Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.3) | 0.43% | — | Guardrails-detectorsAI | 10/7/2026 | 31/8/2026 | A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially… | |
| Pendiente de análisis | Crítica (9.3) | 0.53% | — | Guardrails-detectorsAI | 10/7/2026 | 30/9/2026 | A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from… | |
| Aplazada | Media (4.3) | 0.15% | — | Comment Info DetectorAI | 3/10/2025 | 17/6/2026 | The Comment Info Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing nonce validation on the options.php file when handling form submissions. This makes it possible for unauthenticated attackers to modify plugin settings via a… | |
| Analizada | Crítica (9.8) | 7.8% | 💥 Exploit | WP Mobile Detector Project WP Mobile Detector | 19/7/2025 | 17/6/2026 | The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code… | |
| Aplazada | Media (6.5) | 0.23% | — | Getadmiral AD Blocking DetectorAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Admiral Ad Blocking Detector ad-blocking-detector allows Stored XSS.This issue affects Ad Blocking Detector: from n/a through <= 3.6.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Pierre Lannoy Device DetectorAI | 18/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Device Detector device-detector allows Reflected XSS.This issue affects Device Detector: from n/a through <= 4.2.0. | |
| Aplazada | Media (5.4) | 0.40% | — | Sureshchand CHP ADS Block DetectorAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Suresh Chand CHP Ads Block Detector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CHP Ads Block Detector: from n/a through 3.9.5. | |
| Aplazada | Media (6.1) | 0.29% | — | Wordpress Drag Drop Builder Human Face Detector PRE Built Templates Spam Protection User Email Notifications MoreAI | 7/12/2024 | 17/6/2026 | The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.19 due to insufficient input sanitization and output escaping.… | |
| Aplazada | Crítica (9.8) | 0.52% | — | Phoenixheart Referrer DetectorAI | 16/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Phoenixheart Referrer Detector referrer-detector allows Object Injection.This issue affects Referrer Detector: from n/a through <= 4.2.1.0. | |
| Modificada | Media (5.4) | 0.47% | — | Sureshchand CHP ADS Block Detector | 31/8/2023 | 17/6/2026 | The CHP Ads Block Detector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings reachable though an AJAX action in versions up to, and including, 3.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level… | |
| Modificada | Media (4.3) | 0.52% | — | Sureshchand CHP ADS Block Detector | 31/8/2023 | 17/6/2026 | The CHP Ads Block Detector plugin for WordPress is vulnerable to unauthorized plugin settings update and reset due to a missing capability check on the chp_abd_action function in versions up to, and including, 3.9.4. This makes it possible for subscriber-level attackers to change or reset plugin settings.… | |
| Modificada | Media (4.3) | 0.30% | — | Sureshchand CHP ADS Block Detector | 31/8/2023 | 17/6/2026 | The CHP Ads Block Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.4. This is due to missing or incorrect nonce validation on the chp_abd_action function. This makes it possible for unauthenticated attackers to update or reset plugin settings via a forged… | |
| Modificada | Alta (7.5) | 0.86% | — | Getadmiral AD Blocking Detector | 10/3/2023 | 17/6/2026 | A vulnerability has been found in Ad Blocking Detector Plugin up to 1.2.1 on WordPress and classified as problematic. This vulnerability affects unknown code of the file ad-blocking-detector.php. The manipulation leads to information disclosure. The attack can be initiated remotely. Upgrading to version 1.2.2 is able… | |
| Modificada | Media (5.4) | 0.79% | — | Jenkins Application Detector | 17/5/2022 | 17/6/2026 | Jenkins Application Detector Plugin 1.0.8 and earlier does not escape the name of Chois Application Version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (7.5) | 0.95% | — | Bluedon Internet Access Detector | 24/3/2022 | 17/6/2026 | Bluedon Information Security Technologies Co.,Ltd Internet Access Detector v1.0 was discovered to contain an information leak which allows attackers to access the contents of the password file via unspecified vectors. | |
| Modificada | Media (6.1) | 0.73% | — | Detector Project Detector | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in _contactform.inc.php in Detector 0.8.5 and below version allows remote attackers to inject arbitrary web script or HTML via the cid parameter. | |
| Modificada | Alta (7.8) | 0.47% | — | Maxpcsecure MAX Spyware Detector | 5/2/2021 | 17/6/2026 | In Max Secure Max Spyware Detector 1.0.0.044, the driver file (MaxProc64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x2200019. (This also extends to the various other products from Max Secure that include… | |
| Modificada | Alta (7.2) | 1.3% | — | Charcoal-se Smokedetector | 29/7/2019 | 17/6/2026 | SmokeDetector intentionally does automatic deployments of updated copies of SmokeDetector without server operator authority. | |
| Modificada | Media (5.4) | 0.27% | — | Zombie Detector Project Zombie Detector | 22/9/2014 | 17/6/2026 | The Zombie Detector (aka com.jimmybolstad.zombiedetector) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.1) | 1.8% | — | Apple Data Detectors Engine | 4/8/2008 | 16/6/2026 | Unspecified vulnerability in Data Detectors Engine in Apple Mac OS X 10.5.4 allows attackers to cause a denial of service (resource consumption) via crafted textual content in messages. | |
| Modificada | Media (5.1) | 2.0% | — | Cisco Anomaly Guard ModuleCisco GuardCisco Traffic Anomaly Detector Module | 18/2/2006 | 16/6/2026 | The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a "tacacs-server host" command, allows remote attackers to bypass… |