Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
815 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.29% | — | Luis Rock Master BARAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luis Rock Master Bar master-bar allows Reflected XSS.This issue affects Master Bar: from n/a through <= 1.0. | |
| Modificada | Media (5.3) | 0.42% | — | Masteriyo | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.6. | |
| Modificada | Alta (7.5) | 0.52% | — | Masteriyo | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4. | |
| Aplazada | Media (5.3) | 0.40% | — | Stylemixthemes Masterstudy Elementor WidgetsAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in StylemixThemes Masterstudy Elementor Widgets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Masterstudy Elementor Widgets: from n/a through 1.2.2. | |
| Analizada | Crítica (9.8) | 0.41% | — | Stylemixthemes Masterstudy LMS | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.2.12. | |
| Aplazada | Crítica (9.3) | 18% | — | Delta Electronics Infrasuite Device MasterAI | 30/10/2024 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary .NET objects prior to authentication. | |
| Modificada | Media (6.1) | 0.29% | — | Soft-master Affiliate Platform | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilias Gomatos Affiliate Platform smdp-affiliate-platform allows Reflected XSS.This issue affects Affiliate Platform: from n/a through <= 1.4.8. | |
| Aplazada | Crítica (10) | 1.1% | 💥 PoC | Masterhomepage Automatic TranslationAI | 29/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translation allows Upload a Web Shell to a Web Server.This issue affects Automatic Translation: from n/a through <= 1.0.4. | |
| Analizada | Media (6.5) | 0.63% | — | Masteriyo | 29/10/2024 | 17/6/2026 | The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including, 1.13.3. This makes it possible for… | |
| Analizada | Media (5.4) | 0.28% | — | Masteriyo | 29/10/2024 | 17/6/2026 | The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Baja (2.1) | 0.29% | — | Hikvision Hikcentral Master | 18/10/2024 | 17/6/2026 | There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data. | |
| Modificada | Media (5.5) | 0.55% | — | Hikvision Hikcentral Master | 18/10/2024 | 17/6/2026 | There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file. | |
| Analizada | Alta (8.8) | 0.65% | — | Newtype Flowmaster BPM Plus | 15/10/2024 | 17/6/2026 | The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents. | |
| Analizada | Alta (8.8) | 0.61% | — | Newtype Flowmaster BPM Plus | 15/10/2024 | 17/6/2026 | The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie. | |
| Analizada | Crítica (9.8) | 1.2% | — | Progress Loadmaster | 11/10/2024 | 17/6/2026 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12 and… | |
| Aplazada | Media (6.4) | 0.27% | — | Cmsmasters Content ComposerAI | 9/10/2024 | 17/6/2026 | The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multiple shortcodes in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.36% | — | Stylemixthemes Masterstudy LMS StarterAI | 25/9/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affects Masterstudy LMS Starter: from n/a through 1.1.8. | |
| Modificada | Media (4.8) | 0.40% | — | Expresstech Quiz AND Survey Master | 23/9/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.33% | — | Wp-master Logo Manager FOR Enamad | 17/9/2024 | 17/6/2026 | The Logo Manager For Enamad WordPress plugin through 0.7.1 does not sanitise and escape in its widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (6.8) | 0.55% | — | Progress Multi-tenant LoadmasterProgress Loadmaster | 12/9/2024 | 17/6/2026 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.0 (inclusive) From 7.2.49.0 to 7.2.54.11 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.11 and… | |
| Analizada | Media (5.4) | 0.32% | — | Master-addons Master Addons | 10/9/2024 | 17/6/2026 | The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-jltma-wrapper-link element in all versions up to, and including 2.0.6.4 due to insufficient input sanitization and output escaping on… | |
| Modificada | Alta (7.2) | 44% | 💥 Exploit | Kemptechnologies LoadmasterKemptechnologies Multi-tenant Hypervisor Firmware | 5/9/2024 | 17/6/2026 | Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above | |
| Analizada | Media (5.3) | 0.48% | — | Master-nan Sweet-cms | 30/8/2024 | 17/6/2026 | A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been rated as problematic. This issue affects the function LogHandler of the file middleware/log.go. The manipulation leads to improper output neutralization for logs. The attack may be initiated remotely. This… | |
| Analizada | Media (5.3) | 0.61% | — | Master-nan Sweet-cms | 30/8/2024 | 17/6/2026 | A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been declared as critical. This vulnerability affects unknown code of the file /table/index. The manipulation leads to sql injection. The attack can be initiated remotely. This product is using a rolling release to… | |
| Analizada | Media (4.7) | 0.43% | — | Expresstech Quiz AND Survey Master | 26/8/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks. |