Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-67990 2026-08-13 MEDIUM 5.4 basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that…
CVE-2026-67986 2026-08-13 HIGH 8.4 amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval…
CVE-2026-66704 2026-08-13 HIGH 7.2 Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion
CVE-2026-66700 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover
CVE-2026-66698 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in SureDash
CVE-2026-66697 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce
CVE-2026-66693 2026-08-13 MEDIUM 6.5 Subscriber Broken Access Control in Motors
CVE-2026-66691 2026-08-13 CRITICAL 9.8 Unauthenticated Broken Access Control in Nokri
CVE-2026-66689 2026-08-13 MEDIUM 6.3 Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker
CVE-2026-66687 2026-08-13 MEDIUM 6.5 Customer Cross Site Scripting (XSS) in WpBookingly
CVE-2026-66661 2026-08-13 HIGH 7.7 Subscriber Privilege Escalation in Directories Pro
CVE-2026-66660 2026-08-13 MEDIUM 6.5 Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on
CVE-2026-66658 2026-08-13 HIGH 8.5 Subscriber SQL Injection in Reviewer
CVE-2026-66657 2026-08-13 HIGH 8.1 Unauthenticated Local File Inclusion in Biagiotti Core
CVE-2026-66656 2026-08-13 HIGH 8.1 Unauthenticated Local File Inclusion in Foton Core
CVE-2026-66655 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce
CVE-2026-66654 2026-08-13 MEDIUM 6.0 Subscriber Server Side Request Forgery (SSRF) in Vehica Core
CVE-2026-66653 2026-08-13 HIGH 8.1 Unauthenticated Local File Inclusion in Barista
CVE-2026-66478 2026-08-13 CRITICAL 9.3 Unauthenticated SQL Injection in Church Admin
CVE-2026-66472 2026-08-13 CRITICAL 9.3 Unauthenticated SQL Injection in Everest Backup
CVE-2026-66471 2026-08-13 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in Accordion
CVE-2026-66469 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in Arvow AI SEO Writer
CVE-2026-66468 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce
CVE-2026-66467 2026-08-13 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in FluentCommunity
CVE-2026-66466 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart
CVE-2026-66465 2026-08-13 CRITICAL 9.8 Unauthenticated Broken Authentication in Cartify
CVE-2026-66464 2026-08-13 MEDIUM 6.5 Unauthenticated Broken Access Control in Internal Link Optimiser
CVE-2026-66463 2026-08-13 HIGH 7.5 Unauthenticated Sensitive Data Exposure in iCARRY
CVE-2026-66462 2026-08-13 HIGH 7.5 Unauthenticated Sensitive Data Exposure in WooCommerce Appointments
CVE-2026-66461 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce
CVE-2026-66460 2026-08-13 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in AfterShip Tracking
CVE-2026-66459 2026-08-13 MEDIUM 6.5 Unauthenticated Broken Access Control in AI for SEO
CVE-2026-66458 2026-08-13 CRITICAL 9.3 Unauthenticated SQL Injection in RealPress
CVE-2026-66456 2026-08-13 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft
CVE-2026-66455 2026-08-13 MEDIUM 6.0 Subscriber Broken Access Control in ReactPress
CVE-2026-66454 2026-08-13 MEDIUM 6.5 Unauthenticated Broken Access Control in WP Social Avatar
CVE-2026-66453 2026-08-13 CRITICAL 9.8 Unauthenticated Broken Authentication in Salon booking system
CVE-2026-66450 2026-08-13 HIGH 8.1 Unauthenticated Local File Inclusion in Geo Mashup
CVE-2026-66449 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Geo Mashup
CVE-2026-66446 2026-08-13 CRITICAL 9.3 Subscriber SQL Injection in If-So Dynamic Content Personalization
CVE-2026-66444 2026-08-13 MEDIUM 6.5 Subscriber Sensitive Data Exposure in Payment Forms for Paystack
CVE-2026-66443 2026-08-13 HIGH 7.5 Unauthenticated Sensitive Data Exposure in REST API Log
CVE-2026-66441 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in MultiVendorX
CVE-2026-66436 2026-08-13 CRITICAL 9.3 Unauthenticated SQL Injection in Active Products Tables for WooCommerce
CVE-2026-66432 2026-08-13 HIGH 7.5 Subscriber Sensitive Data Exposure in WPJAM Basic
CVE-2026-66431 2026-08-13 HIGH 7.5 Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK)
CVE-2026-66430 2026-08-13 HIGH 8.5 Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro
CVE-2026-66429 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro
CVE-2026-66426 2026-08-13 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in WP-Stats
CVE-2026-66424 2026-08-13 CRITICAL 9.8 Unauthenticated Privilege Escalation in SMS Alert Order Notifications