Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

380 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.55%—Phoeniixx Filter Portfolio Gallery13/12/202117/6/2026
The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow attackers to make a logged in admin delete arbitrary Gallery.
ModificadaAlta (7.8)0.23%—Intel NUC M15 Laptop KIT HID Event Filter Driver Pack17/11/202117/6/2026
Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit HID Event Filter driver pack before version 2.2.1.383 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.2)0.96%—Schneider-electric Accusine Pcsp Pfvp FirmwareSchneider-electric Accusine Pcsn Active Harmonic Filter Firmware2/9/202117/6/2026
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exist in AccuSine PCS+ / PFV+ (Versions prior to V1.6.7) and AccuSine PCSn (Versions prior to V2.2.4) that could allow an authenticated attacker to access the device via FTP protocol.
ModificadaAlta (8.8)0.85%—Pluginus Wordpress Meta Data AND Taxonomies Filter14/7/202117/6/2026
Cross-site request forgery (CSRF) vulnerability in WordPress Meta Data Filter & Taxonomies Filter versions prior to v.1.2.8 and versions prior to v.2.2.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaMedia (6.5)1.8%—Django-filter Project Django-filterFedoraproject Fedora29/4/202117/6/2026
django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before version 2.4.0, automatically generated `NumberFilter` instances, whose value was later converted to an integer, were subject to potential DoS from maliciously input using exponential format with…
ModificadaMedia (6.1)0.73%—Wfiltericf Wfilter Internet Content Filter15/4/202117/6/2026
Wfilter ICF 5.0.117 contains a cross-site scripting (XSS) vulnerability. An attacker in the same LAN can craft a packet with a malicious User-Agent header to inject a payload in its logs, where an attacker can take over the system by through its plugin-running function.
ModificadaAlta (7.8)0.28%—Intel HID Event Filter Driver12/11/202017/6/2026
Improper permissions in the installer for the Intel(R) HID Event Filter Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.66%—Stiltsoft Table Filter AND Charts FOR Confluence Server29/8/202017/6/2026
The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parameter).
ModificadaAlta (8.9)0.94%—Stiltsoft Table Filter AND Charts FOR Confluence Server29/8/202017/6/2026
The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) through the provided Markdown markup to the "Table from CSV" macro.
ModificadaAlta (8.8)2.3%—Jenkins Source Code Management Filter Jervis6/5/202017/6/2026
Jenkins SCM Filter Jervis Plugin 0.2.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
ModificadaAlta (7.5)1.3%—Mediawiki Abusefilter20/3/202017/6/2026
An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive information, such as deleted/suppressed usernames and summaries, from AbuseLog revision data. This affects REL1_32 and REL1_33.
ModificadaCrítica (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModificadaMedia (5.5)0.43%—Linuxfoundation Foomatic-filtersDebian LinuxFedoraproject Fedora19/11/201916/6/2026
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running…
ModificadaMedia (5.5)0.40%—Linuxfoundation Foomatic-filtersDebian Linux19/11/201916/6/2026
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running…
ModificadaMedia (5.3)1.1%—Mediawiki Abusefilter15/11/201917/6/2026
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially disclosing private or sensitive information within the filter's definition.
ModificadaMedia (5.3)0.93%—Mediawiki Abusefilter29/10/201917/6/2026
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged users, thus disclosing potentially sensitive information.
ModificadaAlta (7.2)1.9%—Awesome Filterable Portfolio Project Awesome Filterable Portfolio10/10/201917/6/2026
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat_id parameter.
ModificadaAlta (7.2)1.9%—Brinidesigner Awesome Filterable Portfolio10/10/201917/6/2026
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via the item_id parameter.
ModificadaAlta (7.5)0.95%—Imapfilter Project ImapfilterDebian LinuxFedoraproject FedoraOpensuse Backports SLE+18/9/201917/6/2026
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
ModificadaMedia (4.2)1.8%—Netfilter Iptables12/7/201917/6/2026
A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted iptables-save file. This is related to add_param_to_argv in xshared.c.
ModificadaMedia (6.1)0.83%—DAJ I-filter9/1/201917/6/2026
HTTP header injection vulnerability in i-FILTER Ver.9.50R05 and earlier may allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks that may result in an arbitrary script injection or setting an arbitrary cookie values via unspecified vectors.
ModificadaMedia (6.1)0.79%—DAJ I-filter9/1/201917/6/2026
Cross-site scripting vulnerability in i-FILTER Ver.9.50R05 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.8)4.0%💥 ExploitArmcode Adult Filter22/11/201817/6/2026
Adult Filter 1.0 has a Buffer Overflow via a crafted Black Domain List file.
ModificadaMedia (5.4)2.6%💥 ExploitRcfilters Project Rcfilters9/9/201817/6/2026
In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters section of the settings).
ModificadaAlta (7.8)1.8%—Hyland Perceptive Document Filters26/4/201817/6/2026
In Hyland Perceptive Document Filters 11.4.0.2647 - x86/x64 Windows/Linux, a crafted OpenDocument document can lead to a SkCanvas object double free resulting in direct code execution.