Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.20% | — | Wpfactory Slugs ManagerAI | 31/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Slugs Manager.This issue affects Slugs Manager: from n/a through 2.6.7. | |
| Analizada | Media (5.3) | 0.66% | — | Rockwellautomation Factorytalk View | 25/3/2024 | 17/6/2026 | A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. If the vulnerability is exploited, it could lead to the loss of view or control of the PanelView™ product. | |
| Analizada | Media (6.1) | 0.47% | — | Jfrog Artifactory | 13/3/2024 | 17/6/2026 | JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism. | |
| Analizada | Alta (8.8) | 0.88% | — | Jfrog Artifactory | 7/3/2024 | 17/6/2026 | JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts. | |
| Analizada | Alta (7.5) | 0.44% | — | Jfrog Artifactory | 7/3/2024 | 17/6/2026 | JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data. | |
| Analizada | Media (6.5) | 0.47% | — | Jfrog Artifactory | 7/3/2024 | 17/6/2026 | JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration. | |
| Analizada | Media (4.9) | 0.49% | — | Dell Precision 3430 Tower FirmwareDell Precision 3431 Tower FirmwareDell Precision 3630 Tower FirmwareDell Precision 5820 Tower Firmware+169 | 1/3/2024 | 17/6/2026 | Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function. | |
| Modificada | Media (5.4) | 0.39% | — | Webfactoryltd WP Login Lockdown | 29/2/2024 | 17/6/2026 | The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the generate_export_file function in all versions up to, and including, 2.08. This makes it possible for authenticated attackers, with subscriber access and higher, to export… | |
| Modificada | Media (6.1) | 0.40% | — | Wpfactory Cost OF Goods FOR Woocommerce | 29/2/2024 | 17/6/2026 | The Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'section' parameter in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Modificada | Media (4.7) | 0.27% | — | Webfactoryltd WP Database Reset | 21/2/2024 | 17/6/2026 | The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing or incorrect nonce validation on the install_wpr() function. This makes it possible for unauthenticated attackers to install the WP Reset Plugin via a forged request… | |
| Analizada | Alta (8.8) | 0.99% | — | Rockwellautomation Factorytalk Services Platform | 16/2/2024 | 17/6/2026 | A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive… | |
| Analizada | Media (6.4) | 0.28% | — | HP Elite Mini 600 G9 FirmwareHP Elite Mini 800 G9 FirmwareHP Elite SFF 600 G9 FirmwareHP Elite SFF 800 G9 Firmware+23 | 14/2/2024 | 17/6/2026 | Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities. | |
| Analizada | Media (6.4) | 0.28% | — | HP Elite Mini 600 G9 FirmwareHP Elite Mini 800 G9 FirmwareHP Elite SFF 600 G9 FirmwareHP Elite SFF 800 G9 Firmware+23 | 14/2/2024 | 17/6/2026 | Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities. | |
| Modificada | Media (4.4) | 0.16% | — | Dell Optiplex 3000 Micro FirmwareDell Optiplex 3000 Small Form Factor FirmwareDell Optiplex 3000 Tower FirmwareDell Optiplex 5000 Micro Firmware+287 | 6/2/2024 | 17/6/2026 | Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Media (5.3) | 0.68% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 5/2/2024 | 17/6/2026 | The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenance… | |
| Modificada | Crítica (9.1) | 0.86% | — | Rockwellautomation Factorytalk Services Platform | 31/1/2024 | 17/6/2026 | A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory. If exploited, a malicious user could… | |
| Modificada | Alta (7.2) | 0.58% | — | Webfactoryltd WP Login Lockdown | 29/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebFactory Ltd Login Lockdown – Protect Login Form.This issue affects Login Lockdown – Protect Login Form: from n/a through 2.06. | |
| Modificada | Media (5.4) | 0.33% | — | Wpfactory Back Button Widget | 29/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Back Button Widget allows Stored XSS.This issue affects Back Button Widget: from n/a through 1.6.3. | |
| Modificada | Media (6.5) | 0.66% | — | Wpfrank Slider Factory PRO | 18/12/2023 | 17/6/2026 | The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any authenticated users, such as subscriber to access the content arbitrary post such as private, draft and password protected | |
| Modificada | Media (5.4) | 0.37% | — | Webfactoryltd Guest Author | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebFactory Ltd Guest Author allows Stored XSS.This issue affects Guest Author: from n/a through 2.3. | |
| Modificada | Media (5.4) | 0.38% | — | Dfactory Responsive Lightbox | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dFactory Responsive Lightbox & Gallery allows Stored XSS.This issue affects Responsive Lightbox & Gallery: from n/a through 2.4.5. | |
| Modificada | Media (6.1) | 0.41% | — | Wpfactory Products, Order & Customers Export FOR Woocommerce | 14/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommerce plugin <= 2.0.7 versions. | |
| Modificada | Alta (8.8) | 0.30% | — | Shawfactor Lh-password-changer | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Peter Shaw LH Password Changer plugin <= 1.55 versions. | |
| Modificada | Alta (8.1) | 2.7% | — | Rockwellautomation Factorytalk Services Platform | 27/10/2023 | 17/6/2026 | Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user… | |
| Modificada | Alta (7.5) | 0.90% | — | Rockwellautomation Factorytalk View | 27/10/2023 | 17/6/2026 | Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition. |