Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.39% | — | Wponlinesupport WP Responsive Header Image Slider | 3/10/2023 | 17/6/2026 | The WP Responsive header image slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sp_responsiveslider' shortcode in versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Modificada | Media (4.8) | 0.47% | — | Nikolov Serial Codes Generator AND Validator With Woocommerce Support | 19/9/2023 | 17/6/2026 | The Serial Codes Generator and Validator with WooCommerce Support WordPress plugin before 2.4.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in… | |
| Modificada | Crítica (9.8) | 1.8% | — | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 5/9/2023 | 17/6/2026 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote attacker to execute underlying operating… | |
| Modificada | Alta (8.1) | 2.4% | — | Zohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Assetexplorer+13 | 28/8/2023 | 17/6/2026 | Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and… | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Ticket Support Script | 28/8/2023 | 17/6/2026 | User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Media (5.4) | 1.1% | 💥 Exploit | Phpjabbers Ticket Support Script | 28/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2. | |
| Modificada | Crítica (9.6) | 0.57% | — | Intel Driver & Support Assistant | 11/8/2023 | 17/6/2026 | Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Media (4.4) | 0.18% | — | Intel Support | 11/8/2023 | 17/6/2026 | Incorrect default permissions in the Intel(R) Support android application before version v23.02.07 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Crítica (9.8) | 1.0% | — | Phpjabbers Ticket Support Script | 10/8/2023 | 17/6/2026 | A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Modificada | Media (5.4) | 2.2% | — | Zohocorp Manageengine Supportcenter Plus | 28/7/2023 | 17/6/2026 | Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module. | |
| Modificada | Media (5.4) | 3.5% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 7/7/2023 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications. | |
| Modificada | Alta (7.2) | 0.85% | — | Supportcandy | 19/6/2023 | 17/6/2026 | The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_add_agent_leaves AJAX function before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | |
| Modificada | Alta (8.8) | 1.2% | — | Supportcandy | 19/6/2023 | 17/6/2026 | The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber. | |
| Modificada | Media (5.5) | 0.16% | — | HPE Insight Remote Support | 16/6/2023 | 17/6/2026 | A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information. | |
| Modificada | Crítica (9.8) | 1.7% | — | Ninjateam Gpdr Ccpa Compliance Support | 7/6/2023 | 17/6/2026 | The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows unauthenticated attackers to inject a PHP Object. | |
| Modificada | Media (5.4) | 0.46% | — | Jenkins Loadcomplete Support | 16/5/2023 | 17/6/2026 | Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.4) | 2.4% | — | Jenkins Testcomplete Support | 16/5/2023 | 17/6/2026 | Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Crítica (9.8) | 41% | 💥 Exploit | Supportcandy | 2/5/2023 | 17/6/2026 | The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks | |
| Modificada | Media (4.9) | 3.0% | — | Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 26/4/2023 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint. | |
| Modificada | Media (5.4) | 0.47% | — | Weavertheme Weaver Xtreme Theme Support | 24/4/2023 | 17/6/2026 | The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.3) | 1.3% | 💥 PoC | Oracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core PolicyOracle Mysql ConnectorsNetapp Active IQ Unified Manager+2 | 18/4/2023 | 17/6/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require… | |
| Modificada | Alta (8.8) | 0.26% | — | Piwebsolution CSS JS Manager, Async Javascript, Defer Render Blocking CSS Supports Woocommerce | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions. | |
| Modificada | Alta (7.5) | 34% | — | Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 6/3/2023 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS). | |
| Modificada | Media (6.5) | 6.3% | — | Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 6/3/2023 | 17/6/2026 | ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports. | |
| Modificada | Alta (7) | 0.13% | — | Intel Driver & Support Assistant | 16/2/2023 | 17/6/2026 | Description: Race condition in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to potentially enable escalation of privilege via local access. |