Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.34% | — | Wpthemespace Magical Addons FOR Elementor | 9/11/2024 | 17/6/2026 | The Magical Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the get_content_type function in includes/widgets/content-reveal.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Modificada | Media (4.3) | 0.57% | 💥 PoC | Wpthemespace Magical Addons FOR Elementor | 4/11/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through <= 1.2.1. | |
| Aplazada | Media (4.3) | 0.39% | — | Bracketspace Advanced Cron ManagerAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in BracketSpace Advanced Cron Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.9. | |
| Analizada | Alta (7.5) | 0.97% | — | Zimaspace Zimaos | 24/10/2024 | 17/6/2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traversal attack, allowing authenticated users to list the contents of any directory… | |
| Analizada | Media (5.3) | 0.47% | — | Zimaspace Zimaos | 24/10/2024 | 17/6/2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-IP>/v1/users/login` in ZimaOS returns distinct responses based on whether a username exists or the password is incorrect. This behavior can be… | |
| Analizada | Alta (7.5) | 24% | 💥 Exploit | Zimaspace Zimaos | 24/10/2024 | 17/6/2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http://<Server-IP>/v1/users/image?path=/var/lib/casaos/1/app_order.json` and… | |
| Modificada | Media (5.3) | 0.52% | — | Zimaspace Zimaos | 24/10/2024 | 17/6/2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, the API endpoint `http://<Server-ip>/v1/users/name` allows unauthenticated users to access sensitive information, such as usernames, without any authorization. This vulnerability could be exploited… | |
| Analizada | Alta (7.5) | 0.71% | — | Zimaspace Zimaos | 24/10/2024 | 17/6/2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the ZimaOS API endpoint `http://<Zima_Server_IP:PORT>/v3/file?token=<token>&files=<file_path>` is vulnerable to arbitrary file reading due to improper input validation. By… | |
| Aplazada | Alta (7.1) | 0.36% | — | Spacetime Ad-inserterAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spacetime Ad Inserter ad-inserter allows Reflected XSS.This issue affects Ad Inserter: from n/a through <= 2.7.37. | |
| Analizada | Media (6.9) | 1.3% | — | Juniper Junos Space | 11/10/2024 | 17/6/2026 | A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on the Junos Space Appliance, leading to remote command execution by the web application, gaining complete control of the device. A… | |
| Modificada | Media (4.2) | 0.31% | — | Monospace Directus | 8/10/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are not redacted and are potentially exposed in system logs which may be persisted. The access token in `req.query` is not redacted when the `LOG_STYLE` is set to `raw`. If these logs are not properly… | |
| Analizada | Media (5.3) | 0.38% | — | Eclipse Dataspace Components | 27/9/2024 | 17/6/2026 | In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a requested catalog, to ensure that only authorized parties are able to view restricted offers. However, there is the possibility to request a single dataset, which should be… | |
| Analizada | Media (5) | 0.47% | — | Monospace Directus | 18/9/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter a user may bypass this block by using other registered loopback devices (like `127.0.0.2` - `127.127.127.127`). This issue has been addressed in release… | |
| Analizada | Media (5.4) | 0.18% | — | Citrix Workspace | 11/9/2024 | 17/6/2026 | Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | |
| Analizada | Alta (7) | 0.25% | — | Citrix Workspace | 11/9/2024 | 17/6/2026 | Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | |
| Analizada | Media (5.1) | 0.41% | — | Eclipse Dataspace Components | 11/9/2024 | 17/6/2026 | In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for token expiration. The issue requires to have a dataplane… | |
| Modificada | Alta (7.8) | 0.27% | — | Ivanti Workspace Control | 10/9/2024 | 17/6/2026 | An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. | |
| Modificada | Alta (7.8) | 0.27% | — | Ivanti Workspace Control | 10/9/2024 | 17/6/2026 | DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.24% | — | Ivanti Workspace Control | 10/9/2024 | 17/6/2026 | Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. | |
| Modificada | Alta (7.8) | 0.16% | — | Ivanti Workspace Control | 10/9/2024 | 17/6/2026 | Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to obtain OS credentials. | |
| Modificada | Alta (7.8) | 0.24% | — | Ivanti Workspace Control | 10/9/2024 | 17/6/2026 | An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. | |
| Modificada | Alta (7.8) | 0.24% | — | Ivanti Workspace Control | 10/9/2024 | 17/6/2026 | DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Media (6.5) | 0.66% | — | Monospace Directus | 10/9/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication URL did not include redirect query string. This happens because on that endpoint for both OpenId and Oauth2 Directus… | |
| Analizada | Alta (7.1) | 0.15% | — | Citrix Workspace | 10/9/2024 | 17/6/2026 | Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to… | |
| Modificada | Media (4.3) | 0.33% | — | Monospace Directus | 15/8/2024 | 17/6/2026 | Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because the application only validates the user parameter in the 'POST /presets' request but not in the PATCH request. When chained with CVE-2024-6533, it could result… |