Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1465▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
–

41 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.39%—Jupiterx CoreAI16/6/202617/6/2026
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
AplazadaMedia (6.5)0.22%—Jupiterx CoreAI15/6/202617/6/2026
Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.
AplazadaAlta (8.8)0.95%—Artbees Jupiter X CoreAI24/3/202617/6/2026
The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in the upload_files() function in all versions up to, and including, 4.14.1. This makes it possible for Authenticated attackers…
AplazadaAlta (8.8)0.69%—Artbees Jupiterx CoreAI22/1/202617/6/2026
Deserialization of Untrusted Data vulnerability in artbees JupiterX Core jupiterx-core allows Object Injection.This issue affects JupiterX Core: from n/a through <= 4.10.1.
AplazadaAlta (7.1)0.15%—Jupitercow WP SifrAI9/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Jupitercow WP sIFR wp-sifr allows Stored XSS.This issue affects WP sIFR: from n/a through <= 0.6.8.1.
AplazadaMedia (6.5)0.21%—Artbees Jupiterx CoreAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in artbees JupiterX Core jupiterx-core allows Stored XSS.This issue affects JupiterX Core: from n/a through <= 4.11.0.
AnalizadaMedia (5.4)0.32%—Artbees Jupiter X Core17/5/202517/6/2026
The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versions up to, and including, 4.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
AplazadaMedia (6.5)0.28%—Artbees Jupiterx CoreAI7/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in artbees JupiterX Core jupiterx-core allows Stored XSS.This issue affects JupiterX Core: from n/a through <= 4.8.11.
AnalizadaAlta (8.1)0.77%—Artbees Jupiter X Core26/4/202517/6/2026
The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8.11 via deserialization of untrusted input from the 'file' parameter of the 'raven_download_file' function. This makes it possible for attackers to inject a PHP Object through a PHAR file. No known…
ModificadaAlta (8.8)1.6%—Artbees Jupiter X Core1/2/202517/6/2026
The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 via the get_svg() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the…
AnalizadaMedia (6.5)0.71%—Artbees Jupiter X Core1/2/202517/6/2026
The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7 via the inline SVG feature. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain…
AnalizadaMedia (5.3)0.41%—Artbees Jupiter X Core7/1/202517/6/2026
The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() function in all versions up to, and including, 4.8.5. This makes it possible for unauthenticated attackers to export popup templates.
AnalizadaMedia (4.3)0.29%—Artbees Jupiter X Core7/1/202517/6/2026
The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sync_libraries() function in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to sync libraries
ModificadaAlta (8.8)0.59%—Artbees Jupiter X Core13/12/202417/6/2026
Missing Authorization vulnerability in Artbees JupiterX Core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.
AnalizadaCrítica (9.8)0.95%—Artbees Jupiter X Core26/9/202417/6/2026
The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper authentication via the Social Login widget. This makes it possible for unauthenticated attackers to log in as the first user to have logged in with a social media account,…
AnalizadaCrítica (9.8)1.5%—Artbees Jupiter X Core26/9/202417/6/2026
The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function in all versions up to, and including, 4.6.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make…
ModificadaCrítica (9.8)1.4%—Artbees Jupiter X Core21/6/202417/6/2026
Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.
ModificadaAlta (8.8)0.43%—Artbees Jupiter X Core19/6/202417/6/2026
Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.
AnalizadaAlta (8.8)0.81%—Artbees Jupiterx17/5/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in artbees JupiterX allows PHP Local File Inclusion.This issue affects JupiterX: from n/a through 3.0.0.
ModificadaCrítica (9.8)1.7%—Artbees Jupiter X Core26/3/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from n/a through 3.3.5.
ModificadaCrítica (9.8)1.6%—Fengjiachun Jupiter1/12/202317/6/2026
A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.
ModificadaAlta (7.5)1.2%—Artbees Jupiter X Core21/7/202317/6/2026
The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6.6. This makes it possible for unauthenticated attackers to download the contents of arbitrary files on the server, which can contain sensitive information. The requires the premium version of the…
ModificadaAlta (7.3)0.85%—Artbees Jupiterx13/6/202217/6/2026
Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin register an AJAX action jupiterx_conditional_manager which can be used to call any function in the includes/condition/class-condition-manager.php file by sending the desired function to call in the sub_action parameter. This can be used to view site…
ModificadaMedia (5.4)0.73%—Artbees Jupiter13/6/202217/6/2026
Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel/logic/plugin-management.php file. Using this functionality, any logged-in user…
ModificadaAlta (8.8)1.6%—Artbees JupiterArtbees Jupiterx13/6/202217/6/2026
Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscriber-level users, to perform Path Traversal and Local File inclusion. In the JupiterX theme, the jupiterx_cp_load_pane_action AJAX action present in the lib/admin/control-panel/control-panel.php file…