Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
413 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.5% | — | Rockwellautomation Factorytalk Services Platform | 23/3/2020 | 17/6/2026 | In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exposes a .NET Remoting endpoint via RNADiagnosticsSrv.exe at TCPtcp/8082, which can insecurely deserialize untrusted data. | |
| Modificada | Alta (7.2) | 1.5% | — | Jfrog Artifactory | 16/3/2020 | 17/6/2026 | In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results." | |
| Modificada | Alta (8.8) | 1.1% | — | Widgetfactorylimited JCE | 9/3/2020 | 17/6/2026 | JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script. | |
| Modificada | Alta (8.8) | 5.5% | 💥 PoC | Jfrog Artifactory | 23/1/2020 | 17/6/2026 | In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the DefaultObjectWrapper class makes certain Java functions… | |
| Modificada | Crítica (9.1) | 23% | 💥 PoC | Webfactoryltd WP Database Reset | 16/1/2020 | 17/6/2026 | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a wp-admin/admin-post.php?db-reset-tables[]=comments URI. | |
| Modificada | Alta (8.8) | 2.5% | — | Webfactoryltd WP Database Reset | 16/1/2020 | 17/6/2026 | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users request) to escalate their privileges to administrator while dropping all other users from the table. | |
| Modificada | Alta (7.6) | 2.0% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 9/1/2020 | 17/6/2026 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting). | |
| Modificada | Media (5.4) | 1.1% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 9/1/2020 | 17/6/2026 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes. | |
| Modificada | Alta (8.8) | 0.92% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 9/1/2020 | 17/6/2026 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo. | |
| Modificada | Crítica (9) | 0.86% | — | Webfactoryltd 301 Redirects | 19/12/2019 | 17/6/2026 | The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in a… | |
| Modificada | Media (6.1) | 0.92% | — | Wpfactory Download Plugins AND Themes From Dashboard | 7/10/2019 | 17/6/2026 | includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues. | |
| Modificada | Crítica (9.8) | 2.0% | — | Wpmadeasy Shortcode Factory | 22/8/2019 | 17/6/2026 | The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion. | |
| Modificada | Media (6.1) | 0.91% | — | Wpmadeeasy Shortcode Factory | 21/8/2019 | 17/6/2026 | The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg. | |
| Modificada | Crítica (9.8) | 2.3% | — | Thephpfactory Micro Deal Factory | 19/6/2019 | 17/6/2026 | SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/. | |
| Modificada | Crítica (9.8) | 2.3% | — | Thephpfactory Dutch Auction Factory | 19/6/2019 | 17/6/2026 | SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter. | |
| Modificada | Crítica (9.8) | 2.3% | — | Thephpfactory Auction Factory | 19/6/2019 | 17/6/2026 | SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter. | |
| Modificada | Media (6.5) | 0.71% | — | Jfrog Artifactory | 31/5/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven… | |
| Modificada | Media (4.3) | 1.8% | — | Jfrog Artifactory | 31/5/2019 | 17/6/2026 | A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. | |
| Modificada | Media (4.3) | 1.8% | — | Jfrog Artifactory | 31/5/2019 | 17/6/2026 | A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in… | |
| Modificada | Media (4.3) | 0.84% | — | Jfrog Artifactory | 31/5/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials… | |
| Modificada | Crítica (9.8) | 3.0% | — | Jfrog Artifactory | 16/4/2019 | 17/6/2026 | JFrog Artifactory Pro 6.5.9 has Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 54% | 💥 Exploit | Jfrog Artifactory | 11/4/2019 | 17/6/2026 | An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP… | |
| Modificada | Alta (7.3) | 0.46% | — | Schneider-electric OPC Factory Server | 25/3/2019 | 17/6/2026 | A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20… | |
| Modificada | Alta (7.5) | 3.9% | — | Rockwellautomation Factorytalk Services Platform | 24/1/2019 | 17/6/2026 | In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated attacker could send numerous crafted packets to service ports resulting in memory consumption that could lead to a partial or complete denial-of-service condition to the affected services. | |
| Modificada | Alta (7.8) | 0.33% | — | Jfrog Artifactory | 9/1/2019 | 17/6/2026 | An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin. |