Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.31% | — | Webp ExpressAI | 4/12/2025 | 17/6/2026 | The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and including, 0.25.9. This is due to the plugin not properly randomizing the name of the config file to prevent direct access on NGINX. This makes it possible for unauthenticated attackers to extract… | |
| Modificada | Media (5.4) | 0.79% | — | Bitwise-it Webp Express | 30/8/2019 | 17/6/2026 | The webp-express plugin before 0.14.8 for WordPress has stored XSS. | |
| Modificada | Alta (7.5) | 1.8% | — | Webp Express Project Webp Express | 22/8/2019 | 17/6/2026 | The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading. |