Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
351 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.1% | — | Craftercms Crafter CMS | 27/11/2020 | 17/6/2026 | Crafter CMS Crafter Studio 3.0.1 is affected by: Cross Site Scripting (XSS), which allows remote attackers to steal users’ cookies. | |
| Modificada | Alta (8.6) | 1.7% | — | Craftercms Crafter CMS | 27/11/2020 | 9/7/2026 | Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band. | |
| Modificada | Alta (7.5) | 2.0% | — | Craftercms Crafter CMS | 27/11/2020 | 9/7/2026 | Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system. | |
| Modificada | Alta (8.6) | 1.5% | — | Craftercms Crafter CMS | 27/11/2020 | 9/7/2026 | In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band. | |
| Modificada | Media (6.1) | 0.75% | — | Craftercms Crafter CMS | 27/11/2020 | 9/7/2026 | In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel. | |
| Modificada | Crítica (9.8) | 2.0% | — | Craftercms Crafter CMS | 27/11/2020 | 9/7/2026 | In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE. | |
| Modificada | Media (6.5) | 0.75% | — | Craftercms Crafter CMS | 27/11/2020 | 9/7/2026 | In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data. | |
| Modificada | Alta (7.2) | 1.1% | — | Craftercms Studio | 6/10/2020 | 17/6/2026 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker template exposed objects. This issue affects: Crafter Software Crafter CMS 3.0 versions prior to 3.0.27; 3.1 versions prior to 3.1.7. | |
| Modificada | Alta (7.2) | 1.1% | — | Craftercms Studio | 6/10/2020 | 17/6/2026 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy scripting. This issue affects: Crafter Software Crafter CMS 3.0 versions prior to 3.0.27; 3.1 versions prior to 3.1.7. | |
| Modificada | Crítica (9.8) | 73% | 💥 Exploit | Craftcms Craft CMS | 4/3/2020 | 17/6/2026 | The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller. | |
| Modificada | Media (6.1) | 3.7% | 💥 Exploit | Craftcms Craft CMS | 31/12/2019 | 17/6/2026 | In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI. | |
| Modificada | Crítica (9.8) | 1.8% | — | Craftcms Craft CMS | 24/10/2019 | 17/6/2026 | In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them. | |
| Modificada | Media (6.1) | 0.84% | — | Craftcms Craft CMS | 11/10/2019 | 17/6/2026 | Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion. | |
| Modificada | Media (4.8) | 0.95% | — | Cybercraftit Content-grabber | 10/10/2019 | 17/6/2026 | The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id. | |
| Modificada | Media (5.4) | 1.0% | — | Webcraftic Woody AD Snippets | 13/9/2019 | 17/6/2026 | The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter. | |
| Modificada | Media (5.4) | 0.70% | — | Ncrafts Formcraft | 10/9/2019 | 17/6/2026 | The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field. | |
| Modificada | Alta (8.8) | 18% | 💥 Exploit | Webcraftic Woody AD Snippets | 3/9/2019 | 17/6/2026 | admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution. | |
| Modificada | Media (6.1) | 1.5% | — | Webcraftic Simple 301 Redirects | 30/8/2019 | 17/6/2026 | The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist. | |
| Modificada | Media (6.1) | 1.3% | — | Webcraftic Simple 301 Redirects-addon-bulk Uploader | 29/8/2019 | 17/6/2026 | The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file. | |
| Modificada | Media (6.1) | 0.91% | — | Crafty Social Buttons Project Crafty Social Buttons | 22/8/2019 | 17/6/2026 | The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS. | |
| Modificada | Alta (8.8) | 0.67% | — | Ncrafts Formcraft | 16/8/2019 | 17/6/2026 | The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF. | |
| Modificada | Alta (7.5) | 1.6% | — | Webcraftic Woody AD Snippets | 8/8/2019 | 17/6/2026 | admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion. | |
| Modificada | Media (5.3) | 9.4% | 💥 Exploit | Craftcms Craft CMS | 26/7/2019 | 17/6/2026 | In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public. | |
| Modificada | Media (6.1) | 0.94% | — | Craftcms Craft CMS | 18/6/2019 | 17/6/2026 | Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS. | |
| Modificada | Alta (8.8) | 0.83% | — | Ncrafts Formcraft | 12/3/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page. |