Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
634 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.39% | — | I13websolution Post Sliders & Post Grids | 8/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Post Sliders & Post Grids plugin <= 1.0.20 versions. | |
| Modificada | Media (5.4) | 0.47% | — | G5theme Grid Plus | 30/10/2023 | 17/6/2026 | The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'grid_plus_save_layout_callback' and 'grid_plus_delete_callback' functions in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (8.8) | 1.1% | — | G5theme Grid Plus | 30/10/2023 | 17/6/2026 | The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a shortcode attribute. This allows subscriber-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to… | |
| Modificada | Alta (8.8) | 1.1% | — | Zpesystems Nodegrid OS | 28/10/2023 | 17/6/2026 | ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 was discovered to contain a command injection vulnerability via the endpoint /v1/system/toolkit/files/. | |
| Modificada | Media (6.1) | 0.33% | — | G5theme Grid-plus | 27/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in G5Theme Grid Plus – Unlimited grid plugin <= 1.3.2 versions. | |
| Analizada | Alta (7.5) | 3.5% | ⚠ Explotación activa | Northgrid Proself | 18/10/2023 | 17/6/2026 | Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data,… | |
| Modificada | Alta (7.5) | 0.36% | — | Zpesystems Nodegrid OS | 14/10/2023 | 17/6/2026 | An issue in ZPE Systems, Inc Nodegrid OS v.5.8.10 thru v.5.8.13 and v.5.10.3 thru v.5.10.5 allows a remote attacker to obtain sensitive information via the TACACS+ server component. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (8.8) | 0.25% | — | Bdwm Responsive Gallery Grid | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jules Colle, BDWM Responsive Gallery Grid plugin <= 2.3.10 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Boldgrid Post AND Page Builder | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.24.1 versions. | |
| Modificada | Crítica (9.8) | 0.60% | — | Presto-changeo Attribute Grid | 5/10/2023 | 17/6/2026 | Presto Changeo attributegrid up to 2.0.3 was discovered to contain a SQL injection vulnerability via the component disable_json.php. | |
| Modificada | Alta (7.4) | 0.55% | — | Redhat Data GridInfinispan HOT ROD | 4/10/2023 | 17/6/2026 | A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. | |
| Modificada | Alta (8.8) | 0.25% | — | Radiustheme THE Post Grid | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 7.2.7 versions. | |
| Modificada | Alta (8.8) | 0.45% | — | Selinc Sel-5037 SEL Grid Configurator | 31/8/2023 | 17/6/2026 | A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run arbitrary commands on managed devices by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details.… | |
| Modificada | Crítica (9.8) | 0.43% | — | Selinc Sel-5037 SEL Grid Configurator | 31/8/2023 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run system commands with the highest level privilege on the system. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue… | |
| Modificada | Media (6.5) | 0.24% | — | Selinc Sel-5037 SEL Grid Configurator | 31/8/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue… | |
| Modificada | Alta (8.4) | 0.21% | — | Selinc Sel-5037 SEL Grid Configurator | 31/8/2023 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Windows allows Authentication Bypass. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue affects SEL-5037 SEL Grid Configurator: before 4.5.0.20. | |
| Modificada | Media (4.9) | 0.70% | — | Metagauss Profilegrid | 31/8/2023 | 17/6/2026 | The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0. This is due to the passphrase and iv being hardcoded in the 'pm_encrypt_decrypt_pass' function and used across all sites running the plugin. This makes it possible for… | |
| Modificada | Media (6.1) | 0.38% | — | Shooflysolutions Featured Image PRO Post Grid | 25/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in A. R. Jones Featured Image Pro Post Grid plugin <= 5.14 versions. | |
| Modificada | Alta (7.2) | 1.2% | — | Northgrid Proself | 18/8/2023 | 17/6/2026 | Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote authenticated attacker with an administrative privilege to execute arbitrary OS commands. | |
| Modificada | Alta (7.5) | 1.0% | — | Northgrid Proself | 18/8/2023 | 17/6/2026 | Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to log in to the product's Control Panel and perform an unintended operation. | |
| Modificada | Media (4.8) | 0.39% | — | Nimbus CAB Grid | 17/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in M Williams Cab Grid plugin <= 1.5.15 versions. | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Video Grid | 16/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Video Grid plugin <= 1.21 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Wpsofts Portfolio Gallery, Product Catalog - Grid KIT Portfolio | 31/7/2023 | 17/6/2026 | The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (8.8) | 0.87% | — | Metagauss Profilegrid | 18/7/2023 | 17/6/2026 | The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the… |