Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

329 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.0%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
ModificadaMedia (6.1)0.91%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
ModificadaCrítica (9.1)2.5%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
ModificadaCrítica (9.8)2.2%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
ModificadaMedia (5.3)1.3%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
ModificadaCrítica (9.8)1.8%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
ModificadaAlta (8.8)0.65%—Expresstech Responsive Menu14/8/201917/6/2026
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
ModificadaMedia (6.1)1.7%—Wpsupportplus WP Support Plus Responsive Ticket System21/3/201917/6/2026
A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in…
ModificadaAlta (7.5)3.5%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through the copy_cut action in ajax_calls.php and the paste_clipboard action in execute.php.
ModificadaAlta (7.5)4.0%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the path parameter, through the save_img action in ajax_calls.php.
ModificadaAlta (7.5)5.0%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, through the create_file action in execute.php.
ModificadaAlta (7.5)3.5%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through the get_file action in ajax_calls.php.
ModificadaMedia (6.1)0.81%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandling of the media_preview action.
ModificadaAlta (7.5)3.6%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass through the delete_file action in execute.php.
ModificadaAlta (7.5)3.6%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path traversal mitigation bypass through the delete_folder action in execute.php.
ModificadaMedia (6.1)0.89%—Responsive Video News Script Project Responsive Video News Script16/2/201917/6/2026
PHP Scripts Mall Responsive Video News Script has XSS via the Search Bar. This might, for example, be leveraged for HTML injection or URL redirection.
ModificadaAlta (8.6)1.5%—Tecrail Responsive Filemanager31/10/201817/6/2026
An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-15495.
ModificadaMedia (6.1)0.81%—Tecrail Responsive Filemanager10/10/201817/6/2026
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote attackers to inject arbitrary web script or HTML.
ModificadaAlta (7.5)0.91%—Tecrail Responsive Filemanager10/10/201817/6/2026
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them with the ability to upload and delete files.
ModificadaMedia (5.4)0.48%—Complete Responsive CMS Blog Project Complete Responsive CMS Blog10/9/201817/6/2026
Complete Responsive CMS Blog through 2018-05-20 has XSS via a comment.
ModificadaMedia (5.5)6.4%💥 ExploitTecrail Responsive Filemanager24/8/201817/6/2026
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.
ModificadaAlta (7.5)45%💥 ExploitTecrail Responsive Filemanager24/8/201817/6/2026
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to a location that is outside of that directory, aka Directory…
ModificadaAlta (7.5)2.4%—Tecrail Responsive Filemanager18/8/201817/6/2026
/filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directly in a curl_exec call, as demonstrated by a file:///etc/passwd value.
ModificadaCrítica (9.8)77%💥 ExploitTecrail Responsive Filemanager3/8/201817/6/2026
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
ModificadaCrítica (9.8)1.4%—Responsive Mega Menu PRO Project Responsive Mega Menu PROPrestashop10/5/201817/6/2026
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute a SQL Injection through function calls in the code parameter.
Orbitaley — Vulnerabilidades