Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

322 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7)0.25%—Squid Analysis Report Generator Project Squid Analysis Report GeneratorOpensuse Backports SLEOpensuse Leap21/1/202017/6/2026
log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create the directory, and place symlinks in it…
ModificadaAlta (7.5)1.6%—Generator-rs Project Generator-rs9/9/201917/6/2026
An issue was discovered in the generator crate before 0.6.18 for Rust. Uninitialized memory is used by Scope, done, and yield_ during API calls.
ModificadaCrítica (9.8)3.4%—Wpserveur WPS Child Theme Generator30/8/201917/6/2026
The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.
ModificadaAlta (8.8)0.67%—Codeermeneer Companion Sitemap Generator16/8/201917/6/2026
The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF.
ModificadaAlta (7.4)1.2%—Openapi-generator Openapi Generator22/4/201917/6/2026
OpenAPI Tools OpenAPI Generator before 4.0.0-20190419.052012-560 uses http:// URLs in various build.gradle, build.gradle.mustache, and build.sbt files, which may have caused insecurely resolved dependencies.
ModificadaMedia (6.1)1.6%—Podcastgenerator Podcast Generator21/3/201917/6/2026
Podcast Generator 2.7 has stored cross-site scripting (XSS) via the URL addcategory parameter.
ModificadaMedia (6.1)1.5%—Jqueryform PHP Formmail Generator13/7/201817/6/2026
The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to stored cross-site scripting. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution…
ModificadaCrítica (9.8)3.3%—Jqueryform PHP Formmail Generator13/7/201817/6/2026
The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may…
ModificadaAlta (7.5)4.4%—Jqueryform PHP Formmail Generator13/7/201817/6/2026
The generated PHP form code does not properly validate user input folder directories, allowing a remote unauthenticated attacker to perform a path traversal and access arbitrary files on the server. The PHP FormMail Generator website does not use version numbers and is updated continuously. Any PHP form code generated…
ModificadaCrítica (9.8)3.4%—Jqueryform PHP Formmail Generator13/7/201817/6/2026
The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download() function. A remote unauthenticated attacker may be able to use this vulnerability to inject PHP code, or along with CVE-2016-9484 to perform local file inclusion attacks and obtain files from the…
ModificadaCrítica (9.8)4.5%—Jqueryform PHP Formmail Generator13/7/201817/6/2026
Code generated by PHP FormMail Generator may allow a remote unauthenticated user to bypass authentication in the to access the administrator panel by navigating directly to /admin.php?mod=admin&func=panel
ModificadaMedia (4.8)0.36%—Ethicon Endo-surgery Generator Gen11 Firmware5/12/201717/6/2026
An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before November 29, 2017. The security authentication mechanism used between the Ethicon Endo-Surgery Generator Gen11 and single-patient use products can be bypassed, allowing for…
ModificadaCrítica (9.8)1.3%—GE Multilin SR 750 Feeder Protection Relay FirmwareGE Multilin SR 760 Feeder Protection Relay FirmwareGE Multilin SR 469 Motor Protection Relay FirmwareMultilin SR 489 Generator Protection Relay Firmware+630/6/201717/6/2026
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protection Relay, firmware versions prior to Version 5.23; SR 489…
ModificadaAlta (7.5)0.82%—Pivotal PCF Tile Generator13/6/201717/6/2026
An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0. Tiles created by the PCF Tile Generator create a running open security group that overrides security groups set by the operator.
ModificadaMedia (6.8)3.0%💥 ExploitCreative-solutions Contact Form Generator16/9/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) create a field, (2) update a field, (3) delete a field, (4) create a form, (5) update a form, (6)…
ModificadaMedia (5)2.3%—Kylegilman Video Embed & Thumbnail Generator19/3/201216/6/2026
The Media Upload form in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to obtain the installation path via unknown vectors.
ModificadaAlta (7.5)3.4%—Kylegilman Video Embed & Thumbnail Generator19/3/201216/6/2026
kg_callffmpeg.php in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to execute arbitrary commands via unspecified vectors.
ModificadaMedia (5)1.2%—Betella Podcast Generator24/9/201116/6/2026
Podcast Generator 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/themes.php and certain other files.
ModificadaMedia (5)1.2%—Musawir ALI Phpformgenerator24/9/201116/6/2026
phpFormGenerator 2.09 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by forms/process.php.
ModificadaAlta (7.5)0.99%💥 ExploitPreprojects PRE Online Tests Generator23/3/201116/6/2026
SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary SQL commands via the tid2 parameter.
ModificadaAlta (7.5)0.91%💥 ExploitLaubrotel G.cms Generator24/6/201016/6/2026
SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang parameter to the default URI, probably index.php.
ModificadaMedia (6.5)2.1%💥 ExploitVirtuenetz Virtue Online Test Generator9/7/200916/6/2026
admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remote authenticated users to have an unknown impact via unspecified vectors.
ModificadaAlta (7.5)1.00%💥 ExploitVirtuenetz Virtue Online Test Generator9/7/200916/6/2026
SQL injection vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to execute arbitrary SQL commands via the tid parameter.
ModificadaMedia (4.3)1.5%💥 ExploitVirtuenetz Virtue Online Test Generator9/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to inject arbitrary web script or HTML via the tid parameter.
ModificadaMedia (6.5)1.8%💥 ExploitPodcast Generator2/4/200916/6/2026
Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action.
Orbitaley — Vulnerabilidades