Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
815 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.34% | — | Expresstechsoftware Quiz AND Survey MasterAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 8.2.2. | |
| Modificada | Crítica (9.8) | 5.0% | 💥 Exploit | Stylemixthemes Masterstudy LMS | 9/4/2024 | 17/6/2026 | The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This… | |
| Modificada | Media (4.3) | 0.47% | — | Stylemixthemes Masterstudy LMS | 9/4/2024 | 17/6/2026 | The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the search_posts function in all versions up to, and including, 3.2.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose draft post titles and… | |
| Modificada | Crítica (9.8) | 1.5% | — | Stylemixthemes Masterstudy LMS | 29/3/2024 | 17/6/2026 | The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This… | |
| Modificada | Crítica (9.8) | 0.83% | — | Stylemixthemes Masterstudy LMS | 29/3/2024 | 17/6/2026 | The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the _register_user() function called by the 'wp_ajax_nopriv_stm_lms_register' AJAX action. This makes it possible for unauthenticated… | |
| Modificada | Media (5.4) | 0.34% | — | Master-addons Master Addons | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1. | |
| Modificada | Media (5.4) | 0.34% | — | Master-addons Master Addons | 27/3/2024 | 17/6/2026 | The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in all versions up to, and including, 2.0.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Crítica (9.3) | 2.0% | 💥 Exploit | Expresstechlabs Quiz AND Survey MasterAI | 26/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4. | |
| Analizada | Alta (7.5) | 13% | — | Progress Loadmaster | 22/3/2024 | 17/6/2026 | A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a scenario, the CSRF payload hosted on the… | |
| Analizada | Alta (8.8) | 55% | — | Progress Loadmaster | 22/3/2024 | 17/6/2026 | An OS command injection vulnerability has been identified in LoadMaster. An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection. | |
| Aplazada | Media (5.4) | 0.20% | — | Expresstechsoftware Quiz AND Survey MasterAI | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.18. | |
| Modificada | Alta (7.5) | 0.80% | — | Stylemixthemes Masterstudy LMS | 13/3/2024 | 17/6/2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 3.2.10. This can allow unauthenticated attackers to extract sensitive data including all registered user's username and email addresses which can be used… | |
| Modificada | Media (5.4) | 0.43% | — | Averta Master Slider | 2/3/2024 | 17/6/2026 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slide shortcode in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on the 'src' user supplied attributes. This makes it possible for… | |
| Modificada | Media (4.8) | 0.65% | — | Averta Master Slider | 2/3/2024 | 17/6/2026 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slides callback functionality in all versions up to, and including, 3.9.9. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts in pages that… | |
| Modificada | Media (4.3) | 0.26% | — | Averta Master Slider | 2/3/2024 | 17/6/2026 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.10. This is due to missing or incorrect nonce validation on the 'process_bulk_action' function. This makes it possible for unauthenticated attackers to duplicate or… | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 Exploit | Progress Loadmaster | 21/2/2024 | 13/7/2026 | Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. | |
| Modificada | Crítica (9.8) | 78% | 💥 Exploit | Stylemixthemes Masterstudy LMS | 17/2/2024 | 17/6/2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to insufficient escaping on the user supplied parameter and lack of… | |
| Modificada | Media (4.3) | 0.32% | — | SAP Master Data Governance FOR Material Data | 13/2/2024 | 17/6/2026 | SAP Master Data Governance for Material Data - versions 618, 619, 620, 621, 622, 800, 801, 802, 803, 804, does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to read some sensitive information but no impact to integrity and… | |
| Modificada | Media (4.4) | 0.11% | — | Gesslergmbh Web-master Firmware | 1/2/2024 | 17/6/2026 | Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can restore the passwords by breaking the hashes stored on the device. | |
| Modificada | Crítica (9.8) | 0.72% | — | Gesslergmbh Web-master Firmware | 1/2/2024 | 17/6/2026 | Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device. | |
| Modificada | Media (4.8) | 0.40% | — | Gravitymaster Product Enquiry FOR Woocommerce | 22/1/2024 | 17/6/2026 | The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.3) | 0.20% | — | Gravitymaster Product Enquiry FOR Woocommerce | 22/1/2024 | 17/6/2026 | The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack | |
| Modificada | Crítica (9.8) | 0.67% | — | Joommasters Jmssetting | 19/1/2024 | 17/6/2026 | In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0. The method `JmsSetting::getSecondImgs()` has a sensitive SQL call that can be executed with a trivial http call and exploited to forge a blind SQL injection. | |
| Analizada | Media (6.1) | 0.46% | — | Gravitymaster Product Enquiry FOR Woocommerce | 16/1/2024 | 17/6/2026 | The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Crítica (9.8) | 0.61% | — | Masterlab | 29/12/2023 | 17/6/2026 | A vulnerability was found in gopeak MasterLab up to 3.3.10. It has been declared as critical. Affected by this vulnerability is the function add/update of the file app/ctrl/admin/User.php. The manipulation of the argument avatar leads to unrestricted upload. The attack can be launched remotely. The exploit has been… |