Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.34% | — | Nafisulbari Life Insurance Management System | 27/8/2024 | 17/6/2026 | A vulnerability was found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file addClient.php. The manipulation of the argument CLIENT ID leads to cross site scripting. The attack may be launched remotely. The exploit… | |
| Analizada | Media (5.3) | 0.32% | — | Nafisulbari Life Insurance Management System | 27/8/2024 | 17/6/2026 | A vulnerability has been found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file editClient.php. The manipulation of the argument AGENT ID leads to cross site scripting. The attack can be launched remotely.… | |
| Analizada | Media (5.3) | 0.44% | — | Nafisulbari Life Insurance Management System | 18/8/2024 | 17/6/2026 | A vulnerability classified as problematic was found in nafisulbari/itsourcecode Insurance Management System 1.0. Affected by this vulnerability is an unknown functionality of the file addNominee.php of the component Add Nominee Page. The manipulation of the argument Nominee-Client ID leads to cross site scripting. The… | |
| Analizada | Media (5.4) | 0.25% | — | SAP Student Life Cycle Management | 13/8/2024 | 17/6/2026 | SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to delete non-sensitive report variants that are typically restricted, causing minimal impact on the… | |
| Aplazada | Media (5.3) | 0.56% | — | Prestalife Product DesignerAI | 9/7/2024 | 17/6/2026 | The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to delete arbitrary attachments.… | |
| Modificada | Alta (7.5) | 0.41% | — | Awplife Event Monster | 21/6/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Event Management Tickets Booking.This issue affects Event Management Tickets Booking: from n/a through 1.4.0. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Datalife EngineAI | 20/6/2024 | 17/6/2026 | An issue in DataLife Engine v.17.1 and before is vulnerable to SQL Injection in dboption. | |
| Modificada | Crítica (9.8) | 0.66% | — | Webinane Lifeline Donation | 20/6/2024 | 17/6/2026 | The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.6. This is due to insufficient verification on the user being supplied during the checkout through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on… | |
| Modificada | Media (5.4) | 0.39% | — | Kraftplugins Wheel OF Life | 20/6/2024 | 17/6/2026 | The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the AjaxFunctions.php file in all versions up to, and including, 1.1.7. This makes it possible for authenticated… | |
| Modificada | Media (6.1) | 0.30% | — | Aegon Life Insurance Management System | 14/6/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at insertClient.php. | |
| Aplazada | Alta (8.1) | 0.58% | — | Aegon LifeAI | 14/6/2024 | 17/6/2026 | An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file. | |
| Modificada | Alta (8.8) | 2.3% | — | Projectworlds Life Insurance Management System | 14/6/2024 | 17/6/2026 | Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php. | |
| Modificada | Media (5.4) | 0.22% | — | SAP Student Life Cycle Management | 11/6/2024 | 17/6/2026 | SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to access and edit non-sensitive report variants that are typically restricted, causing minimal impact… | |
| Modificada | Alta (8.8) | 0.36% | — | Awplife Slider Responsive Slideshow | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow.This issue affects Slider Responsive Slideshow – Image slider, Gallery slideshow: from n/a through 1.4.0. | |
| Modificada | Alta (8.8) | 0.36% | — | Awplife Image Gallery | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery.This issue affects Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery: from n/a through 1.4.5. | |
| Modificada | Alta (8.8) | 0.36% | — | Awplife Album Gallery | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in A WP Life Album Gallery – WordPress Gallery.This issue affects Album Gallery – WordPress Gallery: from n/a through 1.5.7. | |
| Modificada | Alta (8.8) | 0.36% | — | Awplife Media Slider | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in A WP Life Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow.This issue affects Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow: from n/a through 1.3.9. | |
| Analizada | Crítica (9.8) | 0.65% | — | IBM Engineering Lifecycle Optimization Publishing | 9/6/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted request, a remote attacker could exploit this vulnerability to upload a malicious file, which could allow the… | |
| Modificada | Media (6.1) | 0.39% | — | Awplife Formula | 8/6/2024 | 17/6/2026 | The Formula theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in the 'ti_customizer_notify_dismiss_recommended_plugins' AJAX action in all versions up to, and including, 0.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Modificada | Media (6.1) | 0.39% | — | Awplife Formula | 8/6/2024 | 17/6/2026 | The Formula theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in the 'quality_customizer_notify_dismiss_action' AJAX action in all versions up to, and including, 0.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.34% | — | Awplife Contact Form WidgetAI | 3/6/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Contact Form Widget.This issue affects Contact Form Widget: from n/a through 1.3.9. | |
| Aplazada | Media (4.3) | 0.39% | — | WP Life Video Gallery API Gallery Youtube Vimeo Link GalleryAI | 6/5/2024 | 17/6/2026 | Missing Authorization vulnerability in A WP Life Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery.This issue affects Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery: from n/a through 1.5.3. | |
| Aplazada | Alta (7.5) | 0.87% | — | Awplife Grid GalleryAI | 2/5/2024 | 17/6/2026 | The Grid Gallery – Photo Image Grid Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization via shortcode of untrusted input from the awl_gg_settings_ meta value. This makes it possible for authenticated attackers, with contributor access and… | |
| Modificada | Alta (7.5) | 0.85% | — | Awplife Event Monster | 30/4/2024 | 17/6/2026 | The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.9 via deserialization via shortcode of untrusted input from a custom meta value. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.3) | 0.31% | — | Agasta Sanketlife 2.0 Pocket 12 Lead ECG MonitorAI | 22/4/2024 | 17/6/2026 | Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local attacker to cause a denial of service via the Bluetooth Low Energy (BLE) component. |