Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.52% | — | Gpt-crawlerAI | 28/8/2026 | 23/9/2026 | gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segments to overwrite existing files with content sourced from… | |
| Aplazada | Media (4.8) | 0.23% | — | RexcrawlerAI | 27/5/2026 | 17/6/2026 | The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Alta (7.1) | 0.50% | — | Typo3 CrawlerAI | 19/5/2026 | 17/6/2026 | The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation requires administrative privileges to configure… | |
| Aplazada | Media (6.1) | 0.27% | — | RexcrawlerAI | 21/3/2026 | 17/6/2026 | The rexCrawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' and 'regex' parameters in the search-pattern tester page in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.7) | 0.25% | — | Textcrawler PROAI | 11/2/2026 | 17/6/2026 | TextCrawler Pro 3.1.1 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized buffer in the license key field. Attackers can generate a 6000-byte payload and paste it into the activation field to trigger an application crash. | |
| Aplazada | Media (4.3) | 0.26% | — | Upress Booter Booter-bots-crawlers-managerAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in uPress Booter booter-bots-crawlers-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booter: from n/a through <= 1.5.7. | |
| Aplazada | Alta (8.1) | 0.70% | — | Catalog Importer Scraper CrawlerAI | 11/9/2025 | 17/6/2026 | The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5.1.4. This is due to reliance on a guessable numeric token (e.g. ?key= 900001705) without proper authentication, combined with the unsafe use of eval() on user-supplied input. This… | |
| Aplazada | Alta (7.1) | 0.33% | — | Idiatech Catalog Importer Scraper CrawlerAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in idiatech Catalog Importer, Scraper & Crawler intelligent-importer allows Reflected XSS.This issue affects Catalog Importer, Scraper & Crawler: from n/a through <= 5.1.3. | |
| Modificada | Media (4.8) | 0.37% | — | Stopbadbots Block BAD Bots AND Stop BAD Bots Crawlers AND Spiders AND Anti Spam Protection | 23/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bill Minozzi Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin <= 7.31 versions. | |
| Modificada | Alta (7.5) | 1.5% | — | Crawlerdetect Project Crawlerdetect | 22/3/2021 | 17/6/2026 | This affects the package es6-crawler-detect before 3.1.3. No limitation of user agent string length supplied to regex operators. | |
| Modificada | Alta (7.5) | 2.5% | — | PHP Crawler | 24/9/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the footer_file parameter. | |
| Modificada | Alta (7.8) | 3.2% | — | Newzcrawler | 16/5/2007 | 16/6/2026 | Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instability) via certain invalid strings in the URL attribute of an ENCLOSURE element, as demonstrated by a "%s" sequence, a "%Y" sequence, a "%%" sequence, and an "n," sequence. |