Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

379 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)2.5%—Getgrav Grav27/9/202117/6/2026
grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking
ModificadaMedia (5.4)1.6%—Getgrav Grav-plugin-admin27/9/202117/6/2026
grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames
ModificadaMedia (5.5)0.64%—Creolabs Gravity20/9/202117/6/2026
An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function list_iterator_next() located in gravity_core.c. It allows an attacker to cause Denial of Service.
ModificadaAlta (7.8)0.76%—Creolabs Gravity20/9/202117/6/2026
An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function ircode_register_pop_context_protect() located in gravity_ircode.c. It allows an attacker to cause Denial of Service.
ModificadaMedia (5.5)0.64%—Creolabs Gravity20/9/202117/6/2026
An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function gravity_string_to_value() located in gravity_value.c. It allows an attacker to cause Denial of Service.
ModificadaMedia (5.5)0.64%—Creolabs Gravity20/9/202117/6/2026
An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function ircode_add_check() located in gravity_ircode.c. It allows an attacker to cause Denial of Service.
ModificadaAlta (7.8)1.1%—Creolabs Gravity20/9/202117/6/2026
An issue was discovered in gravity through 0.8.1. A heap-buffer-overflow exists in the function gnode_function_add_upvalue located in gravity_ast.c. It allows an attacker to cause code Execution.
ModificadaAlta (7.8)0.21%—Bitdefender Gravityzone Business Security18/5/202117/6/2026
Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to load a third party DLL to elevate privileges. This issue affects Bitdefender GravityZone Business Security versions prior to 6.6.23.329.
ModificadaAlta (7.2)31%💥 ExploitGetgrav Grav13/4/202117/6/2026
Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arbitrary code execution and elevate privileges on the instance. The issue was…
ModificadaAlta (7.2)2.6%—Getgrav Grav Admin13/4/202117/6/2026
The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. As a consequence, users with the permission `admin.login` can install third-party plugins and their dependencies. By installing the right plugin, an attacker can obtain an arbitrary code execution primitive and elevate their…
ModificadaCrítica (9.8)81%💥 ExploitGetgrav Grav-plugin-admin7/4/202117/6/2026
Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an unauthenticated user can execute some methods of administrator controller without needing any credentials. Particular method execution will result in arbitrary YAML file…
ModificadaAlta (8.8)1.4%—Getgrav Grav CMS15/3/202117/6/2026
The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).
ModificadaMedia (5.5)0.98%—Getgrav Grav CMS15/3/202117/6/2026
The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)
ModificadaAlta (8.1)2.9%—Getgrav Grav CMS15/3/202117/6/2026
The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)
ModificadaMedia (5.4)0.78%—Rocketgenius Gravityforms20/1/202117/6/2026
A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via a textarea field. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
ModificadaMedia (5.4)0.78%—Rocketgenius Gravityforms20/1/202117/6/2026
Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
ModificadaMedia (4.8)0.80%—Rocketgenius Gravityforms20/1/202117/6/2026
A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via the import of a GF form. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
ModificadaAlta (7.5)1.8%—Rocketgenius Gravityforms2/6/202017/6/2026
common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.
ModificadaMedia (6.1)11%💥 ExploitGetgrav Grav4/4/202017/6/2026
Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.
ModificadaMedia (6.1)3.9%💥 ExploitKatz Infusionsoft Gravity Forms27/12/201917/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2) contactId, or (3) campaignId parameter.
ModificadaCrítica (9.8)2.3%—Gravitatedesign Gravitate QA Tracker10/9/201917/6/2026
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
ModificadaMedia (6.1)1.5%—Getgrav Grav CMS9/9/201917/6/2026
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
ModificadaMedia (6.1)0.92%—Mediaburst Gravity Forms13/8/201917/6/2026
The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS.
ModificadaCrítica (9.8)1.5%—Bitdefender Gravityzone30/10/201817/6/2026
Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via unspecified vectors.
ModificadaCrítica (9.8)4.3%—Bitdefender Gravityzone24/10/201817/6/2026
The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitrary code by changing the filename while leaving the file's digital signature unchanged.
Orbitaley — Vulnerabilidades