Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 3.4% | — | Textpattern | 7/8/2023 | 17/6/2026 | Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensitive information via the plugin Upload function. | |
| Modificada | Media (6.1) | 0.89% | 💥 Exploit | Johnniejodelljr Twittee Text Tweet | 31/7/2023 | 17/6/2026 | The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen. | |
| Modificada | Media (4.3) | 0.61% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+6 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (6.5) | 0.69% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+7 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,… | |
| Modificada | Media (5.4) | 0.53% | — | Lanacodes Lana Text TO Image | 24/6/2023 | 17/6/2026 | The Lana Text to Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lana_text_to_image' and 'lana_text_to_img' shortcode in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (4.8) | 0.37% | — | Advanced Text Widget Project Advanced Text Widget | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Chirkov Advanced Text Widget plugin <= 2.1.2 versions. | |
| Modificada | Alta (7.1) | 0.30% | — | Opentext Archive Center Administration | 24/5/2023 | 17/6/2026 | The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft… | |
| Modificada | Alta (7.8) | 0.28% | — | Opentext Documentum Content Server | 18/5/2023 | 17/6/2026 | OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to root. The software comes prepackaged with a root owned SUID binary dm_secure_writer. The binary has security controls in place preventing creation of a file in a non-owned directory,… | |
| Modificada | Crítica (9.8) | 0.65% | — | Opentext Bizmanager | 1/5/2023 | 17/6/2026 | OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account. | |
| Modificada | Alta (8.8) | 1.1% | — | Textpattern | 28/4/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file. | |
| Modificada | Alta (8.8) | 0.89% | — | Random Text Project Random Text | 24/4/2023 | 17/6/2026 | The Random Text WordPress plugin through 0.3.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers. | |
| Modificada | Crítica (9.8) | 0.82% | — | Litextension Leurlrewrite | 17/4/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges via the Dispatcher::getController component. | |
| Modificada | Alta (7.2) | 2.0% | 💥 PoC | Textpattern | 12/4/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a crafted PHP file. | |
| Modificada | Alta (7.8) | 0.38% | — | Marktext | 24/2/2023 | 17/6/2026 | A vulnerability has been found in MarkText up to 0.17.1 on Windows and classified as critical. Affected by this vulnerability is an unknown functionality of the component WSH JScript Handler. The manipulation leads to code injection. Local access is required to approach this attack. The exploit has been disclosed to… | |
| Modificada | Media (6.1) | 0.50% | — | Textangular | 21/2/2023 | 17/6/2026 | textAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. There are no known patches. | |
| Modificada | Media (5.4) | 0.54% | — | Webberzone Contextual Related Posts | 6/2/2023 | 17/6/2026 | The Contextual Related Posts WordPress plugin before 3.3.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.62% | — | Responsivevoice Text TO Speech | 6/2/2023 | 17/6/2026 | The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.5) | 0.33% | — | Imageseo Optimize Images ALT Text (alt Tag) & Names FOR SEO Using AI | 23/1/2023 | 17/6/2026 | The Optimize images ALT Text & names for SEO using AI WordPress plugin before 2.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack. | |
| Modificada | Alta (8.8) | 1.9% | — | Opentext Extended ECM | 18/1/2023 | 17/6/2026 | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used to bypass the authentication of the QDS endpoints of the Content Server. These endpoints can be used to create objects and execute arbitrary code. | |
| Modificada | Alta (8.8) | 1.9% | — | Opentext Extended ECM | 18/1/2023 | 17/6/2026 | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common Gateway Interface (CGI) program cs.exe allows an attacker to increase/decrease an arbitrary memory address by 1 and trigger a call to a method of a vftable with a vftable pointer value chosen by the attacker. | |
| Modificada | Alta (8.8) | 1.7% | — | Opentext Extended ECM | 18/1/2023 | 17/6/2026 | A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pipeline of a request. Because the Content Server evaluates and executes Oscript code in HTML files,… | |
| Modificada | Alta (8.8) | 17% | — | Opentext Extended ECM | 18/1/2023 | 17/6/2026 | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a low-privilege user to evaluate webreports. | |
| Modificada | Alta (7.5) | 17% | — | Opentext Extended ECM | 18/1/2023 | 17/6/2026 | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an… | |
| Modificada | Alta (8.1) | 1.4% | — | Opentext Extended ECM | 18/1/2023 | 17/6/2026 | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint itemtemplate.createtemplate2 allows a low-privilege user to delete arbitrary files on the server's local filesystem. | |
| Modificada | Alta (8.8) | 1.6% | — | Opentext Extended ECM | 18/1/2023 | 17/6/2026 | An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd cookie even when the Web Admin password was not entered. This allows access to endpoints, which require a valid AdminPwd cookie, without knowing the password. |