Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

296 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.34%—Xtendify WofficeAI6/10/20266/10/2026
Subscriber SQL Injection in Woffice <= 5.4.35 versions.
AplazadaAlta (7.2)0.31%—ExtendifyAI1/10/20263/10/2026
The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaMedia (6.4)0.16%—Nextendweb Smart Slider 3AI30/9/202630/9/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
AplazadaAlta (8.6)0.53%—Studiowombat Advanced Product Fields Extended FOR WoocommerceAI10/9/202611/9/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6.
AplazadaAlta (8.1)0.37%💥 PoCAcfextended Advanced Custom Fields ExtendedAI2/9/20263/9/2026
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities…
AplazadaAlta (8.1)0.23%—Advancedcustomfields Advanced Custom Fields ExtendedAI2/9/20263/9/2026
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a…
AplazadaMedia (6.9)0.41%—Extendthemes Kubio AI Website BuilderAI31/8/20268/9/2026
Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1.
AplazadaMedia (4.3)0.25%—Acfextended ACF ExtendedAI28/8/202628/8/2026
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
AplazadaMedia (6.4)0.32%—Nextendweb Smart Slider 3AI28/8/202628/8/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
Pendiente de análisisAlta (7)0.24%—Sonicwall NetextenderAI25/8/202628/8/2026
The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.
Pendiente de análisisAlta (8.8)0.50%—Sonicwall NetextenderAI25/8/202631/8/2026
A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to write arbitrary file as root.
AplazadaMedia (4.3)0.41%—Nextendweb Smart Slider 3AI13/7/202614/7/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles and full content excerpts of private, draft,…
AplazadaMedia (5.3)0.29%—Xtendify WofficeAI1/7/20261/7/2026
Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.
AplazadaMedia (4.3)0.12%—Extendthemes Skyline WPAI17/6/20261/10/2026
Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10.
AplazadaAlta (8.6)0.64%—Contact Form Extender FOR DiviAI15/6/202617/6/2026
Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi &#8211; Save Entries, File Upload &amp; Country Code Field <= 1.0.6 versions.
AplazadaMedia (4.9)0.84%—Nextendweb Smart Slider 3AI6/6/202623/7/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can…
AplazadaCrítica (9.8)0.87%💥 PoCAcfextended Advanced Custom Fields ExtendedAI28/5/202621/7/2026
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with…
AplazadaMedia (6.5)0.38%—Acfextended Advanced Custom Fields ExtendedAI12/5/20267/10/2026
The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for…
AplazadaMedia (5.5)0.56%—1024bit Extend-deepAI20/4/202617/6/2026
A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the file index.js. This manipulation of the argument __proto__ causes improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been…
AplazadaCrítica (9.3)0.97%—Nextendweb Smart Slider 3AI9/4/202617/6/2026
Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers,…
AplazadaMedia (5.4)0.32%—Nextendweb Smart Slider 3AI7/4/202624/7/2026
The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not call checkForCap() (which requires…
AplazadaMedia (6.5)0.22%—Extendthemes Kubio AI Page BuilderAI31/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder allows Stored XSS.This issue affects Kubio AI Page Builder: from n/a through 2.7.0.
AplazadaMedia (6.5)0.41%💥 PoCNextendweb Smart Slider 3AI27/3/202617/6/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can…
AplazadaAlta (8.8)0.52%—Wpextended WP ExtendedAI22/3/202617/6/2026
The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the `isDashboardOrProfileRequest()` method in the Menu Editor module using an insecure `strpos()` check against `$_SERVER['REQUEST_URI']` to…
AplazadaAlta (7.1)0.19%—Hugh Mungus Visitor Maps Extended Referer FieldAI20/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Visitor Maps Extended Referer Field visitor-maps-extended-referer-field allows Reflected XSS.This issue affects Visitor Maps Extended Referer Field: from n/a through <= 1.2.6.
Orbitaley — Vulnerabilidades