Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.45% | — | TZ Weekly Radio ScheduleAI | 18/9/2026 | 18/9/2026 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database. | |
| Aplazada | Alta (8.6) | 0.45% | — | TZ Weekly Radio ScheduleAI | 18/9/2026 | 18/9/2026 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database. | |
| Aplazada | Media (6.5) | 0.40% | — | Eight DAY Week Print WorkflowAI | 12/5/2026 | 17/6/2026 | The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' parameter in the `pp-get-articles` AJAX action in all versions up to, and including, 1.2.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Aplazada | Media (4.3) | 0.26% | — | 10up Eight-day-week-print-workflowAI | 24/12/2025 | 7/10/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in 10up Eight Day Week Print Workflow eight-day-week-print-workflow allows Retrieve Embedded Sensitive Data.This issue affects Eight Day Week Print Workflow: from n/a through <= 1.2.5. | |
| Aplazada | Media (4.4) | 0.20% | — | Weekly PlannerAI | 5/12/2025 | 17/6/2026 | The Weekly Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Media (6.1) | 0.35% | — | Shenzhen Interconnection Harbor Network Technology Ofweek Online ExhibitionAI | 30/10/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Technology Co., Ltd Ofweek Online Exhibition v.1.0.0 allows a remote attacker to execute arbitrary code. | |
| Aplazada | Alta (7.1) | 0.35% | — | Pulsar WEB Design Weekly Class ScheduleAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pulsar Web Design Weekly Class Schedule allows Reflected XSS.This issue affects Weekly Class Schedule: from n/a through 3.19. | |
| Modificada | Media (5.4) | 0.65% | — | Weekly Schedule Project Weekly Schedule | 1/6/2021 | 17/6/2026 | The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize input, allowing a user to inject javascript code using the <script> HTML tags and cause a stored XSS issue | |
| Modificada | Media (6.1) | 0.93% | — | Weeklynews Theme Project Weeklynews Theme | 23/10/2019 | 17/6/2026 | The weeklynews theme before 2.2.9 for WordPress has XSS via the s parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Retale - Weekly ADS & Deals | 9/9/2014 | 17/6/2026 | The Retale - Weekly Ads & Deals (aka com.retale.android) application 2.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 1.4% | — | Earl Dunovant Week | 27/2/2010 | 16/6/2026 | The week_post_page function in the Weekly Archive by Node Type module 6.x before 6.x-2.7 for Drupal does not properly implement node access restrictions when constructing SQL queries, which allows remote attackers to read restricted node listings via unspecified vectors. | |
| Modificada | Media (5) | 1.4% | — | Weekly Drawing Contest | 22/3/2007 | 16/6/2026 | Directory traversal vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the order parameter. NOTE: another researcher disputes this vulnerability, noting that the order variable is not used in any context that allows opening files | |
| Modificada | Alta (7.5) | 1.3% | — | Weekly Drawing Contest | 22/3/2007 | 16/6/2026 | admin/contest.php in Weekly Drawing Contest 0.0.1 allows remote attackers to bypass authentication, and insert new contest information into a database, via a direct POST request. | |
| Modificada | Alta (7.5) | 1.0% | — | Weekly Drawing Contest | 22/3/2007 | 16/6/2026 | SQL injection vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to execute arbitrary SQL commands via the order parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Webwiz Database LoginWebwiz JournalWebwiz Site NewsWebwiz Weekly Poll | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site News 3.06 and earlier, (2) Journal 1.0 and earlier, (3) Polls 3.06 and earlier, and (4) and Database Login 1.71 and earlier allows remote attackers to execute arbitrary SQL commands via the txtUserName parameter. |