Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

481 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.79%—Expresstech Quiz AND Survey Master29/11/202217/6/2026
The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible for unauthenticated attackers to inject…
ModificadaAlta (7.5)0.71%—Expresstech Quiz AND Survey Master18/11/202217/6/2026
Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress.
ModificadaMedia (6.1)0.45%—Expresstech Quiz AND Survey Master18/11/202217/6/2026
Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
ModificadaCrítica (9.8)0.75%—Expresstech Quiz AND Survey Master18/11/202217/6/2026
Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
ModificadaMedia (5.4)0.47%—Expresstech Quiz AND Survey Master17/11/202217/6/2026
Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaAlta (7.2)0.90%—Limesurvey15/11/202217/6/2026
LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.
ModificadaAlta (8.8)0.58%—Expresstech Quiz AND Survey Master3/11/202217/6/2026
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.
ModificadaAlta (7.2)0.91%—Expresstech Quiz AND Survey Master28/10/202217/6/2026
Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaMedia (5.4)0.46%—Expresstech Quiz AND Survey Master28/10/202217/6/2026
Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaMedia (5.4)0.50%—Expresstech Quiz AND Survey Master28/10/202217/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaMedia (4.3)0.50%—Quizandsurveymaster Quiz AND Survey Master30/9/202217/6/2026
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.
ModificadaMedia (4.8)0.54%—Wpdevart Poll, Survey, Questionnaire AND Voting System6/9/202217/6/2026
Authenticated (admin+) Cross-Site Scripting (XSS) vulnerability in wpdevart Poll, Survey, Questionnaire and Voting system plugin <= 1.7.4 at WordPress.
ModificadaAlta (8)1.1%—Eveo Urve WEB Manager15/7/202217/6/2026
A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing of the file _internal/uploader.php. The manipulation leads to unrestricted upload. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be…
ModificadaAlta (8)13%—Eveo Urve WEB Manager15/7/202217/6/2026
A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code of the file _internal/collector/upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the…
ModificadaAlta (8)1.1%—Eveo Urve WEB Manager15/7/202217/6/2026
A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the file kreator.html5/img_upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used.
ModificadaMedia (6.1)0.78%—Limesurvey25/5/202217/6/2026
A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.
ModificadaMedia (6.1)0.57%—Surveysparrow Enterprise Survey Software11/5/202217/6/2026
Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter.
ModificadaMedia (5.4)2.4%💥 ExploitSurveysparrow Enterprise Survey Software11/5/202217/6/2026
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.
ModificadaMedia (6.5)1.3%—Surveyking25/3/20229/7/2026
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.
ModificadaCrítica (9.8)1.9%—Surveyking Project Surveyking24/3/202217/6/2026
Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.
ModificadaCrítica (9.8)1.2%—Diaowen Dwsurvey20/3/202217/6/2026
DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java.
ModificadaCrítica (9.8)3.1%—Diaowen Dwsurvey20/3/202217/6/2026
DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java.
ModificadaMedia (5.5)0.37%💥 PoCArgussurveillance DVR1/3/202217/6/2026
Argus Surveillance DVR v4.0 employs weak password encryption.
ModificadaAlta (8.8)14%💥 PoCLimesurvey24/2/202217/6/2026
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a…
ModificadaMedia (6.1)0.83%—Ays-pro Survey Maker21/2/202217/6/2026
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6).
Orbitaley — Vulnerabilidades