Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

574 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.20%—Wpfactory Slugs ManagerAI31/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Slugs Manager.This issue affects Slugs Manager: from n/a through 2.6.7.
AnalizadaMedia (5.3)0.66%—Rockwellautomation Factorytalk View25/3/202417/6/2026
A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. If the vulnerability is exploited, it could lead to the loss of view or control of the PanelView™ product.
AnalizadaMedia (6.1)0.47%—Jfrog Artifactory13/3/202417/6/2026
JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.
AnalizadaAlta (8.8)0.88%—Jfrog Artifactory7/3/202417/6/2026
JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.
AnalizadaAlta (7.5)0.44%—Jfrog Artifactory7/3/202417/6/2026
JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.
AnalizadaMedia (6.5)0.47%—Jfrog Artifactory7/3/202417/6/2026
JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.
AnalizadaMedia (4.9)0.49%—Dell Precision 3430 Tower FirmwareDell Precision 3431 Tower FirmwareDell Precision 3630 Tower FirmwareDell Precision 5820 Tower Firmware+1691/3/202417/6/2026
Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function.
ModificadaMedia (5.4)0.39%—Webfactoryltd WP Login Lockdown29/2/202417/6/2026
The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the generate_export_file function in all versions up to, and including, 2.08. This makes it possible for authenticated attackers, with subscriber access and higher, to export…
ModificadaMedia (6.1)0.40%—Wpfactory Cost OF Goods FOR Woocommerce29/2/202417/6/2026
The Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'section' parameter in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
ModificadaMedia (4.7)0.27%—Webfactoryltd WP Database Reset21/2/202417/6/2026
The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing or incorrect nonce validation on the install_wpr() function. This makes it possible for unauthenticated attackers to install the WP Reset Plugin via a forged request…
AnalizadaAlta (8.8)0.99%—Rockwellautomation Factorytalk Services Platform16/2/202417/6/2026
A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive…
AnalizadaMedia (6.4)0.28%—HP Elite Mini 600 G9 FirmwareHP Elite Mini 800 G9 FirmwareHP Elite SFF 600 G9 FirmwareHP Elite SFF 800 G9 Firmware+2314/2/202417/6/2026
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.
AnalizadaMedia (6.4)0.28%—HP Elite Mini 600 G9 FirmwareHP Elite Mini 800 G9 FirmwareHP Elite SFF 600 G9 FirmwareHP Elite SFF 800 G9 Firmware+2314/2/202417/6/2026
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.
ModificadaMedia (4.4)0.16%—Dell Optiplex 3000 Micro FirmwareDell Optiplex 3000 Small Form Factor FirmwareDell Optiplex 3000 Tower FirmwareDell Optiplex 5000 Micro Firmware+2876/2/202417/6/2026
Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.
ModificadaMedia (5.3)0.68%—Webfactoryltd Minimal Coming Soon & Maintenance Mode5/2/202417/6/2026
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenance…
ModificadaCrítica (9.1)0.86%—Rockwellautomation Factorytalk Services Platform31/1/202417/6/2026
A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory. If exploited, a malicious user could…
ModificadaAlta (7.2)0.58%—Webfactoryltd WP Login Lockdown29/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebFactory Ltd Login Lockdown – Protect Login Form.This issue affects Login Lockdown – Protect Login Form: from n/a through 2.06.
ModificadaMedia (5.4)0.33%—Wpfactory Back Button Widget29/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Back Button Widget allows Stored XSS.This issue affects Back Button Widget: from n/a through 1.6.3.
ModificadaMedia (6.5)0.66%—Wpfrank Slider Factory PRO18/12/202317/6/2026
The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any authenticated users, such as subscriber to access the content arbitrary post such as private, draft and password protected
ModificadaMedia (5.4)0.37%—Webfactoryltd Guest Author15/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebFactory Ltd Guest Author allows Stored XSS.This issue affects Guest Author: from n/a through 2.3.
ModificadaMedia (5.4)0.38%—Dfactory Responsive Lightbox15/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dFactory Responsive Lightbox & Gallery allows Stored XSS.This issue affects Responsive Lightbox & Gallery: from n/a through 2.4.5.
ModificadaMedia (6.1)0.41%—Wpfactory Products, Order & Customers Export FOR Woocommerce14/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommerce plugin <= 2.0.7 versions.
ModificadaAlta (8.8)0.30%—Shawfactor Lh-password-changer9/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Peter Shaw LH Password Changer plugin <= 1.55 versions.
ModificadaAlta (8.1)2.7%—Rockwellautomation Factorytalk Services Platform27/10/202317/6/2026
Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user…
ModificadaAlta (7.5)0.90%—Rockwellautomation Factorytalk View27/10/202317/6/2026
Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition.
Orbitaley — Vulnerabilidades