Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
634 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.80% | — | Metagauss Profilegrid | 18/7/2023 | 17/6/2026 | The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to… | |
| Modificada | Media (4.3) | 0.57% | — | Metagauss Profilegrid | 18/7/2023 | 17/6/2026 | The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to import new users and… | |
| Modificada | Media (4.3) | 0.39% | — | It-rays Rays Grid | 12/7/2023 | 17/6/2026 | The RAYS Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the rsgd_insert_update() function. This makes it possible for unauthenticated attackers to update post fields via a forged request granted they… | |
| Modificada | Media (6.1) | 0.41% | — | Selenium Grid | 5/7/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Selenium Grid v3.141.59 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hub parameter under the /grid/console page. | |
| Modificada | Alta (8.8) | 0.26% | — | Radiustheme THE Post Grid | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 5.0.4 versions. | |
| Modificada | Alta (8.8) | 0.82% | — | Metagauss Profilegrid | 20/3/2023 | 17/6/2026 | The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones. | |
| Modificada | Media (4.3) | 0.57% | — | Boldgrid Total Upkeep | 7/3/2023 | 17/6/2026 | The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions… | |
| Modificada | Alta (7.5) | 0.62% | — | Netapp Storagegrid | 2/3/2023 | 17/6/2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to to a crash of the Local Distribution Router (LDR) service. | |
| Modificada | Media (5.4) | 0.48% | — | Responsive Gallery Grid Project Responsive Gallery Grid | 13/2/2023 | 17/6/2026 | The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.69% | — | Essentialplugin Download Post Category Image With Grid AND Slider | 6/2/2023 | 17/6/2026 | The Post Category Image With Grid and Slider WordPress plugin before 1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high… | |
| Modificada | Crítica (9.8) | 0.69% | — | Yii2-jqgrid-widget Project Yii2-jqgrid-widget | 6/1/2023 | 17/6/2026 | A vulnerability was found in himiklab yii2-jqgrid-widget up to 1.0.7. It has been declared as critical. This vulnerability affects the function addSearchOptionsRecursively of the file JqGridAction.php. The manipulation leads to sql injection. Upgrading to version 1.0.8 is able to address this issue. The name of the… | |
| Modificada | Crítica (9.8) | 0.68% | — | Laravel Jqgrid Project Laravel Jqgrid | 19/12/2022 | 17/6/2026 | A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql injection. The name of the patch is fbc2d94f43d0dc772767a5bdb2681133036f935e. It… | |
| Modificada | Alta (8.8) | 0.70% | — | Metagauss Profilegrid | 17/11/2022 | 17/6/2026 | Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress. | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Metagauss Profilegrid | 14/11/2022 | 17/6/2026 | The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (7.8) | 0.47% | — | Gridea | 30/9/2022 | 17/6/2026 | Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled. | |
| Modificada | Media (6.1) | 0.65% | — | NHN Toast UI Grid | 22/9/2022 | 17/6/2026 | Toast UI Grid is a component to display and edit data. Versions prior to 4.21.3 are vulnerable to cross-site scripting attacks when pasting specially crafted content into editable cells. This issue was fixed in version 4.21.3. There are no known workarounds. | |
| Modificada | Media (5.4) | 0.52% | — | Visualportfolio Visual Portfolio, Photo Gallery & Post Grid | 5/9/2022 | 17/6/2026 | The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks in some of its REST endpoints, allowing users with a role as low as contributor to call them and inject arbitrary CSS in arbitrary saved layouts | |
| Modificada | Media (6.1) | 0.60% | — | Visualportfolio Visual Portfolio, Photo Gallery & Post Grid | 5/9/2022 | 17/6/2026 | The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layouts | |
| Modificada | Alta (8.8) | 5.1% | — | GNU GzipRedhat Jboss Data GridDebian LinuxTukaani XZ | 31/8/2022 | 17/6/2026 | An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing… | |
| Modificada | Media (6.5) | 0.73% | — | Netapp Storagegrid | 10/8/2022 | 17/6/2026 | Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to view limited metrics information and modify alert email recipients and content. | |
| Modificada | Crítica (9.8) | 19% | 💥 PoC | ZlibFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+14 | 5/8/2022 | 14/7/2026 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the… | |
| Modificada | Crítica (9.8) | 1.1% | — | Elliegrid | 30/7/2022 | 17/6/2026 | EllieGrid Android Application version 3.4.1 is vulnerable to Code Injection. The application appears to evaluate user input as code (remote). | |
| Modificada | Media (5.4) | 0.48% | — | Grid Elements Project Grid Elements | 12/7/2022 | 17/6/2026 | The gridelements (aka Grid Elements) extension through 7.6.1, 8.x through 8.7.0, 9.x through 9.7.0, and 10.x through 10.2.0 extension for TYPO3 allows XSS. | |
| Modificada | Media (5.3) | 0.44% | — | Siemens Sicam Gridedge Essential ARMSiemens Sicam Gridedge Essential GDS ARMSiemens Sicam Gridedge Essential GDS IntelSiemens Sicam Gridedge Essential Intel | 12/7/2022 | 17/6/2026 | A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses an improperly protected file to import SSH keys. This could allow attackers with access to the filesystem of the host on which SICAM GridEdge runs to inject a custom SSH key to that file. | |
| Modificada | Media (4.8) | 0.59% | — | Wpwax Post Grid, Slider & Carousel Ultimate | 20/6/2022 | 17/6/2026 | The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. |