Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

413 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)5.5%—Rockwellautomation Factorytalk Services Platform23/3/202017/6/2026
In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exposes a .NET Remoting endpoint via RNADiagnosticsSrv.exe at TCPtcp/8082, which can insecurely deserialize untrusted data.
ModificadaAlta (7.2)1.5%—Jfrog Artifactory16/3/202017/6/2026
In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."
ModificadaAlta (8.8)1.1%—Widgetfactorylimited JCE9/3/202017/6/2026
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.
ModificadaAlta (8.8)5.5%💥 PoCJfrog Artifactory23/1/202017/6/2026
In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the DefaultObjectWrapper class makes certain Java functions…
ModificadaCrítica (9.1)23%💥 PoCWebfactoryltd WP Database Reset16/1/202017/6/2026
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a wp-admin/admin-post.php?db-reset-tables[]=comments URI.
ModificadaAlta (8.8)2.5%—Webfactoryltd WP Database Reset16/1/202017/6/2026
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users request) to escalate their privileges to administrator while dropping all other users from the table.
ModificadaAlta (7.6)2.0%—Webfactoryltd Minimal Coming Soon & Maintenance Mode9/1/202017/6/2026
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).
ModificadaMedia (5.4)1.1%—Webfactoryltd Minimal Coming Soon & Maintenance Mode9/1/202017/6/2026
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
ModificadaAlta (8.8)0.92%—Webfactoryltd Minimal Coming Soon & Maintenance Mode9/1/202017/6/2026
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.
ModificadaCrítica (9)0.86%—Webfactoryltd 301 Redirects19/12/201917/6/2026
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in a…
ModificadaMedia (6.1)0.92%—Wpfactory Download Plugins AND Themes From Dashboard7/10/201917/6/2026
includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues.
ModificadaCrítica (9.8)2.0%—Wpmadeasy Shortcode Factory22/8/201917/6/2026
The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion.
ModificadaMedia (6.1)0.91%—Wpmadeeasy Shortcode Factory21/8/201917/6/2026
The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.
ModificadaCrítica (9.8)2.3%—Thephpfactory Micro Deal Factory19/6/201917/6/2026
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.
ModificadaCrítica (9.8)2.3%—Thephpfactory Dutch Auction Factory19/6/201917/6/2026
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
ModificadaCrítica (9.8)2.3%—Thephpfactory Auction Factory19/6/201917/6/2026
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.
ModificadaMedia (6.5)0.71%—Jfrog Artifactory31/5/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven…
ModificadaMedia (4.3)1.8%—Jfrog Artifactory31/5/201917/6/2026
A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
ModificadaMedia (4.3)1.8%—Jfrog Artifactory31/5/201917/6/2026
A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in…
ModificadaMedia (4.3)0.84%—Jfrog Artifactory31/5/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials…
ModificadaCrítica (9.8)3.0%—Jfrog Artifactory16/4/201917/6/2026
JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.
ModificadaCrítica (9.8)54%💥 ExploitJfrog Artifactory11/4/201917/6/2026
An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP…
ModificadaAlta (7.3)0.46%—Schneider-electric OPC Factory Server25/3/201917/6/2026
A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20…
ModificadaAlta (7.5)3.9%—Rockwellautomation Factorytalk Services Platform24/1/201917/6/2026
In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated attacker could send numerous crafted packets to service ports resulting in memory consumption that could lead to a partial or complete denial-of-service condition to the affected services.
ModificadaAlta (7.8)0.33%—Jfrog Artifactory9/1/201917/6/2026
An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin.
Orbitaley — Vulnerabilidades