Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

472 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.65%—Phpipam14/9/202317/6/2026
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-Host leads to open redirect. The attack may be launched remotely. The exploit has been disclosed to the public…
ModificadaMedia (4.8)0.44%—Didcode Spamreferrerblock30/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Didier Sampaolo SpamReferrerBlock plugin <= 2.22 versions.
ModificadaMedia (4.8)0.35%—Supersoju Block Referer Spam23/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Supersoju Block Referer Spam plugin <= 1.1.9.4 versions.
ModificadaMedia (4.8)0.37%—Stopbadbots Block BAD Bots AND Stop BAD Bots Crawlers AND Spiders AND Anti Spam Protection23/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bill Minozzi Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin <= 7.31 versions.
ModificadaAlta (8.8)0.27%—Oopspam Anti-spam11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in OOPSpam OOPSpam Anti-Spam plugin <= 1.1.44 versions.
ModificadaAlta (8.8)1.3%—Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+127/6/202317/6/2026
Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or…
ModificadaMedia (4.8)0.44%—Trumani Stop Spammers5/6/202317/6/2026
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…
ModificadaMedia (6.1)0.52%—Trumani Stop Spammers5/6/202317/6/2026
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape various parameters before outputting them back in admin dashboard pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (7.8)0.81%—Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO26/4/202317/6/2026
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to…
ModificadaAlta (7.2)0.93%—Softnext Spam SQR27/3/202317/6/2026
Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authenticated remote attacker with administrator privilege can exploit this vulnerability to execute arbitrary system command to perform arbitrary system operation or disrupt service.
ModificadaMedia (4.8)0.39%—Oopspam Anti-spam23/3/202317/6/2026
Auth. (admin+) Cross-Site Scripting vulnerability in OOPSpam OOPSpam Anti-Spam plugin <= 1.1.35 versions.
ModificadaMedia (6.1)3.9%💥 ExploitPhpipam8/3/202317/6/2026
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.
ModificadaMedia (4.8)0.47%—Phpipam7/3/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.
ModificadaAlta (7.2)3.0%💥 ExploitPhpipam7/3/202317/6/2026
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
ModificadaMedia (5.4)0.55%—Mark User AS Spammer Project Mark User AS Spammer6/3/202317/6/2026
A vulnerability was found in Mark User as Spammer Plugin 1.0.0/1.0.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function user_row_actions of the file plugin/plugin.php. The manipulation of the argument url leads to cross site scripting. The attack can be launched remotely.…
ModificadaMedia (5.3)37%💥 ExploitPhpipam4/2/202317/6/2026
Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
ModificadaMedia (6.1)0.45%—Phpipam4/2/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.
ModificadaMedia (6.1)1.5%💥 ExploitPhpipam4/2/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitZohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+1818/1/202331/7/2026
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections,…
ModificadaCrítica (9.8)71%—Zohocorp Manageengine Password Manager PROZohocorp Manageengine Pam360Zohocorp Manageengine Access Manager Plus5/1/202317/6/2026
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.
ModificadaMedia (5.3)0.67%—WP Cerber Security, Anti-spam & Malware Scan2/1/202317/6/2026
The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, which could allow attackers to bypass the restriction in place and list users
ModificadaCrítica (9.8)18%—Trumani Stop Spammers26/12/202217/6/2026
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain
ModificadaMedia (6.1)0.53%—Django-openipam Project Django-openipam18/12/202217/6/2026
A vulnerability classified as problematic has been found in django-openipam. This affects an unknown part of the file openipam/report/templates/report/exposed_hosts.html. The manipulation of the argument description leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is…
ModificadaCrítica (9.8)67%—Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO12/11/202217/6/2026
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.
ModificadaCrítica (9.8)75%—Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO12/11/202217/6/2026
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.
Orbitaley — Vulnerabilidades