Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.34% | — | Webpushr-web-push-notificationsAI | 23/1/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in webpushr Webpushr webpushr-web-push-notifications allows Retrieve Embedded Sensitive Data.This issue affects Webpushr: from n/a through <= 4.38.0. | |
| Aplazada | Media (4.3) | 0.24% | — | Gravitec.net WEB Push NotificationsAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Gravitec.net - Web Push Notifications Gravitec.net – Web Push Notifications gravitec-net-web-push-notifications allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gravitec.net – Web Push Notifications: from n/a through <= 2.9.17. | |
| Aplazada | Media (5.9) | 0.18% | — | Pusheco Pushe WEB Push NotificationAI | 5/9/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pusheco Pushe Web Push Notification pushe-webpush allows Stored XSS.This issue affects Pushe Web Push Notification: from n/a through <= 0.5.0. | |
| Aplazada | Media (4) | 0.41% | — | Web-pushAI | 5/7/2025 | 17/6/2026 | The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a large integer in a Content-Length header. | |
| Analizada | Alta (7.1) | 0.27% | — | Feedify WEB Push Notifications | 10/4/2025 | 17/6/2026 | The Feedify WordPress plugin before 2.4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Alta (7.1) | 0.27% | — | Sjehutch Passbeemedia WEB Push Notification | 20/3/2025 | 17/6/2026 | The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.1) | 0.18% | — | Marco Castelluccio WEB PushAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marco Castelluccio Web Push web-push allows Stored XSS.This issue affects Web Push: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sendpulse Free WEB PushAI | 17/10/2024 | 17/6/2026 | The SendPulse Free Web Push plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.6 due to incorrect use of the wp_kses_allowed_html function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a… | |
| Modificada | Media (5.4) | 0.43% | — | Webpushr WEB Push Notifications | 27/11/2023 | 17/6/2026 | The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks. | |
| Modificada | Alta (8.8) | 0.32% | — | Webpushr WEB Push Notifications | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability leading to Local File Inclusion (LF) in Webpushr Web Push Notifications Web Push Notifications – Webpushr plugin <= 4.34.0 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Sendpulse Free WEB Push | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SendPulse SendPulse Free Web Push plugin <= 1.3.1 versions. | |
| Modificada | Media (6.1) | 0.90% | — | Feedify WEB Push Notifications | 10/9/2021 | 17/6/2026 | The Feedify – Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_msg parameter found in the ~/includes/base.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.8. | |
| Modificada | Media (5.4) | 1.1% | — | Onesignal-free-web-push-notifications | 30/8/2019 | 17/6/2026 | The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter. |