Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.5) | — | — | WC Fields FactoryAI | 6/10/2026 | 6/10/2026 | Subscriber Cross Site Scripting (XSS) in WC Fields Factory <= 4.1.12 versions. | |
| Recibida | Media (6.1) | 0.27% | — | Calculated Fields FormAI | 3/10/2026 | 3/10/2026 | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'arbitrary (whichever names the admin bound via url.<name>)' parameter in all versions up to, and including, 5.5.1.5 due to… | |
| Aplazada | Media (4.7) | 0.20% | — | Calculated Fields FormAI | 1/10/2026 | 3/10/2026 | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (attacker-chosen name matching the form's url.<name> predefined value)' parameter in all versions up to, and including, 5.5.1.3 due… | |
| Aplazada | Media (6.1) | 0.21% | — | Calculatedfields Calculated Fields FormAI | 1/10/2026 | 1/10/2026 | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'x (any URL parameter consumed by the form's calculated equation)' parameter in all versions up to, and including, 5.5.1.3 due to… | |
| Pendiente de análisis | Media (6.8) | 0.15% | — | Nvidia ConnectxAINvidia BluefieldAI | 29/9/2026 | 29/9/2026 | NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Alta (7.2) | 0.24% | — | Repeater Fields FOR Elementor FormsAI | 25/9/2026 | 25/9/2026 | The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (7.1) | 0.18% | — | Calculated Fields FormAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions. | |
| Aplazada | Alta (8.1) | 0.21% | — | WC Fields FactoryAI | 23/9/2026 | 23/9/2026 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to… | |
| Aplazada | Baja (3.3) | 0.13% | — | WC Fields FactoryAI | 23/9/2026 | 23/9/2026 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting… | |
| Aplazada | Media (4.3) | 0.21% | — | Wpgogo Custom Field TemplateAI | 22/9/2026 | 22/9/2026 | The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to delete… | |
| Aplazada | Media (6.5) | 0.58% | — | Wpgogo Custom Field TemplateAI | 19/9/2026 | 21/9/2026 | The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and including, 2.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Baja (3.7) | 0.27% | — | Secure Custom FieldsAI | 19/9/2026 | 21/9/2026 | The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to. | |
| Aplazada | Media (4.3) | 0.25% | — | Checkout Field ManagerAI | 17/9/2026 | 18/9/2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users. | |
| Aplazada | Media (4.3) | 0.25% | — | Checkout Field ManagerAI | 17/9/2026 | 18/9/2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users. | |
| Aplazada | Alta (7.7) | 0.34% | — | Oracle Field ServiceAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. While the… | |
| Aplazada | Media (6.5) | 0.34% | — | Oracle Field ServiceAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of… | |
| Aplazada | Alta (7.1) | 0.29% | — | Oracle Field ServiceAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks… | |
| Pendiente de análisis | Alta (7.6) | 0.31% | — | Oracle Field ServiceAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of… | |
| Aplazada | Media (5.4) | 0.21% | — | Oracle Field ServiceAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks… | |
| Pendiente de análisis | Media (4.3) | 0.40% | — | Plone App.textfieldAI | 15/9/2026 | 30/9/2026 | plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on the release line, RichTextValue.output returns an unsanitized stored RichText value when mimeType equals outputMimeType, including values that claim… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Mipl Grouped Checkout Fields FOR WoocommerceAI | 11/9/2026 | 11/9/2026 | The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.6) | 0.53% | — | Studiowombat Advanced Product Fields Extended FOR WoocommerceAI | 10/9/2026 | 11/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6. | |
| Aplazada | Media (4.3) | 0.43% | — | Checkout Custom Fields Builder FOR WoocommerceAI | 9/9/2026 | 9/9/2026 | The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.2) | 0.51% | — | Repeater Fields FOR Gravity FormsAI | 9/9/2026 | 9/9/2026 | The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Analizada | Media (5.3) | 0.33% | — | Data Field Project Data Field | 2/9/2026 | 9/9/2026 | Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13. |