Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 29% | 💥 Exploit | Gutenberg Template Library & Redux Framework | 2/9/2021 | 17/6/2026 | The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash… | |
| Modificada | Media (6.5) | 1.3% | — | Gutenberg Template Library & Redux Framework | 2/9/2021 | 17/6/2026 | The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-api.php”. The `permissions_callback` used in this file only checked for the… | |
| Modificada | Alta (7.8) | 0.88% | — | Asyncapi Java-spring-cloud-stream-template | 11/8/2021 | 17/6/2026 | @asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection was possible when an attacker controls the AsyncAPI document. An example is provided in GHSA-xj6r-2jpm-qvxp. There are no mitigations available and all users are advised… | |
| Modificada | Alta (8.8) | 0.87% | — | Codemiq Wordpress Email Template Designer | 7/7/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (5.4) | 0.56% | — | Apollo13themes Rife Elementor Extensions & Templates | 5/5/2021 | 17/6/2026 | The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method. | |
| Modificada | Media (5.4) | 0.59% | — | Brainstormforce Elementor - Header, Footer & Blocks Template | 5/5/2021 | 17/6/2026 | The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. | |
| Modificada | Alta (8.8) | 1.6% | — | Cyberchimps Gutenberg & Elementor Templates Importer FOR Responsive | 23/4/2020 | 17/6/2026 | The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests. | |
| Modificada | Alta (7) | 0.26% | — | Redhat Template Service Broker Operator | 19/3/2020 | 17/6/2026 | A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the openshift/template-service-broker-operator. An attacker with access to the container could use this flaw to modify… | |
| Modificada | Crítica (9.8) | 1.3% | — | Pebbletemplates Pebble Templates | 19/12/2019 | 17/6/2026 | Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lang.String) signature. | |
| Modificada | Alta (7.5) | 3.1% | — | Almera Responsive Portfolio Site Template Project Almera Responsive Portfolio Site Template | 11/10/2019 | 17/6/2026 | The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Alta (7.5) | 3.1% | — | Accio Responsive Onepage Parallax Site Template Project Accio Responsive Onepage Parallax Site Template | 11/10/2019 | 17/6/2026 | The ThemeMakers Accio Responsive Parallax One Page Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Alta (7.5) | 3.1% | — | Invento / Architecture Building Agency Template Project Invento / Architecture Building Agency Template | 11/10/2019 | 17/6/2026 | The ThemeMakers Invento Responsive Gallery/Architecture Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Media (4.3) | 7.3% | 💥 Exploit | Alkacon Opencms Apollo Template | 27/8/2019 | 17/6/2026 | In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp. | |
| Modificada | Media (6.1) | 2.9% | 💥 Exploit | Alkacon Opencms Apollo Template | 27/8/2019 | 17/6/2026 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form. | |
| Modificada | Media (6.1) | 2.9% | 💥 Exploit | Alkacon Opencms Apollo Template | 27/8/2019 | 17/6/2026 | In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine. | |
| Modificada | Alta (8.1) | 0.79% | — | Jenkins Email Extension Template | 9/1/2019 | 17/6/2026 | A cross-site request forgery vulnerability exists in Jenkins Email Extension Template Plugin 1.0 and earlier in ExtEmailTemplateManagement.java that allows creating or removing templates. | |
| Modificada | Media (5.4) | 1.6% | 💥 Exploit | PHP Template Store Script Project PHP Template Store Script | 6/8/2018 | 17/6/2026 | PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field in a profile. | |
| Modificada | Alta (8.8) | 0.89% | — | Redhat OpenstackOpenstack Tripleo Heat Templates | 30/7/2018 | 17/6/2026 | A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials. | |
| Modificada | Media (6.1) | 0.83% | — | Bracket-template Project Bracket-template | 7/6/2018 | 17/6/2026 | bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template | |
| Modificada | Media (6.1) | 0.71% | — | IBM Social Rendering Templates FOR Digital Data Connector | 1/2/2017 | 17/6/2026 | IBM Social Rendering Templates for Digital Data Connector is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Alta (7.5) | 2.4% | — | Redhat OpenstackOpenstack Tripleo Heat Templates | 15/4/2016 | 17/6/2026 | The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private… | |
| Modificada | Alta (7.5) | 1.7% | — | Openstack Tripleo Heat Templates | 11/4/2016 | 17/6/2026 | The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter. | |
| Modificada | Media (4.3) | 0.96% | — | IBM Content Template Catalog | 3/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Content Template Catalog 4.x before 4.1.4 for WebSphere Portal 8.0.x and 4.x before 4.3.1 for WebSphere Portal 8.5.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6.8) | 0.57% | — | Node Template Project Node Template | 15/6/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Node Template module for Drupal allows remote attackers to hijack the authentication of users with the "access node template" permission for requests that delete node templates via unspecified vectors. | |
| Modificada | Media (6.8) | 1.3% | 💥 Exploit | Template CMS Project Template CMS | 20/5/2015 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Template CMS 2.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator user via an add action to admin/index.php or (2) conduct static PHP code injection attacks via the… |