Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
188 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.33% | — | LWS OptimizeAI | 2/8/2026 | 26/8/2026 | The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds. | |
| Aplazada | Alta (8.1) | 0.66% | — | Image OptimizerAI | 2/7/2026 | 2/7/2026 | The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file deletion operations without verifying they… | |
| Aplazada | Alta (8.8) | 1.1% | — | Offload AI Optimize With Cloudflare ImagesAI | 18/6/2026 | 18/6/2026 | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the… | |
| Aplazada | Alta (7.2) | 0.54% | — | Shortpixel Image OptimizerAI | 15/6/2026 | 17/6/2026 | Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions. | |
| Aplazada | Media (4.9) | 0.34% | — | Lwsoptimize LWS OptimizeAI | 13/6/2026 | 23/7/2026 | The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.3.19. This is due to the combine_current_css() function trusting <link rel="stylesheet" href="..."> values harvested from page HTML and converting same-site URLs to… | |
| Aplazada | Alta (8.8) | 0.45% | — | AutoptimizeAIClearfy CacheAISiteground Speed OptimizerAI | 18/5/2026 | 17/6/2026 | The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular… | |
| Aplazada | Alta (8.1) | 0.36% | — | SqloptimizerAI | 13/5/2026 | 17/6/2026 | Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled. | |
| Aplazada | Alta (8.1) | 1.2% | — | Wpoptimize WP OptimizeAI | 7/5/2026 | 17/6/2026 | The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4.5.2 This makes it… | |
| Pendiente de análisis | Alta (7.3) | 0.15% | — | HP System OptimizerAI | 15/4/2026 | 17/6/2026 | HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate this potential vulnerability. | |
| Aplazada | Media (5.4) | 0.38% | — | Updraftplus Wp-optimizeAI | 10/4/2026 | 17/6/2026 | The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly invoking… | |
| Aplazada | Media (5.4) | 0.31% | — | Shortpixel Image OptimizerAI | 26/3/2026 | 17/6/2026 | The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to, and including, 6.4.3. This is due to insufficient output escaping in the getEditorPopup() function and its corresponding media-popup.php template. Specifically, the… | |
| Pendiente de análisis | Alta (7.8) | 0.21% | — | Nvidia Model OptimizerAI | 24/3/2026 | 17/6/2026 | NVIDIA Model Optimizer for Windows and Linux contains a vulnerability in the ONNX quantization feature, where a user could cause unsafe deserialization by providing a specially crafted input file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and… | |
| Aplazada | Media (6.4) | 0.20% | — | AutoptimizeAI | 21/3/2026 | 17/6/2026 | The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing in all versions up to, and including, 3.1.14. This is due to the use of an overly permissive regular expression in the `add_lazyload` function that replaces all occurrences of `\ssrc=` in image tags… | |
| Aplazada | Media (6.4) | 0.25% | — | AutoptimizeAI | 21/3/2026 | 17/6/2026 | The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value in all versions up to, and including, 3.1.14. This is due to insufficient input sanitization in the `ao_metabox_save()` function and missing output escaping when the value is rendered into a `<link>`… | |
| Analizada | Alta (7.8) | 0.18% | — | Dell Optimizer | 3/3/2026 | 17/6/2026 | Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Aplazada | Media (6.5) | 0.27% | — | Arya Dhiratara Optimize More ImagesAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Arya Dhiratara Optimize More! – Images optimize-more-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Optimize More! – Images: from n/a through <= 1.1.3. | |
| Aplazada | Media (4.3) | 0.33% | — | Elementor Image OptimizerAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Optimizer by Elementor: from n/a through <= 1.7.1. | |
| Aplazada | Alta (8.7) | 0.40% | — | FileoptimizerAI | 18/2/2026 | 17/6/2026 | FileOptimizer 14.00.2524 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the FileOptimizer32.ini configuration file. Attackers can overwrite the TempDirectory parameter with a 5000-character buffer to cause the application to crash when opening options. | |
| Aplazada | Media (6.4) | 0.23% | — | Robin Image OptimizerAI | 5/2/2026 | 17/6/2026 | The Robin Image Optimizer – Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of a Media Library image in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (4.9) | 0.59% | — | Shortpixel Image OptimizerAI | 5/2/2026 | 17/6/2026 | The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'loadFile' parameter in all versions up to, and including, 6.4.2 due to insufficient path validation and sanitization in the 'loadLogFile' AJAX action. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.26% | — | Passionatebrains ADD Expires Headers AND Optimized MinifyAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Passionate Brains Add Expires Headers & Optimized Minify add-expires-headers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Add Expires Headers & Optimized Minify: from n/a through <= 3.2.0. | |
| Aplazada | Media (4.3) | 0.30% | — | Crush Pics Image OptimizerAI | 14/1/2026 | 17/6/2026 | The Crush.pics Image Optimizer - Image Compression and Optimization plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on multiple functions in all versions up to, and including, 1.8.7. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Modificada | Alta (8.1) | 0.48% | — | Qodeinteractive Optimize | 8/1/2026 | 30/9/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimizewp allows PHP Local File Inclusion.This issue affects Optimize: from n/a through < 2.4. | |
| Aplazada | Alta (7.1) | 0.22% | — | Plugin OptimizerAI | 29/12/2025 | 17/6/2026 | Missing Authorization vulnerability in pluginoptimizer Plugin Optimizer plugin-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Plugin Optimizer: from n/a through <= 1.3.7. | |
| Aplazada | Media (6.5) | 0.25% | — | Anton Vanyukov Offload AI Optimize With Cloudflare ImagesAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Offload, AI & Optimize with Cloudflare Images: from n/a through <= 1.9.5. |