PULSE
EN VIVO49señales / 24h
FEED
ransomqilin reclama a Machinerie P&W · CA · Manufacturingransomqilin reclama a ABM Enviro · CA · Professional Servicesransomkrybit reclama a nilepet.com · EG · Retail & E-Commerceransomthegentlemen reclama a European Design · CA · Otherransomthegentlemen reclama a MK Jewelry · MK · Retail & E-Commerceransomthegentlemen reclama a GUERREIROS seguros · PT · Financial Servicesransomthegentlemen reclama a Tikona Infinet · IN · Technologyransomthegentlemen reclama a TC Printing · AU · Manufacturingransomthegentlemen reclama a Oldelval Oleoductos del Valle · AR · Energy & Utilitiesransomthegentlemen reclama a Decoupe Laser Services · FR · Manufacturingransomthegentlemen reclama a Thialf · NL · Energy & Utilitiesransomthegentlemen reclama a Title Resources · AU · Financial Servicesransomthegentlemen reclama a Clarke Radiology · AU · Healthcareransomthegentlemen reclama a SICSOE · FR · Not Foundransomqilin reclama a Machinerie P&W · CA · Manufacturingransomqilin reclama a ABM Enviro · CA · Professional Servicesransomkrybit reclama a nilepet.com · EG · Retail & E-Commerceransomthegentlemen reclama a European Design · CA · Otherransomthegentlemen reclama a MK Jewelry · MK · Retail & E-Commerceransomthegentlemen reclama a GUERREIROS seguros · PT · Financial Servicesransomthegentlemen reclama a Tikona Infinet · IN · Technologyransomthegentlemen reclama a TC Printing · AU · Manufacturingransomthegentlemen reclama a Oldelval Oleoductos del Valle · AR · Energy & Utilitiesransomthegentlemen reclama a Decoupe Laser Services · FR · Manufacturingransomthegentlemen reclama a Thialf · NL · Energy & Utilitiesransomthegentlemen reclama a Title Resources · AU · Financial Servicesransomthegentlemen reclama a Clarke Radiology · AU · Healthcareransomthegentlemen reclama a SICSOE · FR · Not Found
CVE Watch352,162 en archivo total

Vulnerabilidades explotables hoy

352,162en la vista actual

Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.

En catálogo KEV1,653
Nuevos KEV · 24H0
Exploit Today ≥ 701,590

Distribución · última ventana

  • Crítico
    2,073
  • Alto
    6,924
  • Medio
    5,904
  • Bajo
    547
Filtros

Ventana

Severidad

Filtros

Vulnerabilidades352,081–352,120 · 352,162
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-246394.4 MED
0Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.5h
CVE-2026-6481310.0 CRÍ
0In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session5h
CVE-2026-246285.9 MED
0Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.5h
CVE-2026-655065.3 MED
0Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.5h
CVE-2026-245528.5 ALT
0Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.5h
CVE-2026-655055.3 MED
0Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.5h
CVE-2026-648148.6 ALT
0In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session5h
CVE-2026-245374.3 MED
0Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.5h
CVE-2026-646117.5 ALT
0A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.6h
CVE-2026-153946.4 MED
0The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.7h
CVE-2026-150178.8 ALT
0The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of server-side allow-list validation on the `employee_roles[]` and `new_role` POST parameters before they are passed to `mdjm_set_employee_role()` and `WP_User::set_role()`. This makes it possible for unauthenticated attackers to grant arbitrary MDJM capabilities — including `mdjm_employee` and `mdjm_employee_edit` — to any registered WordPress role, and subsequently leverage a subscriber-level account to escalate privileges to Administrator. `MDJM_Permissions::init()` is registered on the public WordPress `init` hook without any authentication gate, meaning the role-manipulation endpoint is reachable without any prior login.7h
CVE-2026-648158.1 ALT
0In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files5h
CVE-2026-654525.3 MED
0Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.5h
CVE-2026-655007.5 ALT
0Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.5h
CVE-2026-654996.5 MED
0Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.5h
CVE-2026-654535.3 MED
0Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.5h
CVE-2026-654985.3 MED
0Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.5h
CVE-2026-654548.5 ALT
0Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.5h
CVE-2026-654559.1 CRÍ
0Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.5h
CVE-2026-654977.2 ALT
0Administrator PHP Object Injection in Complianz <= 7.5.0 versions.5h
CVE-2026-654564.3 MED
0Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.5h
CVE-2026-654656.5 MED
0Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.5h
CVE-2026-654964.4 MED
0Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.5h
CVE-2026-654957.5 ALT
0Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.5h
CVE-2026-654947.1 ALT
0Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.5h
CVE-2026-654645.4 MED
0Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.5h
CVE-2026-654627.6 ALT
0Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.5h
CVE-2025-36916
0.0%
0
CVE-2026-654937.5 ALT
0Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.5h
CVE-2026-654635.4 MED
0Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.5h
CVE-2026-654927.1 ALT
0Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.5h
CVE-2026-654914.3 MED
0Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.5h
CVE-2026-654905.3 MED
0Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.5h
CVE-2026-654875.3 MED
0Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.5h
CVE-2026-654865.3 MED
0Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.5h
CVE-2026-654855.3 MED
0Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.5h
CVE-2026-654846.3 MED
0Contributor Broken Access Control in Style Kits <= 2.6.5 versions.5h
CVE-2026-654835.9 MED
0Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.5h
CVE-2026-654826.5 MED
0Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.5h
CVE-2026-654817.5 ALT
0Contributor Local File Inclusion in Vino <= 1.9 versions.5h