Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.79% | — | Expresstech Quiz AND Survey Master | 29/11/2022 | 17/6/2026 | The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Alta (7.5) | 0.71% | — | Expresstech Quiz AND Survey Master | 18/11/2022 | 17/6/2026 | Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress. | |
| Modificada | Media (6.1) | 0.45% | — | Expresstech Quiz AND Survey Master | 18/11/2022 | 17/6/2026 | Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. | |
| Modificada | Crítica (9.8) | 0.75% | — | Expresstech Quiz AND Survey Master | 18/11/2022 | 17/6/2026 | Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. | |
| Modificada | Media (5.4) | 0.47% | — | Expresstech Quiz AND Survey Master | 17/11/2022 | 17/6/2026 | Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress. | |
| Modificada | Alta (7.2) | 0.90% | — | Limesurvey | 15/11/2022 | 17/6/2026 | LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php. | |
| Modificada | Alta (8.8) | 0.58% | — | Expresstech Quiz AND Survey Master | 3/11/2022 | 17/6/2026 | Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress. | |
| Modificada | Alta (7.2) | 0.91% | — | Expresstech Quiz AND Survey Master | 28/10/2022 | 17/6/2026 | Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress. | |
| Modificada | Media (5.4) | 0.46% | — | Expresstech Quiz AND Survey Master | 28/10/2022 | 17/6/2026 | Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress. | |
| Modificada | Media (5.4) | 0.50% | — | Expresstech Quiz AND Survey Master | 28/10/2022 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress. | |
| Modificada | Media (4.3) | 0.50% | — | Quizandsurveymaster Quiz AND Survey Master | 30/9/2022 | 17/6/2026 | Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz. | |
| Modificada | Media (4.8) | 0.54% | — | Wpdevart Poll, Survey, Questionnaire AND Voting System | 6/9/2022 | 17/6/2026 | Authenticated (admin+) Cross-Site Scripting (XSS) vulnerability in wpdevart Poll, Survey, Questionnaire and Voting system plugin <= 1.7.4 at WordPress. | |
| Modificada | Alta (8) | 1.1% | — | Eveo Urve WEB Manager | 15/7/2022 | 17/6/2026 | A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing of the file _internal/uploader.php. The manipulation leads to unrestricted upload. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (8) | 13% | — | Eveo Urve WEB Manager | 15/7/2022 | 17/6/2026 | A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code of the file _internal/collector/upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the… | |
| Modificada | Alta (8) | 1.1% | — | Eveo Urve WEB Manager | 15/7/2022 | 17/6/2026 | A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the file kreator.html5/img_upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. | |
| Modificada | Media (6.1) | 0.78% | — | Limesurvey | 25/5/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin. | |
| Modificada | Media (6.1) | 0.57% | — | Surveysparrow Enterprise Survey Software | 11/5/2022 | 17/6/2026 | Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter. | |
| Modificada | Media (5.4) | 2.4% | 💥 Exploit | Surveysparrow Enterprise Survey Software | 11/5/2022 | 17/6/2026 | Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter. | |
| Modificada | Media (6.5) | 1.3% | — | Surveyking | 25/3/2022 | 9/7/2026 | SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application. | |
| Modificada | Crítica (9.8) | 1.9% | — | Surveyking Project Surveyking | 24/3/2022 | 17/6/2026 | Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack. | |
| Modificada | Crítica (9.8) | 1.2% | — | Diaowen Dwsurvey | 20/3/2022 | 17/6/2026 | DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java. | |
| Modificada | Crítica (9.8) | 3.1% | — | Diaowen Dwsurvey | 20/3/2022 | 17/6/2026 | DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java. | |
| Modificada | Media (5.5) | 0.37% | 💥 PoC | Argussurveillance DVR | 1/3/2022 | 17/6/2026 | Argus Surveillance DVR v4.0 employs weak password encryption. | |
| Modificada | Alta (8.8) | 14% | 💥 PoC | Limesurvey | 24/2/2022 | 17/6/2026 | A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a… | |
| Modificada | Media (6.1) | 0.83% | — | Ays-pro Survey Maker | 21/2/2022 | 17/6/2026 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6). |