Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

351 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.1%—Craftercms Crafter CMS27/11/202017/6/2026
Crafter CMS Crafter Studio 3.0.1 is affected by: Cross Site Scripting (XSS), which allows remote attackers to steal users’ cookies.
ModificadaAlta (8.6)1.7%—Craftercms Crafter CMS27/11/20209/7/2026
Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.
ModificadaAlta (7.5)2.0%—Craftercms Crafter CMS27/11/20209/7/2026
Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system.
ModificadaAlta (8.6)1.5%—Craftercms Crafter CMS27/11/20209/7/2026
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.
ModificadaMedia (6.1)0.75%—Craftercms Crafter CMS27/11/20209/7/2026
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.
ModificadaCrítica (9.8)2.0%—Craftercms Crafter CMS27/11/20209/7/2026
In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.
ModificadaMedia (6.5)0.75%—Craftercms Crafter CMS27/11/20209/7/2026
In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data.
ModificadaAlta (7.2)1.1%—Craftercms Studio6/10/202017/6/2026
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker template exposed objects. This issue affects: Crafter Software Crafter CMS 3.0 versions prior to 3.0.27; 3.1 versions prior to 3.1.7.
ModificadaAlta (7.2)1.1%—Craftercms Studio6/10/202017/6/2026
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy scripting. This issue affects: Crafter Software Crafter CMS 3.0 versions prior to 3.0.27; 3.1 versions prior to 3.1.7.
ModificadaCrítica (9.8)73%💥 ExploitCraftcms Craft CMS4/3/202017/6/2026
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
ModificadaMedia (6.1)3.7%💥 ExploitCraftcms Craft CMS31/12/201917/6/2026
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
ModificadaCrítica (9.8)1.8%—Craftcms Craft CMS24/10/201917/6/2026
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
ModificadaMedia (6.1)0.84%—Craftcms Craft CMS11/10/201917/6/2026
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
ModificadaMedia (4.8)0.95%—Cybercraftit Content-grabber10/10/201917/6/2026
The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id.
ModificadaMedia (5.4)1.0%—Webcraftic Woody AD Snippets13/9/201917/6/2026
The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.
ModificadaMedia (5.4)0.70%—Ncrafts Formcraft10/9/201917/6/2026
The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.
ModificadaAlta (8.8)18%💥 ExploitWebcraftic Woody AD Snippets3/9/201917/6/2026
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
ModificadaMedia (6.1)1.5%—Webcraftic Simple 301 Redirects30/8/201917/6/2026
The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.
ModificadaMedia (6.1)1.3%—Webcraftic Simple 301 Redirects-addon-bulk Uploader29/8/201917/6/2026
The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.
ModificadaMedia (6.1)0.91%—Crafty Social Buttons Project Crafty Social Buttons22/8/201917/6/2026
The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS.
ModificadaAlta (8.8)0.67%—Ncrafts Formcraft16/8/201917/6/2026
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
ModificadaAlta (7.5)1.6%—Webcraftic Woody AD Snippets8/8/201917/6/2026
admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion.
ModificadaMedia (5.3)9.4%💥 ExploitCraftcms Craft CMS26/7/201917/6/2026
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
ModificadaMedia (6.1)0.94%—Craftcms Craft CMS18/6/201917/6/2026
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
ModificadaAlta (8.8)0.83%—Ncrafts Formcraft12/3/201917/6/2026
Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.
Orbitaley — Vulnerabilidades