Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2757▲ 47 respecto a la semana anterior
Críticas / altas1482▲ 372 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.31% | — | Ba-booking BA Book EverythingAI | 2/10/2026 | 2/10/2026 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (5.5) | 0.29% | — | Modelcontextprotocol MCP Server FetchAIModelcontextprotocol MCP Server EverythingAI | 2/10/2026 | 2/10/2026 | A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack… | |
| Aplazada | Alta (7.2) | 0.24% | — | Ba-booking BA Book EverythingAI | 25/9/2026 | 25/9/2026 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.5) | 0.23% | — | Pencidesign Penci Filter EverythingAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Filter Everything penci-filter-everything allows Stored XSS.This issue affects Penci Filter Everything: from n/a through <= 1.7. | |
| Aplazada | Media (4.3) | 0.18% | — | Ba-booking BA Book EverythingAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in bookingalgorithms BA Book Everything ba-book-everything allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BA Book Everything: from n/a through <= 1.8.16. | |
| Aplazada | Media (6.4) | 0.18% | — | Ba-booking BA Book EverythingAI | 19/12/2025 | 17/6/2026 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-form shortcode in all versions up to, and including, 1.8.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.8) | 0.09% | — | Voidtools EverythingAI | 4/11/2025 | 17/6/2026 | The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege escalation(only if chained with other elements)… | |
| Aplazada | Media (6.5) | 0.17% | — | Pencidesign Penci Filter EverythingAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Filter Everything penci-filter-everything allows DOM-Based XSS.This issue affects Penci Filter Everything: from n/a through < 1.7. | |
| Aplazada | Media (5.9) | 0.22% | — | Everythingwp Risk Free Cash ON Delivery COD WoocommerceAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in everythingwp Risk Free Cash On Delivery (COD) – WooCommerce risk-free-cash-on-delivery-cod-woocommerce allows Stored XSS.This issue affects Risk Free Cash On Delivery (COD) – WooCommerce: from n/a through <= 1.0.4. | |
| Aplazada | Alta (7.1) | 0.13% | — | Ethoseo Track EverythingAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ethoseo Track Everything track-everything allows Stored XSS.This issue affects Track Everything: from n/a through <= 2.0.1. | |
| Modificada | Media (6.1) | 0.31% | — | Ba-booking BA Book Everything | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bookingalgorithms BA Book Everything ba-book-everything.This issue affects BA Book Everything: from n/a through <= 1.6.20. | |
| Analizada | Media (5.3) | 0.43% | — | Ba-booking BA Book Everything | 24/9/2024 | 17/6/2026 | The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and including, 1.6.20. This is due to the reset_user_password() function not verifying a user's identity prior to setting a password. This makes it possible for unauthenticated attackers to reset any user's… | |
| Analizada | Alta (8.8) | 0.32% | — | Ba-booking BA Book Everything | 24/9/2024 | 17/6/2026 | The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20. This is due to missing or incorrect nonce validation on the my_account_update() function. This makes it possible for unauthenticated attackers to update a user's account details via a… | |
| Modificada | Media (5.4) | 0.29% | — | Ba-booking BA Book Everything | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8. | |
| Modificada | Media (5.4) | 0.33% | — | Ba-booking BA Book Everything | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8. | |
| Modificada | Media (5.4) | 0.32% | — | Ba-booking BA Book Everything | 16/4/2024 | 17/6/2026 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'all-items' shortcode in all versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping on user supplied attributes such as 'classes'. This makes it possible for authenticated… | |
| Modificada | Alta (8.8) | 0.58% | — | Ba-booking BA Book Everything | 15/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Booking Algorithms BA Book Everything.This issue affects BA Book Everything: from n/a through 1.6.4. | |
| Modificada | Media (5.5) | 0.37% | — | Voidtools Everything | 12/4/2023 | 17/6/2026 | Void Tools Everything lower than v1.4.1.1022 was discovered to contain a Regular Expression Denial of Service (ReDoS). | |
| Modificada | Media (6.1) | 1.1% | — | Voidtools Everything | 14/7/2021 | 17/6/2026 | HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote attacker to inject an arbitrary script or alter the website that uses the product. | |
| Modificada | Alta (7.8) | 0.56% | — | Voidtools Everything | 21/8/2020 | 17/6/2026 | voidtools Everything before 1.4.1 Beta Nightly 2020-08-18 allows privilege escalation via a Trojan horse urlmon.dll file in the installation directory. NOTE: this is only relevant if low-privileged users can write to the installation directory, which may be considered a site-specific configuration error | |
| Modificada | Crítica (9.8) | 1.8% | — | Search Everything Project Search Everything | 22/8/2019 | 17/6/2026 | The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316. | |
| Modificada | Crítica (9.8) | 1.9% | — | Search Everything Project Search Everything | 22/8/2019 | 17/6/2026 | The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316. | |
| Modificada | Media (6.8) | 0.95% | — | Zemanta Search Everything | 22/5/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Search Everything plugin before 8.1.1 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Alta (7.5) | 2.2% | — | Zemanta Search Everything | 9/3/2014 | 17/6/2026 | SQL injection vulnerability in se_search_default in the Search Everything plugin before 7.0.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the s parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 2.4% | — | THE Everything Development Company THE Everything Development Engine | 12/2/2008 | 16/6/2026 | The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext in a database, which makes it easier for context-dependent attackers to obtain access to user accounts. |