Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.7) | 0.68% | — | Codection Import Users From CSV With Meta | 8/8/2019 | 17/6/2026 | The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF. | |
| Modificada | Media (6.5) | 0.97% | — | Kubevirt Containerized-data-importer | 28/6/2019 | 17/6/2026 | A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine whether the requesting user has permission to access the Persistent Volume Claim (PVC) in the source namespace. This could allow users to clone any PVC in the cluster into… | |
| Modificada | Media (6.1) | 0.89% | — | Soflyy WP ALL Import | 12/4/2019 | 17/6/2026 | There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in… | |
| Modificada | Media (6.1) | 0.89% | — | Soflyy WP ALL Import | 12/4/2019 | 17/6/2026 | There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator | |
| Modificada | Media (6.1) | 0.86% | — | Soflyy WP ALL Import | 12/4/2019 | 17/6/2026 | There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator | |
| Modificada | Media (6.1) | 0.94% | — | Soflyy WP ALL Import | 12/4/2019 | 17/6/2026 | There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via Add Filtering Options(Add Rule). NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in… | |
| Modificada | Media (6.1) | 0.89% | — | Soflyy WP ALL Import | 12/4/2019 | 17/6/2026 | There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=evaluate. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator | |
| Modificada | Media (6.1) | 0.91% | — | Soflyy WP ALL Import | 12/4/2019 | 17/6/2026 | There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator | |
| Modificada | Media (6.8) | 0.53% | — | Kubevirt Containerized Data Importer | 25/3/2019 | 17/6/2026 | Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when importing data into PVCs from container registries. This could enable man-in-the-middle attacks between a container registry and the virt-cdi-component, leading to possible undetected tampering of… | |
| Modificada | Media (5.3) | 0.52% | — | Jenkins JOB Import | 6/2/2019 | 17/6/2026 | A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allows attackers to copy jobs from a preconfigured other Jenkins instance, potentially installing additional plugins necessary to load the imported job's configuration. | |
| Modificada | Alta (8.8) | 1.0% | — | Jenkins JOB Import | 6/2/2019 | 17/6/2026 | An exposure of sensitive information vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/JobImportAction.java, src/main/java/org/jenkins/ci/plugins/jobimport/JobImportGlobalConfig.java, src/main/java/org/jenkins/ci/plugins/jobimport/model/JenkinsSite.java… | |
| Modificada | Crítica (9.1) | 1.8% | — | Jenkins JOB Import | 6/2/2019 | 17/6/2026 | An XML external entity processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/client/RestApiClient.java that allows attackers with the ability to control the HTTP server (Jenkins) queried in preparation of job import to read arbitrary files,… | |
| Modificada | Media (6.1) | 0.78% | — | Codection Import Users From CSV With Meta | 12/12/2018 | 17/6/2026 | The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell. | |
| Modificada | Alta (7.8) | 5.1% | 💥 Exploit | Webtoffee Wordpress Comments Import AND Export | 19/6/2018 | 17/6/2026 | The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection. | |
| Modificada | Alta (8.1) | 0.92% | — | Igniterealtime User Import Export | 15/5/2018 | 17/6/2026 | An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the retrieval of arbitrary files or denial of service. An authenticated attacker can send a crafted web request to trigger this vulnerability. | |
| Modificada | Media (6.1) | 1.5% | — | Soflyy WP ALL Import | 9/3/2018 | 17/6/2026 | Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 1.5% | — | Soflyy WP ALL Import | 9/3/2018 | 17/6/2026 | Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 0.84% | — | Csv-import-export Project Csv-import-export | 19/12/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the esb-csv-import-export plugin through 1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cie_type, (2) cie_import, (3) cie_update, or (4) cie_ignore parameter to includes/admin/views/esb-cie-import-export-page.php. | |
| Modificada | Media (6.8) | 0.64% | — | User Import Project User Import | 15/6/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the User Import module 6.x-4.x before 6.x-4.4 and 7.x-2.x before 7.x-2.3 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) continue or (2) delete an ongoing import via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | Open Graph Importer Project Open Graph Importer | 15/6/2015 | 17/6/2026 | The Open Graph Importer (og_tag_importer) 7.x-1.x for Drupal does not properly check the create permission for content types created during import, which allows remote authenticated users to bypass intended restrictions by leveraging the "import og_tag_importer" permission. | |
| Modificada | Media (5.4) | 0.27% | — | Myapp Prix Import | 20/10/2014 | 17/6/2026 | The PRIX IMPORT (aka com.myapphone.android.myapppriximport) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 1.3% | — | IBM Infosphere Import Export ManagerIBM Infosphere Information ServerIBM Infosphere Information Server Metabrokers & Bridges | 31/1/2013 | 16/6/2026 | Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joomplace COM Joomportfolio | 28/12/2009 | 16/6/2026 | SQL injection vulnerability in the JoomPortfolio (com_joomportfolio) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the secid parameter in a showcat action to index.php. | |
| Modificada | Alta (7.5) | 7.6% | — | RIM Teamon Import Object Activex Control | 8/5/2007 | 16/6/2026 | Buffer overflow in the SetLanguage function in Research In Motion (RIM) TeamOn Import Object ActiveX control (TOImport.dll) allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Camportail | 2/4/2007 | 16/6/2026 | SQL injection vulnerability in show.php in the Camportail 1.1 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the camid parameter in a showcam action. |