Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

291 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.2)0.37%—Patrickjuchli Basic-ftpAI30/9/202630/9/2026
basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long…
AplazadaAlta (7.5)0.42%—Wpjam BasicAI13/8/202614/8/2026
Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions.
AplazadaCrítica (9.3)0.40%—Wpjam BasicAI13/8/202614/8/2026
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
AplazadaMedia (4.4)0.34%—Sysbasics Customize MY Account FOR WoocommerceAI16/7/202617/7/2026
The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter in all versions up to, and including, 4.4.14 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.2)0.27%—Denishua Wpjam BasicAI13/7/202613/7/2026
Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basic: from n/a through <= 7.0.
AplazadaAlta (8.8)0.52%—Denishua Wpjam BasicAI13/7/202613/7/2026
Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.
AplazadaAlta (7.1)0.27%—Wpkube Simple Basic Contact FormAI23/6/202623/6/2026
The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, leading to a Reflected Cross-Site Scripting vulnerability that unauthenticated attackers can exploit against site visitors via a crafted link or…
AplazadaMedia (6.1)0.21%—Sysbasics Customize MY Account FOR WoocommerceAI18/6/202618/6/2026
The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 4.3.6 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaMedia (6.4)0.19%—Sysbasics Customize MY Account FOR WoocommerceAI18/6/202618/6/2026
The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode in versions up to, and including, 4.3.6. This is due to insufficient input sanitization and output escaping on user supplied attributes (min_height, min_width,…
Pendiente de análisisAlta (8.3)0.12%—Drager Cc-vision BasicAIDrager Cc-vision E-calAI2/6/202622/7/2026
Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerability when loading .gdt files. A crafted .gdt file can trigger a buffer overflow during file parsing, allowing an attacker to crash the application or execute malicious code on the underlying system.
AnalizadaMedia (5.1)0.39%—TFA Basic Plugins Project TFA Basic Plugins28/5/202621/7/2026
An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affects TFA Basic Plugins: from 7.x-1.0 through 7.x-1.2.
AplazadaAlta (7.5)0.54%—Patrickjuchli Basic-ftpAI12/5/202617/6/2026
basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authentication. The client…
AnalizadaAlta (7.5)0.49%—Patrickjuchli Basic-ftp24/4/202617/6/2026
basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings from a remote FTP server. A malicious or compromised server can send an extremely large or never-ending listing response to `Client.list()`, causing…
AplazadaMedia (5.3)0.35%—Basic Google Maps PlacemarksAI16/4/202617/6/2026
The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.10.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify stored map latitude and…
ModificadaBaja (2.7)0.32%—Razormist Basic Library System13/4/202617/6/2026
Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php.
AnalizadaBaja (2.7)0.32%—Razormist Basic Library System13/4/202617/6/2026
Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_admin.php.
AnalizadaBaja (2.7)0.32%—Razormist Basic Library System13/4/202617/6/2026
Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_book.php.
ModificadaAlta (8.6)2.8%💥 PoCPatrickjuchli Basic-ftp9/4/202615/7/2026
basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(), downloadTo(), list(), and removeDir(). The library's protectWhitespace() helper only handles…
AnalizadaAlta (8.8)0.27%—Gatech Computing FOR Good's Basic Laboratory Information System5/4/202624/7/2026
C4G Basic Laboratory Information System 3.4 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the site parameter. Attackers can send GET requests to the users_select.php endpoint with crafted SQL payloads to…
AplazadaCrítica (9.9)0.48%—Denishua Wpjam BasicAI25/3/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJAM Basic: from n/a through <= 6.9.2.
AnalizadaCrítica (9.8)1.0%—Patrickjuchli Basic-ftp25/2/202617/6/2026
The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended…
AnalizadaAlta (8.7)0.95%—Tattile Smart+ FirmwareTattile Tolling+ FirmwareTattile Smart+ Speed FirmwareTattile Smart+ Traffic Light Firmware+624/2/202617/6/2026
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared system) can continue to authenticate to the…
AnalizadaCrítica (9.3)2.7%💥 ExploitTattile Smart+ FirmwareTattile Tolling+ FirmwareTattile Smart+ Speed FirmwareTattile Smart+ Traffic Light Firmware+624/2/202617/6/2026
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access,…
AnalizadaAlta (8.7)1.0%—Tattile Smart+ FirmwareTattile Tolling+ FirmwareTattile Smart+ Speed FirmwareTattile Smart+ Traffic Light Firmware+624/2/202617/6/2026
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized disclosure of surveillance data.
AnalizadaAlta (7.3)0.16%—Siemens Telecontrol Server Basic13/1/202617/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains a local privilege escalation vulnerability that could allow an attacker to run arbitrary code with elevated privileges.
Orbitaley — Vulnerabilidades