Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

392 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.61%—Multidots Mass Pages/posts Creator31/5/201817/6/2026
An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom content. There is no nonce or user capability check, so anyone can launch a DoS attack against a site and create hundreds of…
ModificadaMedia (5.3)0.93%—Multidots Woocommerce Category Banner Management31/5/201817/6/2026
class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting by simply sending a request with a wbm_save_shop_page_banner_data…
ModificadaBaja (3.3)1.1%—Amazon Echo Show FirmwareAmazon Echo Plus FirmwareAmazon Echo DOT FirmwareAmazon Echo Spot Firmware+130/5/201817/6/2026
Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt feature is designed so that if Alexa does not receive an input within 8 seconds, the device can speak a reprompt, then wait an additional 8 seconds for input; if the user still does not respond, the…
ModificadaAlta (7.2)1.3%—Dotcms19/2/201817/6/2026
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.
ModificadaAlta (7.2)1.3%—Dotcms19/2/201817/6/2026
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.
ModificadaMedia (5.4)0.90%—Dotclear14/1/201817/6/2026
Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTML via the nb parameter (aka the page limit number).
ModificadaMedia (5.4)0.90%—Dotclear14/1/201817/6/2026
Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTML via the malicious user's email.
ModificadaMedia (5.4)0.51%—Dotcms10/10/201717/6/2026
The dotCMS 4.1.1 application is vulnerable to Stored Cross-Site Scripting (XSS) affecting a vanity-urls Title field, a containers Description field, and a templates Description field.
AnalizadaAlta (8.8)95%⚠ Explotación activa💥 ExploitDnnsoftware Dotnetnuke20/7/201717/6/2026
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
ModificadaAlta (7.2)7.7%—Dotcms20/7/201717/6/2026
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrators to upload .jsp files to arbitrary locations via directory traversal sequences in the fieldName parameter to servlets/ajax_file_upload. This results in arbitrary code…
ModificadaMedia (5.9)0.56%—Dotit-corp Banque Zitouna5/5/201717/6/2026
The DOT IT Banque Zitouna app 2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.1)0.76%—Dotcms27/3/201717/6/2026
dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.
ModificadaMedia (6.1)0.67%—Dotclear5/3/201717/6/2026
XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.
ModificadaCrítica (9.8)6.3%💥 ExploitDotcms17/2/201717/6/2026
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil…
ModificadaAlta (8.8)2.6%—Dotclear9/2/201717/6/2026
Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage their own media items" and "manage their own entries and comments" permissions to execute arbitrary PHP code by uploading a file with a (1) .pht, (2) .phps, or (3) .phtml…
ModificadaMedia (6.1)2.1%—Dotclear9/2/201717/6/2026
Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via the author name in a comment.
ModificadaMedia (6.1)0.92%—Dotcms6/2/201717/6/2026
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter.
ModificadaMedia (6.1)0.92%—Dotcms6/2/201717/6/2026
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter.
ModificadaMedia (5.4)0.55%—Dotcms6/2/201717/6/2026
XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.
ModificadaCrítica (9.8)75%💥 ExploitDnnsoftware Dotnetnuke6/2/201717/6/2026
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
ModificadaBaja (3.7)1.1%—Dotclear4/1/201717/6/2026
Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.
ModificadaAlta (8.8)3.1%—Dotclear4/1/201717/6/2026
Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by uploading a ZIP file containing a file with a crafted extension, as demonstrated by .php.txt or .php%20.
ModificadaMedia (5.4)0.96%—Dotclear29/12/201617/6/2026
Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated users to inject arbitrary web script or HTML via the upfiletitle or media_title parameter (aka the media title).
ModificadaCrítica (9.8)2.1%—Dotcms19/12/201617/6/2026
SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1.
ModificadaMedia (6.1)1.3%—Dotclear9/12/201617/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) link_type parameter to admin/media.php.
Orbitaley — Vulnerabilidades