Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.31% | — | Eric-oliver Machler Dsgvo YoutubeAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric-Oliver Mächler DSGVO Youtube allows Stored XSS.This issue affects DSGVO Youtube: from n/a through 1.4.5. | |
| Aplazada | Media (6.5) | 0.32% | — | Trade Pips WP TradingviewAI | 17/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Trade Pips WP TradingView allows Stored XSS.This issue affects WP TradingView: from n/a through 1.7. | |
| Modificada | Alta (8.8) | 0.23% | — | Dsgvo-for-wp Dsgvo ALL IN ONE FOR WP | 11/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Leithold DSGVO All in one for WP.This issue affects DSGVO All in one for WP: from n/a through 4.3. | |
| Analizada | Alta (7.5) | 0.45% | — | Geovision Gv-asmanager | 11/3/2024 | 17/6/2026 | GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path. | |
| Modificada | Media (4.8) | 0.34% | — | Gvectors Wpdiscuz | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team Comments – wpDiscuz allows Stored XSS.This issue affects Comments – wpDiscuz: from n/a through 7.6.12. | |
| Modificada | Media (6.5) | 0.52% | — | Gvectors Wpdiscuz | 20/12/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a through 7.6.3. | |
| Modificada | Alta (8.8) | 0.27% | — | Gvectors Woodiscuz - Woocommerce Comments | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0. | |
| Modificada | Alta (8.8) | 0.27% | — | Gvectors Wpforo Forum | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a through 2.2.6. | |
| Modificada | Media (5.4) | 0.38% | — | Gvectors Wpforo Forum | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team wpForo Forum allows Stored XSS.This issue affects wpForo Forum: from n/a through 2.2.3. | |
| Modificada | Alta (8.8) | 0.26% | — | Gvectors Wpdiscuz | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions. | |
| Modificada | Media (6.1) | 0.37% | — | Gvectors Wpdiscuz | 6/11/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions. | |
| Modificada | Media (6.1) | 0.50% | — | Nagvis | 20/10/2023 | 17/6/2026 | XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php. | |
| Modificada | Media (5.3) | 0.48% | — | Gvectors Wpdiscuz | 20/10/2023 | 17/6/2026 | The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a post. | |
| Modificada | Media (5.3) | 0.48% | — | Gvectors Wpdiscuz | 20/10/2023 | 17/6/2026 | The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a comment. | |
| Modificada | Alta (8.8) | 0.96% | — | Netgear Dg834gv5 Firmware | 7/8/2023 | 17/6/2026 | Netgear DG834Gv5 1.6.01.34 was discovered to contain multiple buffer overflows via the wla_ssid and wla_temp_ssid parameters at bsw_ssid.cgi. | |
| Modificada | Media (6.1) | 0.84% | 💥 Exploit | Gvectors Wpforo Forum | 24/7/2023 | 17/6/2026 | The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability. | |
| Modificada | Crítica (9.8) | 0.73% | — | Geovision Gv-adr2701 Firmware | 19/7/2023 | 17/6/2026 | In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application. | |
| Modificada | Alta (7.5) | 0.62% | — | Crestron Cp3n 6505417 FirmwareCrestron CP3 6504877 FirmwareCrestron Cp3-gv 6506034 Firmware | 17/7/2023 | 17/6/2026 | On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash. | |
| Modificada | Media (4.8) | 0.39% | — | Gvectors Wpview | 19/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Display Custom Fields – wpView plugin <= 1.3.0 versions. | |
| Modificada | Alta (8.8) | 61% | — | Gvectors Wpforo Forum | 9/6/2023 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it… | |
| Modificada | Media (6.1) | 0.78% | — | Legalweb WP Dsgvo Tools | 7/6/2023 | 17/6/2026 | The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.1.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Media (4.8) | 0.37% | — | Gvectors Woodiscuz - Woocommerce Comments | 28/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments woodiscuz-woocommerce-comments allows Stored XSS.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.2.9. | |
| Modificada | Media (6.5) | 4.1% | 💥 Exploit | Nagvis | 26/5/2023 | 17/6/2026 | Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php. | |
| Modificada | Media (5.3) | 0.75% | — | Spring-boot-actuator-logview Project Spring-boot-actuator-logview | 11/5/2023 | 17/6/2026 | spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view. | |
| Modificada | Crítica (9.8) | 1.2% | — | Geovision Gv-edge Recording Manager | 4/5/2023 | 9/7/2026 | An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated privileges. |