Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

574 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.3%💥 ExploitSecurenvoy Multi-factor Authentication Solutions10/6/202417/6/2026
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint.…
ModificadaCrítica (9.8)0.40%—Wpfactory Products, Order & Customers Export FOR Woocommerce9/6/202417/6/2026
Missing Authorization vulnerability in WPFactory Products, Order & Customers Export for WooCommerce.This issue affects Products, Order & Customers Export for WooCommerce: from n/a through 2.0.8.
AnalizadaAlta (8.8)0.36%—Dfactory Responsive Lightbox & Gallery9/6/202417/6/2026
Missing Authorization vulnerability in dFactory Responsive Lightbox.This issue affects Responsive Lightbox: from n/a through 2.4.6.
ModificadaMedia (5.4)0.44%—Webfactoryltd Minimal Coming Soon & Maintenance Mode8/6/202417/6/2026
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_ajax functions in all versions up to, and including, 2.38. This makes it possible for authenticated attackers, with…
ModificadaMedia (4.3)0.28%—Webfactoryltd WP Reset8/6/202417/6/2026
The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_ajax function in all versions up to, and including, 2.02. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the value fo the 'License…
ModificadaMedia (4.3)0.35%—Webfactoryltd WP Force SSL8/6/202417/6/2026
The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_setting' function in versions up to, and including, 1.66. This makes it possible for authenticated attackers, subscriber-level permissions and above, to…
ModificadaMedia (6.5)0.59%—Born05 Two-factor Authentication6/6/202417/6/2026
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.
ModificadaAlta (8.1)0.83%—Born05 Two-factor Authentication6/6/202417/6/2026
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.
AplazadaMedia (5.3)0.35%—Webfactoryltd Captcha CodeAI4/6/202417/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in WebFactory Ltd Captcha Code allows Functionality Bypass.This issue affects Captcha Code: from n/a through 2.9.
AplazadaMedia (6.4)0.33%—Dfactory Download AttachmentsAI4/6/202417/6/2026
The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'download-attachments' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaMedia (6.5)0.67%—Wpfactory Download Plugins AND Themes From DashboardAI22/5/202417/6/2026
Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server.
AnalizadaAlta (7.2)1.1%💥 PoCWpfactory EAN FOR Woocommerce17/5/202417/6/2026
Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.
AnalizadaAlta (8.8)0.65%—Rockwellautomation Factorytalk View16/5/202417/6/2026
A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack could result in information exposure,…
AplazadaAlta (7)0.27%💥 PoCRockwellautomation Factorytalk Remote AccessAI16/5/202417/6/2026
An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a…
AplazadaMedia (6.4)0.27%—Jfrog ArtifactoryAIJfrog PlatformAI15/5/202417/6/2026
A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s user email.
AplazadaCrítica (9)0.67%—Jfrog ArtifactoryAI1/5/202417/6/2026
An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.
AplazadaAlta (8.1)0.85%—Wpfactory Customer Email Verification FOR WoocommerceAI30/4/202417/6/2026
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification, and…
AplazadaAlta (8.4)1.1%—Factory MmigroupAI22/4/202417/6/2026
An issue was discovered in a third-party com.factory.mmigroup component, shipped on devices from multiple device manufacturers. Certain software builds for various Android devices contain a vulnerable pre-installed app with a package name of com.factory.mmigroup (versionCode='3', versionName='2.1) that allows local…
AplazadaMedia (6.1)0.17%—Itel Vision 3 TurboAITranssion Autotest FactoryAI22/4/202417/6/2026
Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package name of com.transsion.autotest.factory (versionCode='7', versionName='1.8.0(220310_1027)') that allows local third-party apps to execute arbitrary shell commands in its context (system user) due to…
ModificadaMedia (4.3)0.38%—Wpfactory EAN FOR Woocommerce18/4/202417/6/2026
The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'alg_wc_ean_product_meta' shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level…
ModificadaMedia (5.4)0.32%—Wpfactory EAN FOR Woocommerce18/4/202417/6/2026
The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_product_meta' shortcode in all versions up to, and including, 4.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalizadaMedia (4.3)0.41%—Jfrog Artifactory15/4/202417/6/2026
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.
AplazadaMedia (4.3)0.20%—Dfactory Post Views CounterAI12/4/202417/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Post Views Counter <= 1.4.4 versions.
AnalizadaMedia (4.4)0.18%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+26410/4/202417/6/2026
Dell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.
ModificadaMedia (5.9)0.70%—Webfactoryltd WP Reset9/4/202417/6/2026
The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0 via the use of insufficiently random snapshot names. This makes it possible for unauthenticated attackers to extract sensitive data including site backups by…