Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 46% | 💥 Exploit | Wpdevart Poll, Survey, Questionnaire AND Voting System | 12/7/2021 | 17/6/2026 | The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Video Surveillance 7530pd FirmwareCisco Video Surveillance 7070 Firmware | 8/7/2021 | 17/6/2026 | Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. These vulnerabilities are due… | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Video Surveillance 7530pd FirmwareCisco Video Surveillance 7070 Firmware | 8/7/2021 | 17/6/2026 | Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. These vulnerabilities are due… | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Video Surveillance 7530pd FirmwareCisco Video Surveillance 7070 Firmware | 8/7/2021 | 17/6/2026 | Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. These vulnerabilities are due… | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Video Surveillance 7530pd FirmwareCisco Video Surveillance 7070 Firmware | 8/7/2021 | 17/6/2026 | Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. These vulnerabilities are due… | |
| Modificada | Media (6.1) | 0.69% | — | Limesurvey | 28/6/2021 | 17/6/2026 | Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in application/controllers/admin/PermissiontemplatesController.php. | |
| Modificada | Media (5.4) | 0.55% | — | Limesurvey | 28/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature. | |
| Modificada | Media (6.1) | 0.83% | — | Expresstech Quiz AND Survey Master | 20/6/2021 | 17/6/2026 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to… | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Video Surveillance 7530pd FirmwareCisco Video Surveillance 7070 Firmware | 4/6/2021 | 17/6/2026 | Multiple vulnerabilities in the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected… | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Video Surveillance 7530pd FirmwareCisco Video Surveillance 7070 Firmware | 4/6/2021 | 17/6/2026 | Multiple vulnerabilities in the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected… | |
| Analizada | Crítica (9.8) | 30% | ⚠ Explotación activa | Checkbox Survey | 27/5/2021 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7. | |
| Modificada | Media (6.5) | 0.40% | — | Cisco Video Surveillance 8400 FirmwareCisco Video Surveillance 8000p FirmwareCisco Video Surveillance 8020 FirmwareCisco Video Surveillance 8030 Firmware+4 | 6/5/2021 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause an affected IP camera to reload. This vulnerability is due to missing checks when processing Cisco Discovery Protocol messages. An attacker could… | |
| Modificada | Media (6.5) | 0.78% | — | Curveballjs A12n-server | 16/4/2021 | 17/6/2026 | a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0. This feature should only have been accessible to admins. Unfortunately, privileges were incorrectly checked allowing any logged in user to make this change. Patched in… | |
| Modificada | Crítica (9.8) | 5.9% | — | Qnap Surveillance Station | 14/4/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNAP have already fixed this vulnerability in the following versions: Surveillance Station 5.1.5.4.3 (and later) for ARM… | |
| Modificada | Alta (8.8) | 1.9% | — | Expresstech Quiz AND Survey Master | 12/4/2021 | 17/6/2026 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection. The lowest role allowed to use this… | |
| Modificada | Crítica (9.8) | 2.9% | — | Qnap Surveillance Station | 17/2/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNAP have already fixed this vulnerability in the following versions: Surveillance Station 5.1.5.4.3 (and later) for ARM… | |
| Modificada | Crítica (9.8) | 1.3% | — | Limesurvey | 14/2/2021 | 17/6/2026 | LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model. | |
| Modificada | Media (4.8) | 0.66% | — | Otrs Survey | 8/2/2021 | 17/6/2026 | Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. another agent who wants to make changes in the survey). This issue affects: OTRS AG Survey 6.0.x version 6.0.20 and prior versions; 7.0.x version 7.0.19 and prior versions. | |
| Modificada | Media (5.4) | 0.69% | — | Oracle Application Express Survey Builder | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Application Express Survey Builder component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application… | |
| Modificada | Media (4.3) | 0.50% | — | Cisco Video Surveillance 8000p IP Camera FirmwareCisco Video Surveillance 8020 IP Camera FirmwareCisco Video Surveillance 8030 IP Camera FirmwareCisco Video Surveillance 8070 IP Camera Firmware+4 | 13/1/2021 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause an affected IP camera to reload. The vulnerability is due to missing checks when Cisco Discovery Protocol messages are processed. An attacker… | |
| Modificada | Crítica (9.9) | 76% | 💥 Exploit | Expresstech Quiz AND Survey Master | 1/1/2021 | 17/6/2026 | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via… | |
| Modificada | Crítica (9.8) | 5.1% | — | Expresstech Quiz AND Survey Master | 1/1/2021 | 17/6/2026 | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload,… | |
| Modificada | Media (5.4) | 0.70% | — | Limesurvey | 31/12/2020 | 17/6/2026 | LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser. | |
| Modificada | Media (5.4) | 0.70% | — | Limesurvey | 31/12/2020 | 17/6/2026 | LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parameters). When the survey participant being edited, e.g. by an administrative user, the JavaScript code will be executed in the browser. | |
| Modificada | Crítica (9.8) | 4.9% | — | Urve | 23/12/2020 | 17/6/2026 | An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0%3bpowershell+-c+" substring, it is possible to execute a Powershell command and redirect its output to a file under the web root. |