Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.25% | — | WickedAI | 27/8/2026 | 1/9/2026 | An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c reports the IP total length as the payload length instead of the length of the remaining UDP payload. Consequently, the DHCP option walker in the DHCPv4 client (wickedd-dhcp4) reads up to ihl +… | |
| Pendiente de análisis | Media (5.3) | 0.26% | — | WickedAI | 27/8/2026 | 1/9/2026 | An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c does not verify that the IP total length field (ip_len) is at least as large as the IP header length (ihl) before subtracting the header length. An unauthenticated attacker on the same network… | |
| Pendiente de análisis | Alta (8.8) | 0.49% | — | WickedAIISC DhcpAI | 16/6/2026 | 18/6/2026 | Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine. | |
| Aplazada | Media (4.3) | 0.23% | — | Wickedplugins Wicked FoldersAI | 16/3/2026 | 17/6/2026 | The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the delete_folders() function due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.3) | 0.36% | — | Turanszkij Wicked EngineAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files lparser.C. This issue affects WickedEngine: through 0.71.727. | |
| Aplazada | Media (5.1) | 0.13% | — | Turanszkij Wicked EngineAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files ldebug.C. This issue affects WickedEngine: before 0.71.705. | |
| Modificada | Media (4.3) | 0.29% | — | Wickedplugins Wicked Folders | 9/6/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request… | |
| Modificada | Media (4.3) | 0.31% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… | |
| Modificada | Media (4.3) | 0.31% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… | |
| Modificada | Media (4.3) | 0.31% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… | |
| Modificada | Media (4.3) | 0.31% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform… | |
| Modificada | Media (4.3) | 0.31% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function. This makes it possible for unauthenticated attackers to invoke this function via forged request… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.59% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.32% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request… | |
| Modificada | Media (4.3) | 0.32% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… | |
| Modificada | Media (4.3) | 0.32% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_move_object function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… | |
| Modificada | Media (4.3) | 0.60% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_sort_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.60% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.31% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… |