Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-66687 2026-08-13 MEDIUM 6.5 Customer Cross Site Scripting (XSS) in WpBookingly
CVE-2026-66661 2026-08-13 HIGH 7.7 Subscriber Privilege Escalation in Directories Pro
CVE-2026-66660 2026-08-13 MEDIUM 6.5 Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on
CVE-2026-66658 2026-08-13 HIGH 8.5 Subscriber SQL Injection in Reviewer
CVE-2026-66657 2026-08-13 HIGH 8.1 Unauthenticated Local File Inclusion in Biagiotti Core
CVE-2026-66656 2026-08-13 HIGH 8.1 Unauthenticated Local File Inclusion in Foton Core
CVE-2026-66655 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce
CVE-2026-66654 2026-08-13 MEDIUM 6.0 Subscriber Server Side Request Forgery (SSRF) in Vehica Core
CVE-2026-66653 2026-08-13 HIGH 8.1 Unauthenticated Local File Inclusion in Barista
CVE-2026-66478 2026-08-13 CRITICAL 9.3 Unauthenticated SQL Injection in Church Admin
CVE-2026-66472 2026-08-13 CRITICAL 9.3 Unauthenticated SQL Injection in Everest Backup
CVE-2026-66471 2026-08-13 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in Accordion
CVE-2026-66469 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in Arvow AI SEO Writer
CVE-2026-66468 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce
CVE-2026-66467 2026-08-13 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in FluentCommunity
CVE-2026-66466 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart
CVE-2026-66465 2026-08-13 CRITICAL 9.8 Unauthenticated Broken Authentication in Cartify
CVE-2026-66464 2026-08-13 MEDIUM 6.5 Unauthenticated Broken Access Control in Internal Link Optimiser
CVE-2026-66463 2026-08-13 HIGH 7.5 Unauthenticated Sensitive Data Exposure in iCARRY
CVE-2026-66462 2026-08-13 HIGH 7.5 Unauthenticated Sensitive Data Exposure in WooCommerce Appointments
CVE-2026-66461 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce
CVE-2026-66460 2026-08-13 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in AfterShip Tracking
CVE-2026-66459 2026-08-13 MEDIUM 6.5 Unauthenticated Broken Access Control in AI for SEO
CVE-2026-66458 2026-08-13 CRITICAL 9.3 Unauthenticated SQL Injection in RealPress
CVE-2026-66456 2026-08-13 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft
CVE-2026-66455 2026-08-13 MEDIUM 6.0 Subscriber Broken Access Control in ReactPress
CVE-2026-66454 2026-08-13 MEDIUM 6.5 Unauthenticated Broken Access Control in WP Social Avatar
CVE-2026-66453 2026-08-13 CRITICAL 9.8 Unauthenticated Broken Authentication in Salon booking system
CVE-2026-66450 2026-08-13 HIGH 8.1 Unauthenticated Local File Inclusion in Geo Mashup
CVE-2026-66449 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Geo Mashup
CVE-2026-66446 2026-08-13 CRITICAL 9.3 Subscriber SQL Injection in If-So Dynamic Content Personalization
CVE-2026-66444 2026-08-13 MEDIUM 6.5 Subscriber Sensitive Data Exposure in Payment Forms for Paystack
CVE-2026-66443 2026-08-13 HIGH 7.5 Unauthenticated Sensitive Data Exposure in REST API Log
CVE-2026-66441 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in MultiVendorX
CVE-2026-66436 2026-08-13 CRITICAL 9.3 Unauthenticated SQL Injection in Active Products Tables for WooCommerce
CVE-2026-66432 2026-08-13 HIGH 7.5 Subscriber Sensitive Data Exposure in WPJAM Basic
CVE-2026-66431 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK)
CVE-2026-66430 2026-08-13 HIGH 8.5 Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro
CVE-2026-66429 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro
CVE-2026-66426 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in WP-Stats
CVE-2026-66424 2026-08-13 CRITICAL 9.8 Unauthenticated Privilege Escalation in SMS Alert Order Notifications
CVE-2026-65936 2026-08-13 N/A 0.0 A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information.  See vulnerability B-E4 in the related paper below.
CVE-2026-65935 2026-08-13 N/A 0.0 Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.  See vulnerability B-E3 in the related paper below.
CVE-2026-65934 2026-08-13 N/A 0.0 An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module.  See vulnerability B-E10 in the related paper below.
CVE-2026-65582 2026-08-13 HIGH 7.7 Subscriber Arbitrary File Download in AI Hub
CVE-2026-65580 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Agrion
CVE-2026-65370 2026-08-12 HIGH 7.5 ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version 0.42.65.
CVE-2026-63426 2026-08-13 HIGH 7.1 During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with…
CVE-2026-63425 2026-08-13 HIGH 7.8 During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with…
CVE-2026-63424 2026-08-13 HIGH 7.3 During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.