Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.25% | — | Squid Analysis Report Generator Project Squid Analysis Report GeneratorOpensuse Backports SLEOpensuse Leap | 21/1/2020 | 17/6/2026 | log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create the directory, and place symlinks in it… | |
| Modificada | Alta (7.5) | 1.6% | — | Generator-rs Project Generator-rs | 9/9/2019 | 17/6/2026 | An issue was discovered in the generator crate before 0.6.18 for Rust. Uninitialized memory is used by Scope, done, and yield_ during API calls. | |
| Modificada | Crítica (9.8) | 3.4% | — | Wpserveur WPS Child Theme Generator | 30/8/2019 | 17/6/2026 | The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal. | |
| Modificada | Alta (8.8) | 0.67% | — | Codeermeneer Companion Sitemap Generator | 16/8/2019 | 17/6/2026 | The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF. | |
| Modificada | Alta (7.4) | 1.2% | — | Openapi-generator Openapi Generator | 22/4/2019 | 17/6/2026 | OpenAPI Tools OpenAPI Generator before 4.0.0-20190419.052012-560 uses http:// URLs in various build.gradle, build.gradle.mustache, and build.sbt files, which may have caused insecurely resolved dependencies. | |
| Modificada | Media (6.1) | 1.6% | — | Podcastgenerator Podcast Generator | 21/3/2019 | 17/6/2026 | Podcast Generator 2.7 has stored cross-site scripting (XSS) via the URL addcategory parameter. | |
| Modificada | Media (6.1) | 1.5% | — | Jqueryform PHP Formmail Generator | 13/7/2018 | 17/6/2026 | The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to stored cross-site scripting. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution… | |
| Modificada | Crítica (9.8) | 3.3% | — | Jqueryform PHP Formmail Generator | 13/7/2018 | 17/6/2026 | The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may… | |
| Modificada | Alta (7.5) | 4.4% | — | Jqueryform PHP Formmail Generator | 13/7/2018 | 17/6/2026 | The generated PHP form code does not properly validate user input folder directories, allowing a remote unauthenticated attacker to perform a path traversal and access arbitrary files on the server. The PHP FormMail Generator website does not use version numbers and is updated continuously. Any PHP form code generated… | |
| Modificada | Crítica (9.8) | 3.4% | — | Jqueryform PHP Formmail Generator | 13/7/2018 | 17/6/2026 | The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download() function. A remote unauthenticated attacker may be able to use this vulnerability to inject PHP code, or along with CVE-2016-9484 to perform local file inclusion attacks and obtain files from the… | |
| Modificada | Crítica (9.8) | 4.5% | — | Jqueryform PHP Formmail Generator | 13/7/2018 | 17/6/2026 | Code generated by PHP FormMail Generator may allow a remote unauthenticated user to bypass authentication in the to access the administrator panel by navigating directly to /admin.php?mod=admin&func=panel | |
| Modificada | Media (4.8) | 0.36% | — | Ethicon Endo-surgery Generator Gen11 Firmware | 5/12/2017 | 17/6/2026 | An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before November 29, 2017. The security authentication mechanism used between the Ethicon Endo-Surgery Generator Gen11 and single-patient use products can be bypassed, allowing for… | |
| Modificada | Crítica (9.8) | 1.3% | — | GE Multilin SR 750 Feeder Protection Relay FirmwareGE Multilin SR 760 Feeder Protection Relay FirmwareGE Multilin SR 469 Motor Protection Relay FirmwareMultilin SR 489 Generator Protection Relay Firmware+6 | 30/6/2017 | 17/6/2026 | A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protection Relay, firmware versions prior to Version 5.23; SR 489… | |
| Modificada | Alta (7.5) | 0.82% | — | Pivotal PCF Tile Generator | 13/6/2017 | 17/6/2026 | An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0. Tiles created by the PCF Tile Generator create a running open security group that overrides security groups set by the operator. | |
| Modificada | Media (6.8) | 3.0% | 💥 Exploit | Creative-solutions Contact Form Generator | 16/9/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) create a field, (2) update a field, (3) delete a field, (4) create a form, (5) update a form, (6)… | |
| Modificada | Media (5) | 2.3% | — | Kylegilman Video Embed & Thumbnail Generator | 19/3/2012 | 16/6/2026 | The Media Upload form in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to obtain the installation path via unknown vectors. | |
| Modificada | Alta (7.5) | 3.4% | — | Kylegilman Video Embed & Thumbnail Generator | 19/3/2012 | 16/6/2026 | kg_callffmpeg.php in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to execute arbitrary commands via unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | Betella Podcast Generator | 24/9/2011 | 16/6/2026 | Podcast Generator 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/themes.php and certain other files. | |
| Modificada | Media (5) | 1.2% | — | Musawir ALI Phpformgenerator | 24/9/2011 | 16/6/2026 | phpFormGenerator 2.09 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by forms/process.php. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Preprojects PRE Online Tests Generator | 23/3/2011 | 16/6/2026 | SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary SQL commands via the tid2 parameter. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Laubrotel G.cms Generator | 24/6/2010 | 16/6/2026 | SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang parameter to the default URI, probably index.php. | |
| Modificada | Media (6.5) | 2.1% | 💥 Exploit | Virtuenetz Virtue Online Test Generator | 9/7/2009 | 16/6/2026 | admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remote authenticated users to have an unknown impact via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Virtuenetz Virtue Online Test Generator | 9/7/2009 | 16/6/2026 | SQL injection vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to execute arbitrary SQL commands via the tid parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Virtuenetz Virtue Online Test Generator | 9/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to inject arbitrary web script or HTML via the tid parameter. | |
| Modificada | Media (6.5) | 1.8% | 💥 Exploit | Podcast Generator | 2/4/2009 | 16/6/2026 | Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action. |