Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3077▲ 447 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

612 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.25%—Makestories (for Google WEB Stories)6/10/202317/6/2026
Vulnerabilidad de Cross-Site Request Forgery (CSRF) en el complemento MakeStories Team MakeStories (para Google Web Stories) en versiones <= 2.8.0.
ModificadaAlta (8.8)0.25%—Yasglobal Make Paths Relative4/10/202317/6/2026
Vulnerabilidad de Cross-Site Request Forgery (CSRF) en el complemento YAS Global Team Make Paths Relative en versiones <= 1.3.0.
ModificadaMedia (4.8)0.37%—Carrcommunications Rsvpmaker27/9/202317/6/2026
Vulnerabilidad de Coss-Site Scripting (XSS) autenticada (con permisos de admin o superiores) almacenada en el complemento David F. Carr RSVPMaker en versiones <= 10.6.6.
ModificadaMedia (6.1)0.39%—Carrcommunications Rsvpmaker27/9/202317/6/2026
Vulnerabilidad de Cross-Site Scripting (XSS) Almacenada No Autenticada en el complemento David F. Carr RSVPMaker en versiones <= 10.6.6.
ModificadaMedia (6.1)0.39%—Ays-pro Poll Maker25/9/202317/6/2026
Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada No Autenticada en el complemento Poll Maker Team Poll Maker en versiones <= 4.7.0.
ModificadaAlta (8.1)0.77%—Minitool Movie Maker19/9/202317/6/2026
MiniTool Movie Maker 7.0 contiene un proceso de instalación inseguro que permite a los atacantes lograr la ejecución remota de código a través de un ataque de intermediario.
ModificadaAlta (8.1)0.77%—Minitool Shadowmaker19/9/202317/6/2026
MiniTool Shadow Maker en la versión 4.1 contiene un proceso de instalación inseguro que permite a los atacantes lograr la ejecución remota de código a través de un ataque de man-in-the-middle.
ModificadaCrítica (9.8)0.89%—Phpjabbers Make AN Offer Widget28/8/202317/6/2026
User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaMedia (6.1)1.0%💥 ExploitPhpjabbers Make AN Offer Widget28/8/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.
ModificadaAlta (8.8)0.86%—Netmaker24/8/202317/6/2026
Netmaker makes networks with WireGuard. A Mass assignment vulnerability was found in versions prior to 0.17.1 and 0.18.6 that allows a non-admin user to escalate privileges to those of an admin user. The issue is patched in 0.17.1 and fixed in 0.18.6. If Users are using 0.17.1, they should run `docker pull…
ModificadaAlta (7.5)0.70%—Netmaker24/8/202317/6/2026
Netmaker makes networks with WireGuard. An Insecure Direct Object Reference (IDOR) vulnerability was found in versions prior to 0.17.1 and 0.18.6 in the user update function. By specifying another user's username, it was possible to update the other user's password. The issue is patched in 0.17.1 and fixed in 0.18.6.…
ModificadaAlta (7.5)3.5%💥 ExploitNetmaker24/8/202317/6/2026
Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users to interact with DNS API endpoints. The issue is patched in 0.17.1 and fixed in 0.18.6. If users are using 0.17.1, they should run `docker pull gravitl/netmaker:v0.17.1`…
ModificadaMedia (6.1)0.38%—Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes17/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.6 versions.
ModificadaAlta (8.8)0.26%—Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions.
ModificadaAlta (8.8)0.26%—Wepupil Quiz Expert - Easy Quiz Maker, Exam AND Test Manager11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WePupil Quiz Expert plugin <= 1.5.0 versions.
ModificadaAlta (7.2)0.90%—Carrcommunications Rsvpmaker10/7/202317/6/2026
Auth. (admin+) SQL Injection (SQLi) vulnerability in David F. Carr RSVPMaker plugin < 10.5.5 versions.
ModificadaMedia (6.1)0.46%—Ays-pro Survey Maker5/6/202317/6/2026
The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)2.1%—Ays-pro Quiz Maker5/6/202317/6/2026
The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (7.8)0.22%—Softmaker Flexipdf23/3/202317/6/2026
A stack overfow in SoftMaker Software GmbH FlexiPDF v3.0.3.0 allows attackers to execute arbitrary code after opening a crafted PDF file.
ModificadaMedia (5.4)0.47%—Galleries BY Angie Makes Project Galleries BY Angie Makes27/2/202317/6/2026
The Galleries by Angie Makes WordPress plugin through 1.67 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (7.8)0.30%—Adobe Framemaker17/2/202317/6/2026
FrameMaker 2020 Update 4 (y anteriores) y 2022 (y anteriores), están afectadas por una vulnerabilidad de escritura fuera de límites que podría resultar en una ejecución de código arbitrario en el contexto del usuario actual. Una explotación de este problema requiere la interacción del usuario, ya que la víctima debe…
ModificadaAlta (7.8)0.33%—Adobe Framemaker17/2/202317/6/2026
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
ModificadaMedia (5.5)0.33%—Adobe Framemaker17/2/202317/6/2026
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must…
ModificadaAlta (7.8)0.30%—Adobe Framemaker17/2/202317/6/2026
FrameMaker 2020 Update 4 (y anteriores) y 2022 (y anteriores), están afectadas por una vulnerabilidad de escritura fuera de límites que podría resultar en una ejecución de código arbitrario en el contexto del usuario actual. Una explotación de este problema requiere la interacción del usuario, ya que la víctima debe…
ModificadaMedia (5.5)0.36%—Adobe Framemaker17/2/202317/6/2026
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open…