Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

340 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.30%—Wptools Extra Product OptionsAI30/9/202630/9/2026
Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
AplazadaMedia (5.3)0.24%—Solace ExtraAI30/9/202630/9/2026
The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.
Pendiente de análisisAlta (7.3)0.14%—GNU LibextractorAI25/9/202630/9/2026
GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated…
RechazadaSin puntuar0.17%—Oceanwp Ocean ExtraAI23/9/20261/10/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. False positive detection.
Pendiente de análisisAlta (8.7)0.74%—GNU LibextractorAI14/9/202624/9/2026
GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB on the stack, causing stack overflow and…
AplazadaMedia (5.3)0.24%—Solace ExtraAI2/9/20263/9/2026
The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to read the content of non-published (draft, pending, private, and trashed) Site Builder parts that WordPress would otherwise not serve.
AplazadaAlta (7.5)0.50%—Webtoffee Extra Product Options AND ADD ONS FOR WoocommerceAI18/8/202620/8/2026
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
AplazadaAlta (8.1)0.28%—Max-mapper Extract-zipAI17/8/20269/9/2026
extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and…
AplazadaAlta (7.5)0.45%—Webtoffee Extra Product Options Builder FOR WoocommerceAI16/8/202626/8/2026
The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product Options Builder for WooCommerce WordPress…
AplazadaCrítica (9.1)0.60%—Solace ExtraAI16/8/202620/8/2026
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies…
AplazadaMedia (6.5)0.22%—Bestwebsoft Subscriber Cross Site Scripting Profile Extra FieldsAI13/8/202614/8/2026
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
AplazadaAlta (7.1)0.32%—Solace ExtraAI13/8/202614/8/2026
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
AplazadaMedia (4.3)0.14%—Solace ExtraAI9/8/202626/8/2026
The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.
AplazadaAlta (8.1)0.38%—Solace ExtraAI8/8/202626/8/2026
The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported…
AplazadaAlta (8.8)0.79%—Extra Checkout OptionsAI29/7/202630/7/2026
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged…
AplazadaMedia (6.5)0.33%—Edgarrojas Extra Product Options Builder FOR WoocommerceAI13/7/202613/7/2026
Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extra Product Options Builder for WooCommerce: from n/a through <= 1.2.167.
AplazadaMedia (5.3)0.47%—Solace ExtraAI11/7/202613/7/2026
The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete all content previously…
AplazadaMedia (6.5)0.22%—Averta Shortcodes AND Extra Features FOR Phlox ThemeAI1/7/20262/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS. This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.16.
AnalizadaAlta (8.6)0.53%—Max-mapper Extract-zip26/6/20266/7/2026
extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how…
AnalizadaAlta (8.8)0.48%—Joomlaboat Extra Search19/6/202619/8/2026
Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=com_extrasearch parameter and malicious SQL in the…
Pendiente de análisisMedia (5.6)0.14%—Gnome Tracker-extract-mp3AIGnome Tracker-minersAI16/6/202617/6/2026
A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS)…
AplazadaMedia (6.4)0.32%—Extra Settings FOR RocketchatAI9/6/202623/7/2026
The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat' shortcode's 'title' attribute in versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping in the rxstg_shortcode() function, which concatenates the…
AplazadaMedia (5.5)0.29%—Sourcecodester SEO Meta TAG ExtractorAI1/6/202622/7/2026
A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and…
AplazadaMedia (5.4)0.29%—Oceanwp Ocean ExtraAI7/4/202617/6/2026
Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ocean Extra: from n/a through 2.5.3.
AnalizadaCrítica (9.8)3.6%—Dbashford Textract25/3/202617/6/2026
textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization