Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
822 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.54% | 💥 PoC | Spacex Starlink Wifi Router GEN 2AISpacex Starlink DishAI | 5/4/2024 | 17/6/2026 | SpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow CSRF (e.g., for a reboot) via a DNS Rebinding attack. | |
| Aplazada | Alta (7.1) | 0.35% | — | Joel Starnes PagemashAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joel Starnes pageMash > Page Management allows Reflected XSS.This issue affects pageMash > Page Management: from n/a through 1.3.0. | |
| Aplazada | Alta (7.1) | 0.32% | — | Brainstormforce Starter Templates Elementor Wordpress Beaver Builder TemplatesAIBrainstormforce Premium Starter TemplatesAI | 28/3/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates, Brainstorm Force Premium Starter Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4; Premium Starter Templates:… | |
| Aplazada | Media (6.5) | 0.32% | — | Fivestarplugins Five Star Restaurant MenuAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Menu allows Stored XSS.This issue affects Five Star Restaurant Menu: from n/a through 2.4.14. | |
| Aplazada | Media (6.5) | 0.21% | — | Movistar 4G RouterAIMovistar ES Wld71-t1AI | 13/3/2024 | 17/6/2026 | Cross-Site Request Forgery vulnerability in Movistar's 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an attacker to force an end user to execute unwanted actions in a web application in which they are currently authenticated. | |
| Aplazada | Alta (7.8) | 0.74% | — | Movistar 4G RouterAI | 13/3/2024 | 17/6/2026 | Command injection vulnerability in Movistar 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an authenticated user to execute commands inside the router by making a POST request to the URL '/cgi-bin/gui.cgi'. | |
| Aplazada | Alta (8.8) | 0.28% | — | Movistar 4G Router E S Wld71-t1 V2.0.201820AI | 13/3/2024 | 17/6/2026 | The primary channel is unprotected on Movistar 4G router affecting E version S_WLD71-T1_v2.0.201820. This device has the 'adb' service open on port 5555 and provides access to a shell with root privileges. | |
| Analizada | Media (6.1) | 0.44% | — | Squirrly Starbox | 11/3/2024 | 17/6/2026 | The Starbox WordPress plugin before 3.5.0 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks | |
| Analizada | Alta (8.1) | 1.0% | — | Fullstackhero .net 9 Starter KIT | 29/2/2024 | 17/6/2026 | A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request. | |
| Modificada | Media (5.4) | 0.42% | — | Squirrly Starbox | 29/2/2024 | 17/6/2026 | The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (5.3) | 0.39% | — | Zestard Admin Side Data Storage FOR Contact Form 7 | 23/2/2024 | 17/6/2026 | The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_status() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to alter the message read… | |
| Modificada | Media (5.3) | 0.37% | — | Zestard Admin Side Data Storage FOR Contact Form 7 | 23/2/2024 | 17/6/2026 | The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the zt_dcfcf_change_bookmark() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to alter bookmark… | |
| Modificada | Media (4.3) | 0.20% | — | Zestard Admin Side Data Storage FOR Contact Form 7 | 23/2/2024 | 17/6/2026 | The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the settings update function. This makes it possible for unauthenticated attackers to update the plugin's… | |
| Modificada | Alta (7.2) | 0.56% | — | Zestard Admin Side Data Storage FOR Contact Form 7 | 23/2/2024 | 17/6/2026 | The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' parameter in all versions up to, and including, 1.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Media (5.4) | 0.35% | — | Startbooking Scheduling Plugin | 10/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Start Booking Scheduling Plugin – Online Booking for WordPress allows Stored XSS.This issue affects Scheduling Plugin – Online Booking for WordPress: from n/a through 3.5.10. | |
| Modificada | Media (5.4) | 0.32% | — | Squirrly Starbox | 7/2/2024 | 17/6/2026 | The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Modificada | Media (4.3) | 0.57% | — | Squirrly Starbox | 5/2/2024 | 17/6/2026 | The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.7 via the action function due to missing validation on a user controlled key. This makes it possible for subscribers to view plugin preferences and potentially other… | |
| Modificada | Media (5.4) | 0.31% | — | Fivestarplugins Five Star Restaurant Menu | 5/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue affects Five Star Restaurant Reviews: from n/a through 2.3.5. | |
| Modificada | Media (6.5) | 0.51% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a victim's Qstar instance by executing a specific command in a link. | |
| Modificada | Alta (7.5) | 0.55% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server. | |
| Modificada | Media (5.4) | 0.35% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link. | |
| Modificada | Media (6.1) | 0.41% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link. | |
| Modificada | Alta (8.8) | 1.5% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands. | |
| Modificada | Alta (7.5) | 0.65% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server. | |
| Modificada | Media (6.1) | 0.38% | — | Qstar Archive Storage Manager | 13/1/2024 | 17/6/2026 | QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table. |