Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.9% | — | Random Password Generator Project Random Password Generator | 18/5/2022 | 17/6/2026 | The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction. | |
| Modificada | Media (5.4) | 0.49% | — | PHP Mysql Admin Panel Generator Project PHP Mysql Admin Panel Generator | 28/4/2022 | 9/7/2026 | A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Automatic Question Paper Generator Project Automatic Question Paper Generator | 18/4/2022 | 17/6/2026 | Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter. | |
| Modificada | Media (5.4) | 0.83% | — | Jenkins JOB Generator | 12/4/2022 | 17/6/2026 | Jenkins Job Generator Plugin 1.22 and earlier does not escape the name and description of Generator Parameter and Generator Choice parameters on Job Generator jobs' Build With Parameters views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (8.1) | 1.4% | — | Generator-jhipster | 11/4/2022 | 17/6/2026 | JHipster is a development platform to quickly generate, develop, & deploy modern web applications & microservice architectures. SQL Injection vulnerability in entities for applications generated with the option "reactive with Spring WebFlux" enabled and an SQL database using r2dbc. Applications created without… | |
| Modificada | Media (6.1) | 0.88% | — | Favicon BY Realfavicongenerator | 11/4/2022 | 17/6/2026 | The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.56% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 29/3/2022 | 17/6/2026 | A vulnerability was found in Automatic Question Paper Generator System 1.0. It has been classified as problematic. This affects the file /aqpg/users/login.php of the component My Account Page. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. It is possible to initiate… | |
| Modificada | Crítica (9.8) | 0.81% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 29/3/2022 | 17/6/2026 | A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely. | |
| Modificada | Media (6.4) | 0.65% | — | Childtheme-generator Child Theme Generator | 14/3/2022 | 17/6/2026 | The Child Theme Generator WordPress plugin through 2.2.7 does not sanitise escape the parade parameter before outputting it back, leading to a Reflected Cross-Site Scripting in the admin dashboard | |
| Modificada | Alta (8.8) | 3.0% | 💥 Exploit | Wow-company Button Generator | 10/1/2022 | 17/6/2026 | The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE. | |
| Modificada | Alta (8.8) | 0.52% | — | Xml-sitemaps Unlimited Sitemap Generator | 24/11/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specially crafted web page. | |
| Modificada | Alta (7.8) | 1.6% | 💥 Exploit | Google SLO Generator | 4/10/2021 | 17/6/2026 | SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within the context of the SLO Generator. We recommend upgrading SLO Generator past https://github.com/google/slo-generator/pull/173 | |
| Modificada | Media (5.4) | 0.62% | — | Custom Post View Generator Project Custom Post View Generator | 13/9/2021 | 17/6/2026 | The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leading to a Reflected Cross-Site issue | |
| Modificada | Media (6.1) | 0.83% | — | Favicon BY Realfavicongenerator | 30/8/2021 | 17/6/2026 | The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator. | |
| Modificada | Media (6.5) | 0.92% | — | Zint Barcode Generator | 17/8/2021 | 17/6/2026 | Zint Barcode Generator before 2.10.0 has a one-byte buffer over-read, related to is_last_single_ascii in code1.c, and rs_encode_uint in reedsol.c. | |
| Modificada | Media (5.9) | 1.1% | — | Generator Project Generator | 8/8/2021 | 17/6/2026 | An issue was discovered in the generator crate before 0.7.0 for Rust. It does not ensure that a function (for yielding values) has Send bounds. | |
| Modificada | Media (5.5) | 0.40% | — | Openapi-generator Openapi Generator | 10/5/2021 | 17/6/2026 | OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Using `File.createTempFile` in JDK will result in creating and using insecure temporary files that can leave application and system data vulnerable to… | |
| Modificada | Alta (7) | 0.35% | — | Openapi-generator Openapi Generator | 10/5/2021 | 17/6/2026 | Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. openapi-generator-online creates insecure temporary folders with File.createTempFile during the code generation process. The insecure… | |
| Modificada | Baja (3.3) | 0.30% | — | Openapi-generator Openapi Generator | 27/4/2021 | 17/6/2026 | OpenAPI Generator allows generation of API client libraries, server stubs, documentation and configuration automatically given an OpenAPI Spec. Using `File.createTempFile` in JDK will result in creating and using insecure temporary files that can leave application and system data vulnerable to attacks. OpenAPI… | |
| Modificada | Alta (7.5) | 2.4% | — | Zint Barcode Generator | 26/2/2021 | 17/6/2026 | ean_leading_zeroes in backend/upcean.c in Zint Barcode Generator 2.9.1 has a stack-based buffer overflow that is reachable from the C API through an application that includes the Zint Barcode Generator library code. | |
| Modificada | Media (6.1) | 1.1% | — | Egavilanmedia Barcodes Generator | 15/12/2020 | 17/6/2026 | EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website. | |
| Modificada | Alta (8.2) | 2.0% | 💥 PoC | Node-pdf-generator Project Node-pdf-generator | 6/10/2020 | 17/6/2026 | This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack. | |
| Modificada | Media (5.3) | 1.2% | — | Generator-jhipster-kotlin | 25/6/2020 | 17/6/2026 | In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This is vulnerable to https://cwe.mitre.org/data/definitions/117.html This problem affects only… | |
| Modificada | Alta (8.8) | 0.69% | — | Supsystic Data Tables Generator | 23/4/2020 | 17/6/2026 | The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS. | |
| Modificada | Alta (8.8) | 1.0% | — | Supsystic Data Tables Generator | 23/4/2020 | 17/6/2026 | The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions. |