Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2538▼ 400 respecto a la semana anterior
Críticas / altas1320▲ 39 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.18% | — | Biostar Vivid LED DJAI | 21/9/2026 | 21/9/2026 | A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where condition. Local access is required to approach this attack. The… | |
| Aplazada | Media (5.5) | 0.34% | — | Wpvivid Backup Migration StagingAI | 4/9/2026 | 8/9/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root. | |
| Aplazada | Media (5.5) | 0.38% | — | Wpvivid Backup Migration StagingAI | 4/9/2026 | 8/9/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files. | |
| Aplazada | Media (4.1) | 0.31% | — | WpvividAI | 2/9/2026 | 3/9/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing administrators to perform SQL injection attacks. | |
| Aplazada | Media (6.6) | 0.26% | — | Wpvivid Backup Migration StagingAI | 30/8/2026 | 3/9/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution. | |
| Aplazada | Crítica (9.1) | 0.52% | — | Wpvivid Backup Migration StagingAI | 16/8/2026 | 26/8/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log file in any existing writable directory of the site, including the… | |
| Aplazada | Media (4.9) | 0.44% | — | Wpvivid Backup MigrationAI | 1/8/2026 | 12/8/2026 | The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versions up to, and including, 0.9.131. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The values are received in… | |
| Aplazada | Media (4.4) | 0.24% | — | Wpvivid Backup FOR MainwpAI | 10/7/2026 | 10/7/2026 | The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.9.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Aplazada | Baja (3.8) | 0.39% | — | Wpvivid Backup MigrationAI | 6/6/2026 | 23/7/2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all versions up to, and including, 0.9.128. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 33% | — | Wpvivid Backup MigrationAI | 11/2/2026 | 17/6/2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when writing uploaded files.… | |
| Aplazada | Baja (2.7) | 0.41% | — | Wpvivid Backup MigrationAI | 21/12/2025 | 17/6/2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This is due to the check_filesystem_permissions() function not properly restricting the directories that can be created, or in what location.… | |
| Analizada | Alta (7.2) | 55% | — | Wpvivid Migration, Backup, Staging | 3/7/2025 | 17/6/2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (7.2) | 2.3% | — | Wpvivid Backup & Migration | 22/2/2025 | 17/6/2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated attackers, with Administrator-level access… | |
| Analizada | Media (5.3) | 0.42% | — | Vividcolorsjp Aforms Eats | 12/2/2025 | 17/6/2026 | The AForms Eats plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.3.1. This is due the /vendor/aura/payload-interface/phpunit.php file being publicly accessible and displaying error messages. This makes it possible for unauthenticated attackers to retrieve the full path… | |
| Modificada | Crítica (9.8) | 0.40% | — | Wpvivid Migration, Backup, Staging | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in wpvividplugins WPvivid Backup and Migration wpvivid-backuprestore allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPvivid Backup and Migration: from n/a through <= 0.9.106. | |
| Analizada | Alta (8.8) | 0.65% | — | Wpvivid Migration, Backup, Staging | 14/11/2024 | 17/6/2026 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replace_row_data' and 'replace_serialize_data' functions. This makes it possible for unauthenticated attackers to inject a PHP… | |
| Analizada | Alta (8.8) | 1.2% | — | Wpvivid Migration, Backup, Staging | 16/10/2024 | 17/6/2026 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This… | |
| Analizada | Media (6.5) | 0.55% | — | Wpvivid Migration, Backup, Staging | 16/10/2024 | 17/6/2026 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their… | |
| Analizada | Alta (7.5) | 0.58% | — | Wpvivid Migration, Backup, Staging | 2/10/2024 | 17/6/2026 | The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups. | |
| Modificada | Media (6.1) | 0.26% | — | Wpvivid Backup FOR Mainwp | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpvividplugins WPvivid Backup for MainWP wpvivid-backup-mainwp allows Reflected XSS.This issue affects WPvivid Backup for MainWP: from n/a through <= 0.9.32. | |
| Analizada | Alta (8.8) | 0.71% | — | Wpvivid Migration, Backup, Staging | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a through 0.9.90. | |
| Modificada | Alta (7.2) | 42% | — | Wpvivid Migration, Backup, Staging | 12/4/2024 | 17/6/2026 | WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpvividstg_get_custom_exclude_path_free action. This is due to the plugin not providing sufficient path validation on the tree_node[node][id]… | |
| Modificada | Media (6.1) | 0.61% | — | Wpvivid Backup FOR Mainwp | 13/3/2024 | 17/6/2026 | The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 0.9.32 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Crítica (9.1) | 0.83% | — | Wpvivid Migration, Backup, Staging | 29/2/2024 | 17/6/2026 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() functions in all versions up to, and including, 0.9.68. This makes it possible for unauthenticated attackers to exploit a SQL injection… | |
| Analizada | Crítica (9.1) | 1.1% | — | Wpvivid Migration, Backup, Staging | 29/2/2024 | 17/6/2026 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers… |