Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
340 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.30% | — | Wptools Extra Product OptionsAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions. | |
| Aplazada | Media (5.3) | 0.24% | — | Solace ExtraAI | 30/9/2026 | 30/9/2026 | The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve. | |
| Pendiente de análisis | Alta (7.3) | 0.14% | — | GNU LibextractorAI | 25/9/2026 | 30/9/2026 | GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated… | |
| Rechazada | Sin puntuar | 0.17% | — | Oceanwp Ocean ExtraAI | 23/9/2026 | 1/10/2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. False positive detection. | |
| Pendiente de análisis | Alta (8.7) | 0.74% | — | GNU LibextractorAI | 14/9/2026 | 24/9/2026 | GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB on the stack, causing stack overflow and… | |
| Aplazada | Media (5.3) | 0.24% | — | Solace ExtraAI | 2/9/2026 | 3/9/2026 | The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to read the content of non-published (draft, pending, private, and trashed) Site Builder parts that WordPress would otherwise not serve. | |
| Aplazada | Alta (7.5) | 0.50% | — | Webtoffee Extra Product Options AND ADD ONS FOR WoocommerceAI | 18/8/2026 | 20/8/2026 | Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions. | |
| Aplazada | Alta (8.1) | 0.28% | — | Max-mapper Extract-zipAI | 17/8/2026 | 9/9/2026 | extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and… | |
| Aplazada | Alta (7.5) | 0.45% | — | Webtoffee Extra Product Options Builder FOR WoocommerceAI | 16/8/2026 | 26/8/2026 | The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product Options Builder for WooCommerce WordPress… | |
| Aplazada | Crítica (9.1) | 0.60% | — | Solace ExtraAI | 16/8/2026 | 20/8/2026 | The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies… | |
| Aplazada | Media (6.5) | 0.22% | — | Bestwebsoft Subscriber Cross Site Scripting Profile Extra FieldsAI | 13/8/2026 | 14/8/2026 | Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. | |
| Aplazada | Alta (7.1) | 0.32% | — | Solace ExtraAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions. | |
| Aplazada | Media (4.3) | 0.14% | — | Solace ExtraAI | 9/8/2026 | 26/8/2026 | The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates. | |
| Aplazada | Alta (8.1) | 0.38% | — | Solace ExtraAI | 8/8/2026 | 26/8/2026 | The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported… | |
| Aplazada | Alta (8.8) | 0.79% | — | Extra Checkout OptionsAI | 29/7/2026 | 30/7/2026 | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged… | |
| Aplazada | Media (6.5) | 0.33% | — | Edgarrojas Extra Product Options Builder FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extra Product Options Builder for WooCommerce: from n/a through <= 1.2.167. | |
| Aplazada | Media (5.3) | 0.47% | — | Solace ExtraAI | 11/7/2026 | 13/7/2026 | The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete all content previously… | |
| Aplazada | Media (6.5) | 0.22% | — | Averta Shortcodes AND Extra Features FOR Phlox ThemeAI | 1/7/2026 | 2/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS. This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.16. | |
| Analizada | Alta (8.6) | 0.53% | — | Max-mapper Extract-zip | 26/6/2026 | 6/7/2026 | extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how… | |
| Analizada | Alta (8.8) | 0.48% | — | Joomlaboat Extra Search | 19/6/2026 | 19/8/2026 | Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=com_extrasearch parameter and malicious SQL in the… | |
| Pendiente de análisis | Media (5.6) | 0.14% | — | Gnome Tracker-extract-mp3AIGnome Tracker-minersAI | 16/6/2026 | 17/6/2026 | A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS)… | |
| Aplazada | Media (6.4) | 0.32% | — | Extra Settings FOR RocketchatAI | 9/6/2026 | 23/7/2026 | The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat' shortcode's 'title' attribute in versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping in the rxstg_shortcode() function, which concatenates the… | |
| Aplazada | Media (5.5) | 0.29% | — | Sourcecodester SEO Meta TAG ExtractorAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Media (5.4) | 0.29% | — | Oceanwp Ocean ExtraAI | 7/4/2026 | 17/6/2026 | Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ocean Extra: from n/a through 2.5.3. | |
| Analizada | Crítica (9.8) | 3.6% | — | Dbashford Textract | 25/3/2026 | 17/6/2026 | textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization |