Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.13% | — | Code-atlantic Popup MakerAI | 2/10/2026 | 2/10/2026 | The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service… | |
| Aplazada | Alta (7.2) | 0.49% | — | Code-atlantic Popup MakerAI | 18/9/2026 | 18/9/2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.4) | 0.26% | — | Code-atlantic Popup MakerAI | 18/9/2026 | 19/9/2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Baja (3.7) | 0.33% | — | Withsecure AtlantAIWithsecure CapricornAI | 14/9/2026 | 22/9/2026 | Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine. | |
| Aplazada | Alta (8.8) | 0.44% | — | Runatlantis AtlantisAI | 28/8/2026 | 24/9/2026 | Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key and webhook secret, enabling installation token minting and webhook… | |
| Aplazada | Alta (8.1) | 0.80% | — | Runatlantis AtlantisAI | 21/8/2026 | 9/9/2026 | Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted repository-level atlantis.yaml configuration or authenticated /api/plan input before… | |
| Aplazada | Alta (7.1) | 0.25% | — | Code-atlantic Popup MakerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Code-atlantic Content ControlAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions. | |
| Aplazada | Alta (7.2) | 1.2% | — | Code-atlantic Popup MakerAI | 9/7/2026 | 9/7/2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Media (6.4) | 0.25% | — | Code-atlantic Popup MakerAI | 26/9/2025 | 17/6/2026 | The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.20.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Analizada | Media (6.9) | 0.46% | — | Runatlantis Atlantis | 6/9/2025 | 17/6/2026 | Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target known vulnerabilities associated with… | |
| Aplazada | Media (6.4) | 0.28% | — | Code-atlantic Popup MakerAI | 3/6/2025 | 17/6/2026 | The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID' parameter in all versions up to, and including, 1.20.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (6.5) | 0.25% | — | Code-atlantic Content ControlAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Iser Content Control content-control allows DOM-Based XSS.This issue affects Content Control: from n/a through <= 2.6.1. | |
| Aplazada | Media (5.3) | 0.42% | — | Code-atlantic Content ControlAI | 5/3/2025 | 17/6/2026 | The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.0 via the WordPress core search feature. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (5.4) | 0.31% | — | Code-atlantic Popup Maker | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Iser Popup Maker popup-maker allows Stored XSS.This issue affects Popup Maker: from n/a through <= 1.20.2. | |
| Modificada | Baja (3.5) | 0.42% | — | Code-atlantic Popup Maker | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1. | |
| Analizada | Media (5.4) | 0.31% | — | Code-atlantic Popup Maker | 12/12/2024 | 17/6/2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’ parameter in all versions up to, and including, 1.20.2 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Alta (7.5) | 0.51% | — | Withsecure AtlantAI | 1/12/2024 | 17/6/2026 | WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption during scanning of a PE32 file. | |
| Analizada | Alta (8.5) | 0.72% | — | Runatlantis Atlantis | 8/11/2024 | 17/6/2026 | Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and to perform actions on GitHub. When… | |
| Modificada | Crítica (9.8) | 0.41% | — | Code-atlantic Popup Maker | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Daniel Iser Popup Maker popup-maker.This issue affects Popup Maker: from n/a through <= 1.19.2. | |
| Aplazada | Alta (8.8) | 1.2% | — | Stmatlantic BOT FOR Telegram ON WoocommerceAI | 12/10/2024 | 17/6/2026 | The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'stm_wpcfto_get_settings' AJAX action in all versions up to, and including, 1.2.7. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Analizada | Media (4.8) | 0.47% | — | Code-atlantic Popup Maker | 9/9/2024 | 17/6/2026 | The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (5.4) | 0.30% | — | Code-atlantic Popup Maker | 20/8/2024 | 17/6/2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘close_text’ parameter in all versions up to, and including, 1.19.0 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (5.3) | 0.47% | — | Code-atlantic Content ControlAI | 2/5/2024 | 17/6/2026 | The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.0 via the API. This makes it possible for unauthenticated attackers to extract post titles,… | |
| Modificada | Media (5.4) | 0.34% | — | Code-atlantic Popup Maker | 9/4/2024 | 17/6/2026 | The Popup Maker – Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.18.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… |