Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.20% | — | Fox-themes Whizz-pluginsAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Whizz Plugins whizz-plugins allows Reflected XSS.This issue affects Whizz Plugins: from n/a through <= 1.9. | |
| Modificada | Crítica (9.8) | 0.36% | — | Upqode Whizzy | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in UPQODE Whizzy.This issue affects Whizzy: from n/a through 1.1.18. | |
| Aplazada | Media (6.5) | 0.36% | — | Upqode WhizzAI | 31/3/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in UPQODE Whizz.This issue affects Whizzy: from n/a through 1.1.18. | |
| Modificada | Alta (8.1) | 0.64% | — | Browserweb INC Whizz | 24/4/2017 | 17/6/2026 | There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request. | |
| Modificada | Media (6.1) | 3.4% | — | Browserweb Whizz | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin whizz v1.0.7 | |
| Modificada | Media (4.3) | 1.3% | — | Unverse.net Abitwhizzy | 30/3/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in aBitWhizzy allow remote attackers to inject arbitrary web script or HTML via the d parameter to (1) whizzery/whizzypic.php or (2) whizzery/whizzylink.php. | |
| Modificada | Baja (2.6) | 3.2% | — | Unverse.net Abitwhizzy | 30/3/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in aBitWhizzy allow remote attackers to list arbitrary directories via a .. (dot dot) in the d parameter to (1) whizzery/whizzypic.php or (2) whizzery/whizzylink.php, different vectors than CVE-2006-6384. | |
| Modificada | Alta (7.8) | 1.5% | — | John Goodman Abitwhizzy | 7/12/2006 | 16/6/2026 | Absolute path traversal vulnerability in abitwhizzy.php before 20061204 allows remote attackers to read arbitrary files via an absolute pathname in the Filename text window (f parameter), a variant of CVE-2006-6084. | |
| Modificada | Media (5) | 3.9% | — | Unverse.net Abitwhizzy | 24/11/2006 | 16/6/2026 | Directory traversal vulnerability in abitwhizzy.php in aBitWhizzy allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. NOTE: some of these details are obtained from third party information. |