Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.29% | — | Rest API LOGAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions. | |
| Aplazada | Media (6.9) | 0.38% | — | Miniorange JWT Authentication FOR WP Rest ApisAI | 15/9/2026 | 24/9/2026 | miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification.… | |
| Aplazada | Crítica (9.2) | 0.40% | — | Hiperdino Rest APIAI | 14/9/2026 | 18/9/2026 | Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone… | |
| Aplazada | Alta (7.5) | 0.42% | — | Rest API LOGAI | 13/8/2026 | 14/8/2026 | Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions. | |
| Aplazada | Media (5.9) | 0.39% | — | Rest API LOGAI | 4/8/2026 | 26/8/2026 | The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does it check the capability of the requester, allowing unauthenticated users in possession of any such token to download the logged REST API requests and responses of any… | |
| Aplazada | Alta (8.1) | 0.35% | — | Foroup Customer Rest APIAI | 30/7/2026 | 31/7/2026 | A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of other users without checking that the caller owns the data associated with that record. | |
| Aplazada | Media (6.5) | 0.34% | — | Foroup Customer Rest APIAI | 30/7/2026 | 31/7/2026 | A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body. | |
| Analizada | Media (5.8) | 0.42% | — | Pavelzbornik Whisperx Rest API | 6/4/2026 | 17/6/2026 | The whisperX API is a tool for enhancing and analyzing audio content. From 0.3.1 to 0.5.0, FileService.download_from_url() in app/services/file_service.py calls requests.get(url) with zero URL validation. The file extension check occurs AFTER the HTTP request is already made, and can be bypassed by appending .mp3 to… | |
| Aplazada | Media (5.3) | 0.44% | — | Rest API TO MiniprogramAI | 21/3/2026 | 17/6/2026 | The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2. This is due to the permission callback (update_user_wechatshop_info_permissions_check) only validating that the supplied 'openid' parameter corresponds to an existing… | |
| Aplazada | Media (4.3) | 0.40% | — | ACF TO Rest APIAI | 7/1/2026 | 17/6/2026 | The ACF to REST API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.4. This is due to insufficient capability checks in the update_item_permissions_check() method, which only verifies that the current user has the edit_posts capability without checking… | |
| Aplazada | Media (5.3) | 0.26% | — | Airesvsg ACF TO Rest APIAI | 27/10/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in airesvsg ACF to REST API acf-to-rest-api allows Retrieve Embedded Sensitive Data.This issue affects ACF to REST API: from n/a through <= 3.3.4. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Copypress Rest APIAI | 30/9/2025 | 17/6/2026 | The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function in versions 1.1 to 1.2. The plugin falls back to a hard-coded JWT signing key when no secret is defined and does not restrict which file types can be fetched and saved as attachments. As a result,… | |
| Aplazada | Crítica (9.8) | 0.24% | — | Bedevious Password Reset With Code FOR Wordpress Rest APIAI | 18/9/2025 | 17/6/2026 | The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers. | |
| Aplazada | Crítica (9.8) | 0.63% | — | Rest API Custom API Generator FOR Cross Platform AND Import Export IN WPAI | 13/6/2025 | 17/6/2026 | The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the process_handler() function in versions 1.0.0 to 2.0.3. This makes it possible for unauthenticated attackers to POST an arbitrary import_api… | |
| Aplazada | Media (6.6) | 0.61% | — | Laravel Rest APIAI | 30/5/2025 | 17/6/2026 | Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute could be silently overridden. Due to how the framework merged validation rules across multiple contexts (such as index, store, and update actions),… | |
| Aplazada | Media (6.4) | 0.32% | — | Cuba Rest API Add-onAI | 22/4/2025 | 17/6/2026 | The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which consists of a file path and name, can be manipulated to return the Content-Type header with text/html if the name part ends with .html. This could allow malicious JavaScript code to be executed in the… | |
| Analizada | Media (6.5) | 0.69% | — | Haulmont Cuba PlatformHaulmont Cuba Rest APIHaulmont Jmix FrameworkHaulmont JPA WEB API | 22/4/2025 | 17/6/2026 | Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large files, potentially causing… | |
| Analizada | Media (5.4) | 0.36% | — | Haulmont Cuba PlatformHaulmont Cuba Rest APIHaulmont Jmix FrameworkHaulmont JPA WEB API | 22/4/2025 | 17/6/2026 | Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the input parameter, which consists of a file path and name, can be manipulated to return the Content-Type header with text/html if the name part ends with .html. This could… | |
| Aplazada | Media (5.4) | 0.51% | — | Miniorange Wordpress Rest API AuthenticationAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress REST API Authentication wp-rest-api-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress REST API Authentication: from n/a through <= 3.6.3. | |
| Aplazada | Media (4.3) | 0.17% | — | Rest API TO MiniprogramAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in xjb REST API TO MiniProgram rest-api-to-miniprogram allows Cross Site Request Forgery.This issue affects REST API TO MiniProgram: from n/a through <= 5.1.2. | |
| Aplazada | Media (6.1) | 0.39% | — | Ultimate Endpoints With Rest APIAI | 12/12/2024 | 17/6/2026 | The Ultimate Endpoints With Rest Api plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Modificada | Crítica (9.8) | 0.51% | — | Vivektamrakar WP Rest API FNS | 20/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Upload a Web Shell to a Web Server.This issue affects WP REST API FNS: from n/a through <= 1.0.0. | |
| Modificada | Crítica (9.8) | 1.5% | — | Vivektamrakar WP Rest API FNS | 20/10/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through <= 1.0.0. | |
| Modificada | Crítica (9.8) | 0.59% | — | Jianbo Rest API TO Miniprogram | 25/9/2024 | 17/6/2026 | The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validation on the 'openid' user controlled key that determines what user will be updated. This makes it possible for… | |
| Modificada | Alta (7.5) | 3.8% | — | Jianbo Rest API TO Miniprogram | 25/9/2024 | 17/6/2026 | The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all versions up to, and including, 4.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… |