Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 17% | 💥 Exploit | Wedevs WP User Frontend | 24/1/2022 | 17/6/2026 | The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting | |
| Modificada | Media (6.5) | 1.3% | — | Parity Frontier | 14/1/2022 | 17/6/2026 | Frontier is Substrate's Ethereum compatibility layer. Prior to commit number `8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664`, a bug in Frontier's MODEXP precompile implementation can cause an integer underflow in certain conditions. This will cause a node crash for debug builds. For release builds (and production… | |
| Modificada | Media (6.1) | 0.80% | — | Wpfront User Role Editor | 27/12/2021 | 17/6/2026 | The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 8.5% | 💥 Exploit | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 21/12/2021 | 17/6/2026 | The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections | |
| Modificada | Media (6.1) | 0.66% | — | Vfront | 8/11/2021 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in VFront 0.99.5 via the (1) s parameter in search_all.php and the (2) msg parameter in add.attach.php. | |
| Modificada | Alta (8.8) | 1.3% | — | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 8/11/2021 | 17/6/2026 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using… | |
| Modificada | Media (4.8) | 0.62% | — | Wooassist Storefront Footer Text | 8/11/2021 | 17/6/2026 | The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed. | |
| Modificada | Media (5.3) | 1.4% | — | Parity Frontier | 13/10/2021 | 17/6/2026 | Frontier is Substrate's Ethereum compatibility layer. In the newly introduced signed Frontier-specific extrinsic for `pallet-ethereum`, a large part of transaction validation logic was only called in transaction pool validation, but not in block execution. Malicious validators can take advantage of this to put invalid… | |
| Modificada | Media (6.1) | 26% | 💥 Exploit | Frontend Uploader Project Frontend Uploader | 11/10/2021 | 17/6/2026 | The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly | |
| Modificada | Media (5.4) | 0.62% | — | Wpfront Notification BAR | 6/9/2021 | 17/6/2026 | The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.3) | 1.2% | — | Parity Frontier | 3/9/2021 | 17/6/2026 | Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26, a bug in `pallet-ethereum` can cause invalid transactions to be included in the Ethereum block state in `pallet-ethereum` due to not validating the input data size. Any invalid transactions included… | |
| Modificada | Media (5.4) | 0.62% | — | Wpfront Scroll TOP | 23/8/2021 | 17/6/2026 | The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (4.8) | 0.69% | — | Wpfront Notification BAR | 16/8/2021 | 17/6/2026 | The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue | |
| Modificada | Crítica (9.8) | 0.71% | — | Amazon Cloudfront | 12/8/2021 | 17/6/2026 | Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consider to be weak ciphers. | |
| Modificada | Crítica (9.8) | 1.2% | — | Frontiersoftware Ichris | 29/5/2021 | 17/6/2026 | Frontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by any client user. | |
| Modificada | Alta (7.5) | 1.2% | — | Frontiersoftware Ichris | 29/5/2021 | 17/6/2026 | Frontier ichris through 5.18 mishandles making a DNS request for the hostname in the HTTP Host header, as demonstrated by submitting 127.0.0.1 multiple times for DoS. | |
| Modificada | Media (4.3) | 0.67% | — | Otrs ItsmconfigurationmanagementOtrscisincustomerfrontend | 22/3/2021 | 17/6/2026 | Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects: OTRSCIsInCustomerFrontend 7.0.15 and prior versions, ITSMConfigurationManagement 7.0.24 and prior versions | |
| Modificada | Alta (7.5) | 1.1% | — | Epignosishq Efront | 3/3/2021 | 17/6/2026 | A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password reset 1-time token. An attacker can visit the password reset supplying the password reset token to reset the password of an account of their… | |
| Modificada | Media (4.3) | 0.76% | — | Otrs CIS IN Customer Frontend | 8/2/2021 | 17/6/2026 | Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions. | |
| Modificada | Crítica (9.8) | 1.5% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Media (6.5) | 0.53% | — | View Frontend Statistics Project View Frontend Statistics | 18/11/2020 | 17/6/2026 | An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext passwords if ext:felogin is installed) may be… | |
| Modificada | Media (4.9) | 1.0% | — | Frontaccounting | 30/9/2020 | 17/6/2026 | An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php. | |
| Modificada | Media (6.5) | 1.3% | — | Citrix Storefront Server | 18/9/2020 | 17/6/2026 | Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server. | |
| Modificada | Alta (7.1) | 0.72% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 14/7/2020 | 17/6/2026 | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'. |