Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
472 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.57% | — | Phpipam | 2/11/2022 | 17/6/2026 | A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown functionality of the file app/admin/import-export/import-load-data.php of the component Import Preview Handler. The manipulation leads to cross site scripting. The attack can be launched remotely.… | |
| Modificada | Alta (7.2) | 1.1% | — | Cleantalk Spam Protection, Antispam, Firewall | 25/10/2022 | 17/6/2026 | The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin | |
| Modificada | Crítica (9.8) | 1.4% | — | Phpipam | 3/10/2022 | 17/6/2026 | phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php. | |
| Modificada | Crítica (9.8) | 1.5% | — | Linux-pam | 19/9/2022 | 17/6/2026 | The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with denied access to a machine can still get… | |
| Analizada | Crítica (9.8) | 99% | — | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO | 16/9/2022 | 17/6/2026 | Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities. | |
| Modificada | Media (5.3) | 0.76% | — | Cm-wp Titan Anti-spam & Security | 16/9/2022 | 17/6/2026 | The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers. | |
| Modificada | Media (5.3) | 0.86% | — | WP Cerber Security, Anti-spam & Malware Scan | 6/9/2022 | 17/6/2026 | The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumeration possible. This is due to improper validation on the value supplied through the 'author' parameter found in the ~/cerber-load.php file. In vulnerable versions, the… | |
| Modificada | Media (6.5) | 0.66% | — | Stop Spam Comments Project Stop Spam Comments | 29/8/2022 | 17/6/2026 | The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preventing abuse of comment section, allowing threat authors to easily collect the value and add it to the request. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO | 19/7/2022 | 17/6/2026 | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.) | |
| Modificada | Media (6.1) | 0.65% | — | Wp-spamfree Anti-spam Project Wp-spamfree Anti-spam | 24/6/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in WP-SpamFree Anti-Spam Plugin 2.1.1.4. This affects an unknown part. The manipulation leads to basic cross site scripting. It is possible to initiate the attack remotely. | |
| Modificada | Media (4.3) | 0.43% | — | GTI Throws Spam Away | 8/6/2022 | 17/6/2026 | The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all, spam, or pending), allowing attackers to make a logged in admin delete comments via a CSRF attack | |
| Analizada | Crítica (9.8) | 84% | 💥 Exploit | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO | 28/4/2022 | 17/6/2026 | Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring. | |
| Modificada | Crítica (9.8) | 1.3% | — | PAM Tacplus Project PAM Tacplus | 21/4/2022 | 17/6/2026 | In pam_tacplus.c in pam_tacplus before 1.4.1, pam_sm_acct_mgmt does not zero out the arep data structure. | |
| Modificada | Media (6.1) | 2.9% | — | Cleantalk Antispam | 19/4/2022 | 17/6/2026 | The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php` | |
| Modificada | Media (6.1) | 2.4% | — | Cleantalk Antispam | 19/4/2022 | 17/6/2026 | The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Comments.php` | |
| Modificada | Media (6.5) | 1.0% | — | Phpipam | 4/4/2022 | 17/6/2026 | Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6. | |
| Modificada | Media (6.5) | 1.0% | — | Phpipam | 4/4/2022 | 17/6/2026 | Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. | |
| Modificada | Media (6.5) | 1.0% | — | Phpipam | 4/4/2022 | 17/6/2026 | Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. | |
| Modificada | Media (6.1) | 0.92% | — | Phpipam | 25/3/2022 | 17/6/2026 | phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality. | |
| Modificada | Media (5.4) | 0.54% | — | Wpamelia Amelia | 23/3/2022 | 17/6/2026 | The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts onto a pages that executes whenever a… | |
| Modificada | Crítica (9.8) | 2.0% | — | Highfivery Zero-spam | 14/3/2022 | 17/6/2026 | The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | WP Cerber Security, Anti-spam & Malware Scan | 7/3/2022 | 17/6/2026 | The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability. | |
| Modificada | Alta (7.2) | 25% | 💥 Exploit | Phpipam | 19/1/2022 | 17/6/2026 | PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php | |
| Modificada | Media (4.8) | 0.62% | — | Phpipam | 19/1/2022 | 17/6/2026 | PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS. | |
| Modificada | Crítica (9.8) | 3.4% | — | Zohocorp Manageengine Pam360 | 20/12/2021 | 17/6/2026 | Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required. |