Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
–

178 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.27%—Wpchill Modula Image GalleryAI25/9/202625/9/2026
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author-level access and above,…
AplazadaAlta (7.5)0.39%—Wpchill Modula Image GalleryAI25/9/202625/9/2026
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being hooked to wp_head on every frontend request and looking up any post via…
AplazadaAlta (7.7)0.44%—PTC Windchill PdmlinkAIPTC FlexplmAI20/8/20269/9/2026
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
AplazadaCrítica (9.2)0.56%—PTC WindchillAIPTC FlexplmAI20/8/20269/9/2026
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
AplazadaCrítica (9.3)0.43%—PTC Windchill Risk AND ReliabilityAI20/8/20269/9/2026
A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.
AplazadaAlta (8.7)0.51%—Inventec Appliances Chiline CloudAI11/8/202626/8/2026
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.
AplazadaMedia (5.4)0.23%—Child Pages CardAI6/8/202626/8/2026
The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page, allowing users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaBaja (2.7)0.30%—Wpchill Simple RestrictAI2/8/202626/8/2026
The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with…
AplazadaAlta (8.1)0.47%—Mainwp ChildAI27/7/202627/7/2026
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an…
AplazadaMedia (6.5)0.22%—Wpchill Modula Image GalleryAI23/7/202623/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.
AplazadaAlta (8.2)0.17%—Child Theme WizardAI26/6/202626/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions.
AplazadaAlta (7.5)0.31%—Mainwp ChildAI25/6/202629/6/2026
Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.
AnalizadaCrítica (9.3)46%⚠ Explotación activaPTC FlexplmPTC Windchill Pdmlink18/6/20261/8/2026
—
AplazadaAlta (7.2)0.24%—Mitsubishielectric Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Packaged AIR ConditionersAIMitsubishielectric RefrigeratorsAI+1217/6/202617/6/2026
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump…
AplazadaMedia (6.5)0.22%—Wpchill Modula Image GalleryAI15/6/202617/6/2026
Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions.
AplazadaMedia (5.3)0.29%—Wpchill Rsvp AND Event ManagementAI25/5/202620/7/2026
Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RSVP and Event Management: from n/a through 2.7.16.
AplazadaMedia (4.3)0.27%—Wpchill Image Photo Gallery Final Tiles GridAI20/5/202624/7/2026
Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11.
AplazadaMedia (4.3)0.20%—Ostheimer Child Height PredictorAI20/5/202624/7/2026
The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.3. This is due to missing nonce verification in the options() function, which handles plugin settings updates. The form template does not include a wp_nonce_field() call, and…
AplazadaMedia (6.4)0.26%—Caterhamcomputing CC Child PagesAI14/5/202617/6/2026
The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
AplazadaMedia (5.3)0.33%—Wpchill Rsvp AND Event ManagementAI8/4/202624/7/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Chill RSVP and Event Management rsvp allows Retrieve Embedded Sensitive Data.This issue affects RSVP and Event Management: from n/a through <= 2.7.16.
AplazadaBaja (2.7)0.28%—WP Chill Image Photo Gallery Final Tiles Grid Gallery LiteAI8/4/202624/7/2026
Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.11.
AplazadaMedia (5.3)0.44%—Mainwp Child ReportsAI8/4/202624/7/2026
The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaBaja (1.9)1.4%—Chrischinchilla Vale-mcpAI6/4/202624/7/2026
A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.ts of the component HTTP Interface. The manipulation of the argument config_path results in os command injection. Attacking locally is a requirement. The exploit has been…
Pendiente de análisisCrítica (9.3)0.76%—PTC WindchillAIPTC FlexplmAI23/3/202617/6/2026
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0,…
AplazadaAlta (8.5)0.39%—Wpchill Filr ProtectionAI5/3/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue affects Filr: from n/a through <= 1.2.14.