Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.61% | — | Multidots Mass Pages/posts Creator | 31/5/2018 | 17/6/2026 | An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom content. There is no nonce or user capability check, so anyone can launch a DoS attack against a site and create hundreds of… | |
| Modificada | Media (5.3) | 0.93% | — | Multidots Woocommerce Category Banner Management | 31/5/2018 | 17/6/2026 | class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting by simply sending a request with a wbm_save_shop_page_banner_data… | |
| Modificada | Baja (3.3) | 1.1% | — | Amazon Echo Show FirmwareAmazon Echo Plus FirmwareAmazon Echo DOT FirmwareAmazon Echo Spot Firmware+1 | 30/5/2018 | 17/6/2026 | Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt feature is designed so that if Alexa does not receive an input within 8 seconds, the device can speak a reprompt, then wait an additional 8 seconds for input; if the user still does not respond, the… | |
| Modificada | Alta (7.2) | 1.3% | — | Dotcms | 19/2/2018 | 17/6/2026 | SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter. | |
| Modificada | Alta (7.2) | 1.3% | — | Dotcms | 19/2/2018 | 17/6/2026 | SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter. | |
| Modificada | Media (5.4) | 0.90% | — | Dotclear | 14/1/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTML via the nb parameter (aka the page limit number). | |
| Modificada | Media (5.4) | 0.90% | — | Dotclear | 14/1/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTML via the malicious user's email. | |
| Modificada | Media (5.4) | 0.51% | — | Dotcms | 10/10/2017 | 17/6/2026 | The dotCMS 4.1.1 application is vulnerable to Stored Cross-Site Scripting (XSS) affecting a vanity-urls Title field, a containers Description field, and a templates Description field. | |
| Analizada | Alta (8.8) | 95% | ⚠ Explotación activa💥 Exploit | Dnnsoftware Dotnetnuke | 20/7/2017 | 17/6/2026 | DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites." | |
| Modificada | Alta (7.2) | 7.7% | — | Dotcms | 20/7/2017 | 17/6/2026 | Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrators to upload .jsp files to arbitrary locations via directory traversal sequences in the fieldName parameter to servlets/ajax_file_upload. This results in arbitrary code… | |
| Modificada | Media (5.9) | 0.56% | — | Dotit-corp Banque Zitouna | 5/5/2017 | 17/6/2026 | The DOT IT Banque Zitouna app 2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.1) | 0.76% | — | Dotcms | 27/3/2017 | 17/6/2026 | dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields. | |
| Modificada | Media (6.1) | 0.67% | — | Dotclear | 5/3/2017 | 17/6/2026 | XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters. | |
| Modificada | Crítica (9.8) | 6.3% | 💥 Exploit | Dotcms | 17/2/2017 | 17/6/2026 | An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil… | |
| Modificada | Alta (8.8) | 2.6% | — | Dotclear | 9/2/2017 | 17/6/2026 | Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage their own media items" and "manage their own entries and comments" permissions to execute arbitrary PHP code by uploading a file with a (1) .pht, (2) .phps, or (3) .phtml… | |
| Modificada | Media (6.1) | 2.1% | — | Dotclear | 9/2/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via the author name in a comment. | |
| Modificada | Media (6.1) | 0.92% | — | Dotcms | 6/2/2017 | 17/6/2026 | XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter. | |
| Modificada | Media (6.1) | 0.92% | — | Dotcms | 6/2/2017 | 17/6/2026 | XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter. | |
| Modificada | Media (5.4) | 0.55% | — | Dotcms | 6/2/2017 | 17/6/2026 | XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter. | |
| Modificada | Crítica (9.8) | 75% | 💥 Exploit | Dnnsoftware Dotnetnuke | 6/2/2017 | 17/6/2026 | The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx. | |
| Modificada | Baja (3.7) | 1.1% | — | Dotclear | 4/1/2017 | 17/6/2026 | Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header. | |
| Modificada | Alta (8.8) | 3.1% | — | Dotclear | 4/1/2017 | 17/6/2026 | Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by uploading a ZIP file containing a file with a crafted extension, as demonstrated by .php.txt or .php%20. | |
| Modificada | Media (5.4) | 0.96% | — | Dotclear | 29/12/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated users to inject arbitrary web script or HTML via the upfiletitle or media_title parameter (aka the media title). | |
| Modificada | Crítica (9.8) | 2.1% | — | Dotcms | 19/12/2016 | 17/6/2026 | SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1. | |
| Modificada | Media (6.1) | 1.3% | — | Dotclear | 9/12/2016 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) link_type parameter to admin/media.php. |