Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.22%—Wpo365AI6/10/20266/10/2026
Subscriber Broken Access Control in WPO365 <= 44.1 versions.
AplazadaAlta (8.8)0.25%—Wpo365 LoginAI23/7/202624/7/2026
The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options'…
AplazadaMedia (6.4)0.27%—Marco VAN Wieren Wpo365 LoginAI22/1/202617/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Marco van Wieren WPO365 wpo365-login allows Server Side Request Forgery.This issue affects WPO365: from n/a through <= 40.0.
AnalizadaMedia (6.1)0.29%—Wpo365 Microsoft 365 Graph Mailer24/2/202517/6/2026
The WPO365 | MICROSOFT 365 GRAPH MAILER plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible for unauthenticated attackers to redirect users to…
ModificadaMedia (6.1)0.34%—Wpo365 Mail Integration FOR Office 365 / Outlook23/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin <= 1.9.0 versions.
ModificadaMedia (6.1)0.97%—Wpo365 Wordpress + Azure AD / Microsoft Office 36519/11/202117/6/2026
The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper…
ModificadaAlta (7.5)2.1%—Wpo365 Wordpress + Azure AD / Microsoft Office 3652/10/202017/6/2026
The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.
Orbitaley — Vulnerabilidades