.This issue affects OnionBuzz: from n/a through <= 1.0.7. | |
| Aplazada | Media (5.3) | 0.32% | — | Viralloops Viral Loops WP IntegrationAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Viral Loops WP Integration: from n/a through <= 3.8.1. | |
| Aplazada | Media (4.3) | 0.28% | — | Viralloops Viral Loops WP IntegrationAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Viral Loops WP Integration: from n/a through <= 3.8.1. | |
| Aplazada | Media (5.3) | 0.50% | — | Viralloops Viral Loops WP IntegrationAI | 1/4/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Retrieve Embedded Sensitive Data.This issue affects Viral Loops WP Integration: from n/a through <= 3.4.0. | |
| Aplazada | Alta (7.5) | 0.45% | — | Arielbrailovsky ViraladAI | 13/3/2025 | 17/6/2026 | The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the printResultAndDie() function in all versions up to, and including, 1.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Alta (7.5) | 0.45% | — | Arielbrailovsky Viral ADAI | 13/3/2025 | 17/6/2026 | The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'text' and 'id' parameters of the limpia() function in all versions up to, and including, 1.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Media (4.3) | 0.47% | — | Hashthemes Viral MAGAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in HashThemes Viral Mag allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Viral Mag: from n/a through 1.0.9. | |
| Analizada | Crítica (9.8) | 3.3% | — | Wow-company Viral Signup | 4/9/2024 | 17/6/2026 | The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | |
| Analizada | Media (4.8) | 0.37% | — | Wow-company Viral Signup | 29/8/2024 | 17/6/2026 | The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (4.3) | 0.18% | — | Mythemeshop SociallyviralAI | 12/7/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop SociallyViral.This issue affects SociallyViral: from n/a through 1.0.10. | |
| Aplazada | Media (4.3) | 0.50% | — | Hashthemes Viral NewsAIHashthemes ViralAIHashthemes HashoneAI | 25/3/2024 | 17/6/2026 | Missing Authorization vulnerability in HashThemes Viral News, HashThemes Viral, HashThemes HashOne.This issue affects Viral News: from n/a through 1.4.5; Viral: from n/a through 1.8.0; HashOne: from n/a through 1.3.0. | |
| Modificada | Media (6.8) | 0.61% | — | Viralheat Argyle Social | 1/1/2015 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Argyle Social 2011-04-26 allow remote attackers to hijack the authentication of administrators for requests that (1) modify credentials via the role parameter to users/create/, (2) modify rules via the terms field in stream_filter_rule JSON data to… | |
| Modificada | Media (5.4) | 0.27% | — | Aceviral Angry Gran Toss | 9/9/2014 | 17/6/2026 | The Angry Gran Toss (aka com.aceviral.angrygrantoss) application 1.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.1% | — | Yourfreeworld Viral Marketing Script | 21/8/2008 | 16/6/2026 | SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | E-topbiz Viral DX 1 | 26/6/2008 | 16/6/2026 | SQL injection vulnerability in adclick.php in E-topbiz Viral DX 1 2.07 allows remote attackers to execute arbitrary SQL commands via the bannerid parameter. | |
| Modificada | Alta (7.5) | 2.8% | — | Duncan Hall Viralator | 6/12/2001 | 16/6/2026 | viralator CGI script in Viralator 0.9pre1 and earlier allows remote attackers to execute arbitrary code via a URL for a file being downloaded, which is insecurely passed to a call to wget. |