Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

300 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.0%—Weplugins WP Maps12/8/201917/6/2026
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
ModificadaMedia (5.4)1.1%—Codecabin WP GO Maps9/8/201917/6/2026
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.
ModificadaAlta (8.8)1.0%—Fla-shop Html5 Maps5/7/201917/6/2026
Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaCrítica (9.8)79%💥 ExploitCodecabin WP GO Maps2/4/201917/6/2026
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.
ModificadaMedia (6.1)3.2%💥 ExploitCodecabin WP GO Maps22/3/201917/6/2026
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
ModificadaAlta (8.8)0.80%—Mapsvg Lite4/2/201917/6/2026
MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_save that can result in an attacker can modify post data, including embedding javascript. This attack appears to be exploitable via the victim must be logged in to…
ModificadaMedia (4.8)0.68%—Google XML Sitemaps Project Google XML Sitemaps9/1/201917/6/2026
Cross-site scripting vulnerability in Google XML Sitemaps Version 4.0.9 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.1)1.2%—Atmist Snazzy Maps3/10/201817/6/2026
The Snazzy Maps plugin before 1.1.5 for WordPress has XSS via the text or tab parameter.
ModificadaMedia (5.9)1.6%—Mapsplugin Googlemaps28/9/201717/6/2026
The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7428.
ModificadaCrítica (9.8)2.2%—Mapsplugin Googlemaps14/9/201717/6/2026
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.
ModificadaAlta (7.5)1.9%—Mapsplugin Googlemaps7/9/201717/6/2026
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url parameter to plugin_googlemap2_proxy.php.
ModificadaMedia (6.1)0.90%—Mapsplugin Googlemaps29/8/201717/6/2026
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!.
ModificadaAlta (7.5)1.6%—Mapsplugin Googlemaps29/8/201717/6/2026
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism.
ModificadaMedia (5.3)1.1%—Mapsplugin Googlemaps29/8/201717/6/2026
Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.
ModificadaMedia (6.1)0.76%—Mapsplugin Googlemaps28/8/201717/6/2026
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the xmlns parameter.
ModificadaMedia (6.1)0.89%—Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+4722/5/201717/6/2026
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,…
ModificadaCrítica (9.8)4.8%—Debian LinuxOsgeo Mapserver15/3/201717/6/2026
Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving WFS get feature requests.
ModificadaAlta (7.5)1.5%—Osgeo Mapserver8/12/201617/6/2026
In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails.
ModificadaMedia (6.1)4.4%💥 ExploitHero-maps-pro Project Hero-maps-pro10/10/201617/6/2026
Reflected XSS in wordpress plugin hero-maps-pro v2.1.0
ModificadaAlta (7.5)2.2%—OLD GSI Maps19/6/201617/6/2026
Directory traversal vulnerability in kml2jsonp.php in Geospatial Information Authority of Japan (aka GSI) Old_GSI_Maps before January 2015 on Windows allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (5.8)2.1%—Nokia Maps & Places Project Nokia Maps & Places1/7/201517/6/2026
Open redirect vulnerability in nokia-mapsplaces.php in the Nokia Maps & Places plugin 1.6.6 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the href parameter to page/place.html. NOTE: this was originally reported as a cross-site scripting (XSS)…
ModificadaMedia (5)2.0%—Infoware Mapsuite1/12/201417/6/2026
Server-side request forgery (SSRF) vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to trigger requests to intranet servers via unspecified vectors.
ModificadaMedia (5)1.3%—Infoware Mapsuite1/12/201417/6/2026
Absolute path traversal vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (4.3)2.5%—Codecabin WP GO Maps22/10/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.php.
ModificadaMedia (5.4)0.29%—Daum Maps - Subway2/10/201417/6/2026
The Daum Maps - Subway (aka net.daum.android.map) application 3.9.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades