Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
815 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.68% | 💥 PoC | Kemptechnologies LoadmasterAI | 21/8/2024 | 5/7/2026 | Buffer Overflow vulnerability found in Kemptechnologies Loadmaster before v.7.2.60.0 allows a remote attacker to casue a denial of service via the libkemplink.so, isreverse library. | |
| Modificada | Alta (8.1) | 0.29% | — | Masteriyo | 18/8/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4. | |
| Analizada | Media (6.1) | 0.27% | — | Addonmaster Post Grid Master | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AddonMaster Post Grid Master allows Reflected XSS.This issue affects Post Grid Master: from n/a through 3.4.10. | |
| Analizada | Media (5.9) | 0.33% | — | Expresstech Quiz AND Survey Master | 3/8/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks | |
| Analizada | Media (6.5) | 0.26% | — | Wp-master Pardakht-delkhah | 30/7/2024 | 17/6/2026 | The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack | |
| Aplazada | Media (6.4) | 0.27% | — | Master Currency WPAI | 27/7/2024 | 17/6/2026 | The Master Currency WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's currencyconverterform shortcode in all versions up to, and including, 1.1.61 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (6.5) | 0.23% | — | Averta Master Slider | 26/7/2024 | 17/6/2026 | During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10. | |
| Modificada | Alta (8.8) | 0.49% | — | Stylemixthemes Masterstudy LMS | 22/7/2024 | 17/6/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have. | |
| Aplazada | Media (5.9) | 0.27% | — | Codexhelp Master PopupsAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodexHelp Master Popups allows Stored XSS.This issue affects Master Popups: from n/a through 1.0.3. | |
| Analizada | Media (4.8) | 0.26% | — | Master-addons Master Addons | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through 2.0.6.2. | |
| Modificada | Media (5.4) | 0.38% | — | Expresstech Quiz AND Survey Master | 11/7/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.53% | — | Stylemixthemes Consulting Elementor WidgetsStylemixthemes Masterstudy Elementor Widgets | 9/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Masterstudy Elementor Widgets, StylemixThemes Consulting Elementor Widgets.This issue affects Masterstudy Elementor Widgets: from n/a through 1.2.2; Consulting Elementor Widgets: from n/a through 1.3.0. | |
| Modificada | Alta (8.8) | 0.59% | — | Expresstech Quiz AND Survey Master | 2/7/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role | |
| Analizada | Media (5.5) | 0.35% | — | Expresstech Quiz AND Survey Master | 1/7/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Analizada | Alta (8.1) | 0.52% | — | Wp-master Logo Manager FOR Enamad | 25/6/2024 | 17/6/2026 | The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Analizada | Media (6.1) | 0.33% | — | Averta Master Slider | 20/6/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Averta Master Slider allows Reflected XSS.This issue affects Master Slider: from n/a through 3.10.0. | |
| Analizada | Media (4.3) | 0.16% | — | Averta Master Slider | 19/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.10. | |
| Modificada | Alta (8.8) | 0.62% | — | Webhuntinfotech Photo Video Gallery Master | 19/6/2024 | 17/6/2026 | The Photo Video Gallery Master plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5.3 via deserialization of untrusted input 'PVGM_all_photos_details' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP… | |
| Modificada | Media (5.4) | 0.32% | — | Averta Master Slider | 18/6/2024 | 17/6/2026 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_layer' shortcode in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on the 'css_id' user supplied attribute. This makes it possible for… | |
| Aplazada | Crítica (9.4) | 0.52% | — | Terra-master TOSAI | 14/6/2024 | 17/6/2026 | Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also be used to login to the administration panel and to perform privileged actions. | |
| Aplazada | Alta (7.2) | 0.62% | — | Asus Download MasterAI | 14/6/2024 | 17/6/2026 | ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device. | |
| Aplazada | Alta (7.2) | 0.65% | — | Asus Download MasterAI | 14/6/2024 | 17/6/2026 | The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device. | |
| Analizada | Media (4.6) | 0.19% | — | Wp-master Azan | 14/6/2024 | 17/6/2026 | The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Modificada | Alta (7.2) | 0.53% | — | Asus Download Master | 14/6/2024 | 17/6/2026 | The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory, allowing arbitrary system commands to be… | |
| Modificada | Media (4.8) | 0.29% | — | Asus Download Master | 14/6/2024 | 17/6/2026 | The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Stored Cross-site scripting attacks. |