Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2561▼ 314 respecto a la semana anterior
Críticas / altas1347▲ 83 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.23% | — | Webxiaowei FoldersAI | 27/11/2025 | 17/6/2026 | The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'wcp_change_post_folder' function in all versions up to, and including, 3.1.5. This makes it possible for… | |
| Analizada | Media (6.5) | 0.49% | — | Hirewebxperts Passwords Manager | 16/1/2025 | 17/6/2026 | The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX actions in all versions up to, and including, 1.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Media (4.3) | 0.39% | — | Hirewebxperts Passwords Manager | 16/1/2025 | 17/6/2026 | The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pms_save_setting' and 'post_new_pass' AJAX actions in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Analizada | Alta (7.5) | 0.51% | — | Hirewebxperts Passwords Manager | 16/1/2025 | 17/6/2026 | The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fuctions in all versions up to, and including, 1.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.48% | — | Webxmedia Bulk Change RoleAI | 30/10/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in webxmedia Bulk Change Role bulk-role-change allows Privilege Escalation.This issue affects Bulk Change Role: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.25% | — | Scrollbar BY WebxappAI | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in siteengineai Scrollbar by webxapp – Best vertical/horizontal scrollbars plugin scrollbar-by-webxapp allows Stored XSS.This issue affects Scrollbar by webxapp – Best vertical/horizontal scrollbars plugin: from n/a… | |
| Modificada | Alta (7.5) | 5.1% | — | Webxell Editor | 15/7/2008 | 16/6/2026 | Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute arbitrary code by uploading a .php file with a jpeg content type, then accessing it via a direct request to the file in upload/. | |
| Modificada | Media (5) | 1.3% | — | WEB Crossing Webx | 31/12/2001 | 16/6/2026 | WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions. | |
| Modificada | Media (5) | 8.5% | — | Datawizard Webxq | 27/6/2001 | 16/6/2026 | Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack. |