Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

729 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.91%—Expresstech Quiz AND Survey Master28/10/202217/6/2026
Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaMedia (5.4)0.46%—Expresstech Quiz AND Survey Master28/10/202217/6/2026
Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaMedia (5.4)0.50%—Expresstech Quiz AND Survey Master28/10/202217/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaAlta (7.5)1.2%—Devexpress Asp.net WEB Forms Controls18/10/202217/6/2026
The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) vulnerability which allows attackers to access the application source code. NOTE:…
ModificadaAlta (7.5)0.79%—Villatheme Dropshipping AND Fulfillment FOR Aliexpress AND Woocommerce14/10/202217/6/2026
Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 on WordPress.
ModificadaMedia (6.1)0.95%—Express XSS Sanitizer Project Express XSS Sanitizer26/9/202217/6/2026
The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.
ModificadaAlta (7.5)0.78%—Hcltech Versionvault Express30/8/202217/6/2026
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
ModificadaMedia (6.5)0.46%—Hcltech Versionvault Express30/8/202217/6/2026
HCL VersionVault Express exposes administrator credentials.
ModificadaAlta (8.8)3.6%—Devexpress3/8/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentication is required to exploit this vulnerability. The specific flaw exists within the SafeBinaryFormatter library. The issue results from the lack of proper validation of user-supplied data, which can…
ModificadaMedia (5.9)1.1%—Cisco ExpresswayCisco Telepresence Video Communication Server6/7/202217/6/2026
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. Note: Cisco Expressway Series refers…
ModificadaMedia (6.5)1.9%—Cisco ExpresswayCisco Telepresence Video Communication Server6/7/202217/6/2026
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. Note: Cisco Expressway Series refers…
ModificadaCrítica (9.8)1.6%—Mitel Mivoice BusinessMitel Mivoice Business Express17/6/202217/6/2026
A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow attack due to insufficient validation of URL parameters. A…
ModificadaAlta (8.1)2.0%💥 PoCCaphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaCrítica (9.1)0.59%—Hcltech Versionvault Express25/5/202217/6/2026
VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.
ModificadaAlta (7.5)1.4%—Express-fileupload Project Express-fileupload12/4/202217/6/2026
An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite of files in the web application server.
ModificadaCrítica (9.8)2.9%—Express-fileupload Project Express-fileupload12/4/202217/6/2026
An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted PHP file. NOTE: the vendor's position is that the observed behavior can only occur with "intentional misusing of the API": the express-fileupload middleware is not…
ModificadaMedia (6.1)0.74%—Auth0 Express Openid Connect31/3/202217/6/2026
Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middleware, either directly or through the default `authRequired` option, are vulnerable to an Open Redirect when the middleware is applied to a catch all route. If all routes…
ModificadaAlta (8.8)1.3%—Expresstech Responsive Menu18/3/202217/6/2026
Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).
ModificadaAlta (7.5)2.5%—CkeditorDrupalOracle Application ExpressOracle Commerce Merchandising+516/3/202217/6/2026
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A…
ModificadaMedia (5.4)1.2%—CkeditorDrupalOracle Application ExpressOracle Commerce Merchandising+516/3/202217/6/2026
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could…
AnalizadaCrítica (9.8)87%⚠ Explotación activa💥 ExploitMitel MicollabMitel Mivoice Business Express10/3/202217/6/2026
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for…
ModificadaMedia (5.3)1.2%—Correosexpress Project Correosexpress7/3/202217/6/2026
The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensitive information such as sender/receiver names, phone numbers, physical and email addresses
ModificadaAlta (7.2)0.93%—Expressionengine18/2/202217/6/2026
Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel access to execute the attack.
ModificadaAlta (8.8)1.2%—Frourio-express7/2/202217/6/2026
Frourio-express is a minimal full stack framework, for TypeScript. Frourio-express users who uses frourio-express version prior to v0.26.0 and integration with class-validator through `validators/` folder are subject to a input validation vulnerability. Validators do not work properly for request bodies and queries in…
ModificadaMedia (5.4)0.97%—Expresstech Quiz AND Survey Master17/1/202217/6/2026
Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master.
Orbitaley — Vulnerabilidades