Vulnerabilidades explotables hoy
352,162en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,653
Nuevos KEV · 24H0
Exploit Today ≥ 701,590
Distribución · última ventana
- Crítico2,073
- Alto6,924
- Medio5,904
- Bajo547
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-246394.4 MED—
——0Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.5hCVE-2026-6481310.0 CRÍ—
——0In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session5hCVE-2026-246285.9 MED—
——0Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.5hCVE-2026-655065.3 MED—
——0Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.5hCVE-2026-245528.5 ALT—
——0Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.5hCVE-2026-655055.3 MED—
——0Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.5hCVE-2026-648148.6 ALT—
——0In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session5hCVE-2026-245374.3 MED—
——0Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.5hCVE-2026-646117.5 ALT—
——0A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.6hCVE-2026-153946.4 MED—
——0The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.7hCVE-2026-150178.8 ALT—
——0The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of server-side allow-list validation on the `employee_roles[]` and `new_role` POST parameters before they are passed to `mdjm_set_employee_role()` and `WP_User::set_role()`. This makes it possible for unauthenticated attackers to grant arbitrary MDJM capabilities — including `mdjm_employee` and `mdjm_employee_edit` — to any registered WordPress role, and subsequently leverage a subscriber-level account to escalate privileges to Administrator. `MDJM_Permissions::init()` is registered on the public WordPress `init` hook without any authentication gate, meaning the role-manipulation endpoint is reachable without any prior login.7hCVE-2026-648158.1 ALT—
——0In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files5hCVE-2026-654525.3 MED—
——0Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.5hCVE-2026-655007.5 ALT—
——0Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.5hCVE-2026-654996.5 MED—
——0Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.5hCVE-2026-654535.3 MED—
——0Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.5hCVE-2026-654985.3 MED—
——0Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.5hCVE-2026-654548.5 ALT—
——0Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.5hCVE-2026-654559.1 CRÍ—
——0Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.5hCVE-2026-654977.2 ALT—
——0Administrator PHP Object Injection in Complianz <= 7.5.0 versions.5hCVE-2026-654564.3 MED—
——0Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.5hCVE-2026-654656.5 MED—
——0Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.5hCVE-2026-654964.4 MED—
——0Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.5hCVE-2026-654957.5 ALT—
——0Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.5hCVE-2026-654947.1 ALT—
——0Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.5hCVE-2026-654645.4 MED—
——0Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.5hCVE-2026-654627.6 ALT—
——0Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.5hCVE-2025-36916—0.0%
——0——CVE-2026-654937.5 ALT—
——0Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.5hCVE-2026-654635.4 MED—
——0Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.5hCVE-2026-654927.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.5hCVE-2026-654914.3 MED—
——0Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.5hCVE-2026-654905.3 MED—
——0Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.5hCVE-2026-654875.3 MED—
——0Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.5hCVE-2026-654865.3 MED—
——0Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.5hCVE-2026-654855.3 MED—
——0Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.5hCVE-2026-654846.3 MED—
——0Contributor Broken Access Control in Style Kits <= 2.6.5 versions.5hCVE-2026-654835.9 MED—
——0Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.5hCVE-2026-654826.5 MED—
——0Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.5hCVE-2026-654817.5 ALT—
——0Contributor Local File Inclusion in Vino <= 1.9 versions.5h