Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

403.004 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.29%—Salonbookingsystem Salon Booking SystemAI6/10/20266/10/2026
Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions.
AplazadaAlta (7.1)0.24%—Wpmailster WP MailsterAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions.
AplazadaMedia (6.5)0.35%—WordpressAI6/10/20266/10/2026
Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions.
AplazadaAlta (8.8)0.32%—WP User ProfilesAI6/10/20266/10/2026
Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions.
AplazadaMedia (5.3)0.32%—Zero SpamAI6/10/20266/10/2026
Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.
AplazadaAlta (7.1)0.24%—Epiph Form BlockAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions.
AplazadaAlta (7.2)0.32%—Codection Import AND Export Users AND CustomersAI6/10/20266/10/2026
Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions.
AplazadaAlta (8.1)0.26%—HaakenAI6/10/20266/10/2026
Unauthenticated PHP Object Injection in Haaken <= 1.5 versions.
AplazadaAlta (7.1)0.18%—GivewpAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions.
AplazadaAlta (7.1)0.18%—Thimpress LearnpressAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions.
AplazadaAlta (7.3)0.29%—PicuAI6/10/20266/10/2026
Unauthenticated Broken Access Control in picu <= 3.10.1 versions.
AplazadaAlta (8.1)0.28%—GivewpAI6/10/20266/10/2026
Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions.
AplazadaMedia (6.9)0.41%—Stylemixthemes MotorsAI6/10/20266/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124.
AplazadaAlta (7.1)0.24%—PicuAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions.
AplazadaAlta (7.1)0.24%—CharitableAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions.
AplazadaAlta (7.2)0.32%—Blubrry PowerpressAI6/10/20266/10/2026
Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions.
AplazadaAlta (7.5)0.30%—GroundhoggAI6/10/20266/10/2026
Unauthenticated Sensitive Data Exposure in Groundhogg <= 4.8.3 versions.
AplazadaAlta (7.1)0.15%—Tomlister Payflex Payment GatewayAI6/10/20266/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1.
AplazadaAlta (8.5)0.22%—Wpo365AI6/10/20266/10/2026
Subscriber Broken Access Control in WPO365 <= 44.1 versions.
AplazadaAlta (7.5)0.30%—Xserver MigratorAI6/10/20266/10/2026
Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions.
AplazadaMedia (5.3)0.26%—Webfactoryltd Advanced Google RecaptchaAI6/10/20266/10/2026
Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions.
AplazadaCrítica (9.3)0.37%—SchmoozeAI6/10/20266/10/2026
This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys.…
AplazadaMedia (6.9)0.26%—Sourcecodester Simple Student Information SystemAI6/10/20266/10/2026
A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in sql injection. The attack can be initiated remotely.
Pendiente de análisisMedia (5.4)0.19%—KeycloakAI6/10/20266/10/2026
A flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities to obtain security tokens. The issue occurs because the flow fails to check the minimum authentication level required by a client…
AplazadaMedia (6.5)0.16%—Elegro Crypto PaymentAI6/10/20266/10/2026
The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been…