Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3077▲ 447 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
612 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.25% | — | Makestories (for Google WEB Stories) | 6/10/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Request Forgery (CSRF) en el complemento MakeStories Team MakeStories (para Google Web Stories) en versiones <= 2.8.0. | |
| Modificada | Alta (8.8) | 0.25% | — | Yasglobal Make Paths Relative | 4/10/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Request Forgery (CSRF) en el complemento YAS Global Team Make Paths Relative en versiones <= 1.3.0. | |
| Modificada | Media (4.8) | 0.37% | — | Carrcommunications Rsvpmaker | 27/9/2023 | 17/6/2026 | Vulnerabilidad de Coss-Site Scripting (XSS) autenticada (con permisos de admin o superiores) almacenada en el complemento David F. Carr RSVPMaker en versiones <= 10.6.6. | |
| Modificada | Media (6.1) | 0.39% | — | Carrcommunications Rsvpmaker | 27/9/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) Almacenada No Autenticada en el complemento David F. Carr RSVPMaker en versiones <= 10.6.6. | |
| Modificada | Media (6.1) | 0.39% | — | Ays-pro Poll Maker | 25/9/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada No Autenticada en el complemento Poll Maker Team Poll Maker en versiones <= 4.7.0. | |
| Modificada | Alta (8.1) | 0.77% | — | Minitool Movie Maker | 19/9/2023 | 17/6/2026 | MiniTool Movie Maker 7.0 contiene un proceso de instalación inseguro que permite a los atacantes lograr la ejecución remota de código a través de un ataque de intermediario. | |
| Modificada | Alta (8.1) | 0.77% | — | Minitool Shadowmaker | 19/9/2023 | 17/6/2026 | MiniTool Shadow Maker en la versión 4.1 contiene un proceso de instalación inseguro que permite a los atacantes lograr la ejecución remota de código a través de un ataque de man-in-the-middle. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Make AN Offer Widget | 28/8/2023 | 17/6/2026 | User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Phpjabbers Make AN Offer Widget | 28/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0. | |
| Modificada | Alta (8.8) | 0.86% | — | Netmaker | 24/8/2023 | 17/6/2026 | Netmaker makes networks with WireGuard. A Mass assignment vulnerability was found in versions prior to 0.17.1 and 0.18.6 that allows a non-admin user to escalate privileges to those of an admin user. The issue is patched in 0.17.1 and fixed in 0.18.6. If Users are using 0.17.1, they should run `docker pull… | |
| Modificada | Alta (7.5) | 0.70% | — | Netmaker | 24/8/2023 | 17/6/2026 | Netmaker makes networks with WireGuard. An Insecure Direct Object Reference (IDOR) vulnerability was found in versions prior to 0.17.1 and 0.18.6 in the user update function. By specifying another user's username, it was possible to update the other user's password. The issue is patched in 0.17.1 and fixed in 0.18.6.… | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Netmaker | 24/8/2023 | 17/6/2026 | Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users to interact with DNS API endpoints. The issue is patched in 0.17.1 and fixed in 0.18.6. If users are using 0.17.1, they should run `docker pull gravitl/netmaker:v0.17.1`… | |
| Modificada | Media (6.1) | 0.38% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 17/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.6 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Wepupil Quiz Expert - Easy Quiz Maker, Exam AND Test Manager | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WePupil Quiz Expert plugin <= 1.5.0 versions. | |
| Modificada | Alta (7.2) | 0.90% | — | Carrcommunications Rsvpmaker | 10/7/2023 | 17/6/2026 | Auth. (admin+) SQL Injection (SQLi) vulnerability in David F. Carr RSVPMaker plugin < 10.5.5 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Ays-pro Survey Maker | 5/6/2023 | 17/6/2026 | The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 2.1% | — | Ays-pro Quiz Maker | 5/6/2023 | 17/6/2026 | The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (7.8) | 0.22% | — | Softmaker Flexipdf | 23/3/2023 | 17/6/2026 | A stack overfow in SoftMaker Software GmbH FlexiPDF v3.0.3.0 allows attackers to execute arbitrary code after opening a crafted PDF file. | |
| Modificada | Media (5.4) | 0.47% | — | Galleries BY Angie Makes Project Galleries BY Angie Makes | 27/2/2023 | 17/6/2026 | The Galleries by Angie Makes WordPress plugin through 1.67 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (7.8) | 0.30% | — | Adobe Framemaker | 17/2/2023 | 17/6/2026 | FrameMaker 2020 Update 4 (y anteriores) y 2022 (y anteriores), están afectadas por una vulnerabilidad de escritura fuera de límites que podría resultar en una ejecución de código arbitrario en el contexto del usuario actual. Una explotación de este problema requiere la interacción del usuario, ya que la víctima debe… | |
| Modificada | Alta (7.8) | 0.33% | — | Adobe Framemaker | 17/2/2023 | 17/6/2026 | FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (5.5) | 0.33% | — | Adobe Framemaker | 17/2/2023 | 17/6/2026 | FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must… | |
| Modificada | Alta (7.8) | 0.30% | — | Adobe Framemaker | 17/2/2023 | 17/6/2026 | FrameMaker 2020 Update 4 (y anteriores) y 2022 (y anteriores), están afectadas por una vulnerabilidad de escritura fuera de límites que podría resultar en una ejecución de código arbitrario en el contexto del usuario actual. Una explotación de este problema requiere la interacción del usuario, ya que la víctima debe… | |
| Modificada | Media (5.5) | 0.36% | — | Adobe Framemaker | 17/2/2023 | 17/6/2026 | FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open… |