Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.15% | — | Deepak Anand WP Dummy Content GeneratorAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0. | |
| Aplazada | Alta (8.1) | 0.39% | — | Taskingai QR Code GeneratorAI | 2/10/2026 | 2/10/2026 | In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter. | |
| Aplazada | Baja (3.5) | 0.14% | — | Business Name GeneratorAI | 19/9/2026 | 21/9/2026 | The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.5) | 0.25% | — | Privacy Policy Generator Terms ConditionsAI | 26/8/2026 | 26/8/2026 | The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before 3.7.1 does not include an authorization check on a REST route that returns stored account data, allowing unauthenticated visitors to retrieve the connected service's API secret and account… | |
| Aplazada | Baja (2.1) | 0.33% | — | Sourcecodester Dynamic Input Field GeneratorAI | 21/8/2026 | 24/8/2026 | A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester Dynamic Input Field Generator Using Html CSS AND PHPAI | 21/8/2026 | 24/8/2026 | A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions… | |
| Aplazada | Crítica (9.3) | 0.41% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |
| Aplazada | Alta (8.6) | 0.39% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |
| Aplazada | Crítica (9.1) | 0.43% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |
| Aplazada | Crítica (9.1) | 0.43% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAI | 13/8/2026 | 28/8/2026 | : Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All… | |
| Aplazada | Media (5.3) | 0.33% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |
| Aplazada | Alta (8.2) | 0.34% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |
| Aplazada | Crítica (10) | 0.50% | — | Soft Solutions Priority ERP Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |
| Aplazada | Alta (8.6) | 0.42% | — | Soft Solutions Priority ERPAISoft Solutions Portal GeneratorAISoft Solutions PriwallAI | 13/8/2026 | 28/8/2026 | : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).. This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions).: All versions without Priwall v3. | |
| Aplazada | Crítica (9.8) | 0.91% | — | AI Copilot Content GeneratorAI | 8/8/2026 | 12/8/2026 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new… | |
| Aplazada | Baja (1.9) | 0.21% | — | Zombodroid Meme GeneratorAI | 5/8/2026 | 12/8/2026 | A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the component com.zombodroid.MemeGenerator. Such manipulation leads to path traversal. Local access is required to approach this attack. The exploit has been disclosed publicly and… | |
| Analizada | Alta (7.5) | 0.49% | — | Koxudaxi Datamodel-code-generator | 28/7/2026 | 6/8/2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.11.6 until 0.64.0, datamodel-code-generator allows attacker-controlled x-python-import or customTypePath schema extensions to reach… | |
| Aplazada | Baja (3.7) | 0.34% | — | Koxudaxi Datamodel-code-generatorAI | 28/7/2026 | 30/7/2026 | datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_generator/http.py get_body reuses Authorization, Cookie, and Proxy-Authorization headers when following cross-origin redirects while fetching remote schemas, allowing credentials scoped to one schema host… | |
| Analizada | Alta (7.5) | 0.30% | — | Koxudaxi Datamodel-code-generator | 28/7/2026 | 6/8/2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.63.0, datamodel-code-generator validates a URL host once in src/datamodel_code_generator/http.py through get_body,… | |
| Aplazada | Alta (7.5) | 0.53% | — | Datamodel Code GeneratorAI | 28/7/2026 | 30/7/2026 | datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:redefine, and xs:override schemaLocation values outside the input base path,… | |
| Analizada | Alta (7.5) | 0.55% | — | Koxudaxi Datamodel-code-generator | 28/7/2026 | 6/8/2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref targets in src/datamodel_code_generator/parser/jsonschema.py through… | |
| Aplazada | Alta (8.2) | 0.38% | — | Koxudaxi Datamodel-code-generatorAI | 28/7/2026 | 30/7/2026 | datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts --url targets and redirect chain targets without host/IP validation, allowing server-side request forgery against loopback, private, link-local, metadata,… | |
| Analizada | Alta (8.2) | 0.39% | — | Koxudaxi Datamodel-code-generator | 28/7/2026 | 6/8/2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.9.1 until 0.61.0, datamodel-code-generator silently dereferences attacker-controlled JSON Schema $ref HTTP or HTTPS URLs in… | |
| Analizada | Alta (7.8) | 0.25% | — | Koxudaxi Datamodel-code-generator | 28/7/2026 | 6/8/2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.52.1 until 0.60.2, datamodel-code-generator interpolates validators from --extra-template-data in… |