Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.43% | — | Shortpixel Adaptive ImagesAI | 16/8/2026 | 20/8/2026 | The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.22% | — | Shortpixel Adaptive ImagesAI | 2/7/2026 | 2/7/2026 | Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions. | |
| Aplazada | Media (5.8) | 0.47% | — | Shortpixel Adaptive ImagesAI | 26/6/2026 | 26/6/2026 | Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions. | |
| Aplazada | Media (4.4) | 0.25% | — | Shortpixel Adaptive ImagesAI | 2/8/2025 | 17/6/2026 | The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.4) | 0.45% | — | Shortpixel Adaptive ImagesAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShortPixel Adaptive Images: from n/a through <= 3.10.0. | |
| Aplazada | Media (4.3) | 0.25% | — | Shortpixel Adaptive ImagesAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affects ShortPixel Adaptive Images: from n/a through <= 3.8.3. | |
| Aplazada | Media (4.4) | 0.36% | — | Shortpixel Adaptive ImagesAI | 14/5/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affects ShortPixel Adaptive Images: from n/a through <= 3.8.3. | |
| Aplazada | Media (5.3) | 0.39% | — | Shortpixel Adaptive ImagesAI | 10/4/2024 | 17/6/2026 | Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affects ShortPixel Adaptive Images: from n/a through <= 3.8.2. | |
| Modificada | Alta (8.8) | 0.31% | — | Shortpixel Adaptive Images | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin <= 3.7.1 versions. | |
| Modificada | Media (6.1) | 0.88% | — | Shortpixel Adaptive Images | 27/2/2023 | 17/6/2026 | The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against any high privilege users such as admin | |
| Modificada | Media (4.3) | 0.63% | — | Shortpixel Adaptive Images | 25/4/2022 | 17/6/2026 | Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings. | |
| Modificada | Alta (7.5) | 4.7% | — | Nevma Adaptive Images | 21/7/2019 | 17/6/2026 | An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to delete arbitrary files via the $REQUEST['adaptive-images-settings'] parameter in adaptive-images-script.php. | |
| Modificada | Alta (7.5) | 63% | — | Nevma Adaptive Images | 21/7/2019 | 17/6/2026 | A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php. |