Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.27% | — | Wpchill Modula Image GalleryAI | 25/9/2026 | 25/9/2026 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author-level access and above,… | |
| Aplazada | Alta (7.5) | 0.39% | — | Wpchill Modula Image GalleryAI | 25/9/2026 | 25/9/2026 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up to, and including, 3.0.1. This is due to the Modula_Meta::add_metas() function being hooked to wp_head on every frontend request and looking up any post via… | |
| Aplazada | Alta (7.7) | 0.44% | — | PTC Windchill PdmlinkAIPTC FlexplmAI | 20/8/2026 | 9/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. | |
| Aplazada | Crítica (9.2) | 0.56% | — | PTC WindchillAIPTC FlexplmAI | 20/8/2026 | 9/9/2026 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. | |
| Aplazada | Crítica (9.3) | 0.43% | — | PTC Windchill Risk AND ReliabilityAI | 20/8/2026 | 9/9/2026 | A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition. | |
| Aplazada | Alta (8.7) | 0.51% | — | Inventec Appliances Chiline CloudAI | 11/8/2026 | 26/8/2026 | Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data. | |
| Aplazada | Media (5.4) | 0.23% | — | Child Pages CardAI | 6/8/2026 | 26/8/2026 | The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page, allowing users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Baja (2.7) | 0.30% | — | Wpchill Simple RestrictAI | 2/8/2026 | 26/8/2026 | The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with… | |
| Aplazada | Alta (8.1) | 0.47% | — | Mainwp ChildAI | 27/7/2026 | 27/7/2026 | The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an… | |
| Aplazada | Media (6.5) | 0.22% | — | Wpchill Modula Image GalleryAI | 23/7/2026 | 23/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30. | |
| Aplazada | Alta (8.2) | 0.17% | — | Child Theme WizardAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions. | |
| Aplazada | Alta (7.5) | 0.31% | — | Mainwp ChildAI | 25/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions. | |
| Analizada | Crítica (9.3) | 46% | ⚠ Explotación activa | PTC FlexplmPTC Windchill Pdmlink | 18/6/2026 | 1/8/2026 | — | |
| Aplazada | Alta (7.2) | 0.24% | — | Mitsubishielectric Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Packaged AIR ConditionersAIMitsubishielectric RefrigeratorsAI+12 | 17/6/2026 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump… | |
| Aplazada | Media (6.5) | 0.22% | — | Wpchill Modula Image GalleryAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Wpchill Rsvp AND Event ManagementAI | 25/5/2026 | 20/7/2026 | Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RSVP and Event Management: from n/a through 2.7.16. | |
| Aplazada | Media (4.3) | 0.27% | — | Wpchill Image Photo Gallery Final Tiles GridAI | 20/5/2026 | 24/7/2026 | Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11. | |
| Aplazada | Media (4.3) | 0.20% | — | Ostheimer Child Height PredictorAI | 20/5/2026 | 24/7/2026 | The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.3. This is due to missing nonce verification in the options() function, which handles plugin settings updates. The form template does not include a wp_nonce_field() call, and… | |
| Aplazada | Media (6.4) | 0.26% | — | Caterhamcomputing CC Child PagesAI | 14/5/2026 | 17/6/2026 | The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (5.3) | 0.33% | — | Wpchill Rsvp AND Event ManagementAI | 8/4/2026 | 24/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Chill RSVP and Event Management rsvp allows Retrieve Embedded Sensitive Data.This issue affects RSVP and Event Management: from n/a through <= 2.7.16. | |
| Aplazada | Baja (2.7) | 0.28% | — | WP Chill Image Photo Gallery Final Tiles Grid Gallery LiteAI | 8/4/2026 | 24/7/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.11. | |
| Aplazada | Media (5.3) | 0.44% | — | Mainwp Child ReportsAI | 8/4/2026 | 24/7/2026 | The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Baja (1.9) | 1.4% | — | Chrischinchilla Vale-mcpAI | 6/4/2026 | 24/7/2026 | A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.ts of the component HTTP Interface. The manipulation of the argument config_path results in os command injection. Attacking locally is a requirement. The exploit has been… | |
| Pendiente de análisis | Crítica (9.3) | 0.76% | — | PTC WindchillAIPTC FlexplmAI | 23/3/2026 | 17/6/2026 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. This issue affects Windchill PDMLink: 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0,… | |
| Aplazada | Alta (8.5) | 0.39% | — | Wpchill Filr ProtectionAI | 5/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue affects Filr: from n/a through <= 1.2.14. |