Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
737 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.82% | — | Cisco Unified Contact Center ExpressCisco Unified Intelligence Center | 8/4/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly… | |
| Modificada | Alta (8.8) | 0.80% | — | Expresstech Responsive Menu | 5/4/2021 | 17/6/2026 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the… | |
| Modificada | Alta (8.8) | 1.2% | — | Expresstech Responsive Menu | 5/4/2021 | 17/6/2026 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site. | |
| Modificada | Alta (8.8) | 8.2% | 💥 PoC | Expresstech Responsive Menu | 5/4/2021 | 17/6/2026 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an… | |
| Modificada | Crítica (9.8) | 75% | 💥 Exploit | Mongo-express Project Mongo-express | 30/3/2021 | 17/6/2026 | mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769. | |
| Modificada | Alta (8.8) | 2.8% | — | Expressionengine | 15/3/2021 | 17/6/2026 | ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under the system/user/language directory. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Expressvpn | 10/3/2021 | 9/7/2026 | An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request. | |
| Modificada | Media (6.7) | 0.50% | — | Ucopia Express Wireless Appliance | 2/2/2021 | 17/6/2026 | UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with root privileges using chroothole_client's PHP call, a related issue to CVE-2017-11322. | |
| Modificada | Alta (8.8) | 2.7% | — | Peerigon Angular-expressions | 1/2/2021 | 17/6/2026 | angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2 there is a vulnerability which allows Remote Code Execution if you call "expressions.compile(userControlledInput)" where "userControlledInput" is text that comes from… | |
| Modificada | Media (6.5) | 2.2% | — | CkeditorOracle Agile Product Lifecycle ManagementOracle Application ExpressOracle Banking Party Management+6 | 26/1/2021 | 25/8/2026 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin). | |
| Modificada | Media (6.5) | 2.0% | — | CkeditorOracle Agile Product Lifecycle ManagementOracle Application ExpressOracle Financial Services Analytical Applications Infrastructure+3 | 26/1/2021 | 25/8/2026 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin). | |
| Modificada | Media (5.4) | 0.69% | — | Oracle Application Express Survey Builder | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Application Express Survey Builder component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application… | |
| Modificada | Media (5.4) | 0.69% | — | Oracle Application Express Opportunity Tracker | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Application Express Opportunity Tracker component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle… | |
| Modificada | Crítica (9.9) | 76% | 💥 Exploit | Expresstech Quiz AND Survey Master | 1/1/2021 | 17/6/2026 | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via… | |
| Modificada | Crítica (9.8) | 5.1% | — | Expresstech Quiz AND Survey Master | 1/1/2021 | 17/6/2026 | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload,… | |
| Modificada | Media (4.8) | 0.69% | — | Nchsoftware Express Invoice | 28/12/2020 | 17/6/2026 | NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module. | |
| Modificada | Media (6.5) | 0.76% | — | Nchsoftware Express Accounts | 28/12/2020 | 17/6/2026 | In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users. | |
| Modificada | Media (5.5) | 0.29% | — | Nchsoftware Express Accounts | 28/12/2020 | 17/6/2026 | NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file. | |
| Modificada | Media (6.5) | 0.75% | — | Tibco Partnerexpress | 15/12/2020 | 17/6/2026 | The REST API component of TIBCO Software Inc.'s TIBCO PartnerExpress contains a vulnerability that theoretically allows an unauthenticated attacker with network access to obtain an authenticated login URL for the affected system via a REST API. Affected releases are TIBCO Software Inc.'s TIBCO PartnerExpress: version… | |
| Modificada | Crítica (9.8) | 2.2% | — | Express-gateway Docker Image | 8/12/2020 | 17/6/2026 | The official Express Gateway Docker images before 1.14.0 contain a blank password for a root user. Systems using the Express Gateway Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access. | |
| Modificada | Media (6.5) | 1.4% | — | Cisco ExpresswayCisco Telepresence Video Communication Server | 18/11/2020 | 17/6/2026 | A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations. The vulnerability is due to improper validation of specific connection… | |
| Modificada | Media (4.6) | 0.31% | — | Resourcexpress Qubi3 Firmware | 17/11/2020 | 17/6/2026 | QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obtain sensitive information via the debug interface (keystrokes over a USB cable), aka wireless password visibility. | |
| Modificada | Media (6.1) | 2.0% | — | CkeditorOracle Agile Product Lifecycle ManagementOracle Application ExpressOracle Banking Party Management+5 | 12/11/2020 | 25/8/2026 | A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs. | |
| Modificada | Crítica (9.8) | 2.2% | — | Resourcexpress Meeting Monitor | 12/11/2020 | 17/6/2026 | SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and information disclosure. | |
| Modificada | Media (5.3) | 1.6% | — | Express-validators Project Express-validators | 11/11/2020 | 17/6/2026 | All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validating specifically-crafted invalid urls. |