Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.9) | 3.0% | — | Getgrav Grav | 15/5/2024 | 17/6/2026 | Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twig Syntax. This includes Grav user account files - `/grav/user/accounts/*.yaml`. This file stores hashed user password, 2FA secret, and the password reset token. This can… | |
| Analizada | Crítica (9.8) | 0.73% | — | Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center | 9/4/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: Bitdefender… | |
| Analizada | Crítica (9.8) | 0.52% | — | Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center | 9/4/2024 | 17/6/2026 | An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint Security for Linux version 7.0.5.200089… | |
| Analizada | Alta (8.8) | 1.6% | — | Getgrav Grav | 21/3/2024 | 17/6/2026 | Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from grav context, an attacker can redefine the escape function and execute arbitrary commands. Twig processing of static pages can be enabled in the front matter by any… | |
| Analizada | Alta (8.8) | 1.2% | — | Getgrav Grav | 21/3/2024 | 17/6/2026 | Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Grav context, an attacker can redefine config variable. As a result, attacker can bypass a previous SSTI mitigation. Twig processing of static pages can be enabled in the… | |
| Analizada | Alta (8.8) | 1.4% | — | Getgrav Grav | 21/3/2024 | 17/6/2026 | Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDangerousFunction function, but does not impose restrictions on twig functions like twig_array_map, allowing attackers to bypass the validation and execute arbitrary commands.… | |
| Analizada | Alta (8.8) | 5.8% | 💥 PoC | Getgrav Grav | 21/3/2024 | 17/6/2026 | Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI), which allows any authenticated user (editor permissions are sufficient) to execute arbitrary code on the remote server bypassing the existing security sandbox. Version… | |
| Analizada | Alta (8.8) | 61% | — | Getgrav Grav | 21/3/2024 | 17/6/2026 | Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling attackers to replace or create files with extensions like .json, .zip, .css, .gif, etc. This critical security flaw poses severe risks, that… | |
| Analizada | Alta (8.8) | 1.4% | — | Getgrav Grav | 21/3/2024 | 17/6/2026 | Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient permission validation and inadequate file name validation. This may lead to remote code execution. Version 1.7.43 fixes this issue. | |
| Modificada | Media (5.4) | 0.44% | — | Vickyagravat Codemirror Blocks | 28/2/2024 | 17/6/2026 | The CodeMirror Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Code Mirror block in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Modificada | Media (5.4) | 1.00% | — | Getgrav Grav | 9/2/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover attribute of an ISINDEX element. | |
| Modificada | Media (4.8) | 0.40% | — | Gravitymaster Product Enquiry FOR Woocommerce | 22/1/2024 | 17/6/2026 | The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.3) | 0.20% | — | Gravitymaster Product Enquiry FOR Woocommerce | 22/1/2024 | 17/6/2026 | The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack | |
| Analizada | Media (6.1) | 0.46% | — | Gravitymaster Product Enquiry FOR Woocommerce | 16/1/2024 | 17/6/2026 | The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (8.8) | 0.22% | — | Brightplugins Block IPS FOR Gravity Forms | 29/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bright Plugins Block IPs for Gravity Forms.This issue affects Block IPs for Gravity Forms: from n/a through 1.0.1. | |
| Modificada | Crítica (9.8) | 0.62% | — | Gravityforms Gravity Forms | 20/12/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3. | |
| Modificada | Alta (8.8) | 0.27% | — | Gravitymaster Product Enquiry FOR Woocommerce | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Gravity Master Product Enquiry for WooCommerce.This issue affects Product Enquiry for WooCommerce: from n/a through 3.0. | |
| Modificada | Media (6.1) | 0.43% | — | Getgrav Dom-sanitizer | 22/11/2023 | 17/6/2026 | DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions. | |
| Analizada | Media (6.1) | 0.41% | — | Gravitymaster Product Enquiry FOR Woocommerce | 16/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions. | |
| Modificada | Media (6.1) | 0.43% | — | Gravitymaster Product Enquiry FOR Woocommerce | 13/11/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions. | |
| Modificada | Media (5.4) | 0.54% | — | Gravitydesign Telephone Number Linker | 7/11/2023 | 17/6/2026 | The Telephone Number Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'telnumlink' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (8.8) | 2.8% | — | Getgrav Grav | 18/7/2023 | 17/6/2026 | Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|filter` and `|reduce` twigs implemented in the commit `71bbed1` introduces bypass of the denylist due to incorrect return value from… | |
| Modificada | Media (6.1) | 0.49% | — | Mediaburst Gravity Forms | 17/7/2023 | 17/6/2026 | The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin. | |
| Modificada | Media (6.5) | 0.31% | — | Gsheetconnector Gravity Forms Google Sheets Connector | 27/6/2023 | 17/6/2026 | The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Modificada | Media (6.1) | 0.59% | — | Getgrav Grav | 14/6/2023 | 17/6/2026 | Grav is a flat-file content management system. In versions 1.7.42 and prior, the "/forgot_password" page has a self-reflected cross-site scripting vulnerability that can be exploited by injecting a script into the "email" parameter of the request. While this vulnerability can potentially allow an attacker to execute… |