Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

822 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.32%—Qstar Archive Storage Manager13/1/202417/6/2026
QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component qnme-ajax?method=tree_level.
ModificadaMedia (5.3)0.50%—Qstar Archive Storage Manager13/1/202417/6/2026
An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log contents via executing a crafted command.
ModificadaMedia (4.3)0.32%—Themeisle Lightstart11/1/202417/6/2026
The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with…
ModificadaMedia (6.1)0.32%—Videowhisper Rate Star Review8/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VideoWhisper Rate Star Review – AJAX Reviews for Content, with Star Ratings allows Reflected XSS.This issue affects Rate Star Review – AJAX Reviews for Content, with Star Ratings: from n/a through 1.5.1.
ModificadaAlta (8.1)0.71%—Startutorial PHP Backend FOR Resumable.js26/12/202317/6/2026
resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/form-data content to upload.php. (File overwrite hasn't been possible with the code available in GitHub in recent years, however.)
ModificadaCrítica (9.8)0.70%—Starnight Micro Http Server25/12/202317/6/2026
In MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long URI.
ModificadaCrítica (9.8)1.5%💥 PoCStarnight Micro Http Server17/12/202317/6/2026
In MicroHttpServer (aka Micro HTTP Server) through 4398570, _ReadStaticFiles in lib/middleware.c allows a stack-based buffer overflow and potentially remote code execution via a long URI.
ModificadaCrítica (9.8)0.83%—Joomstar Starshop14/12/202317/6/2026
SQLi vulnerability in Starshop component for Joomla.
ModificadaMedia (5.4)0.40%—Brainstormforce Starter Templates7/12/202317/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4.
ModificadaMedia (5.3)1.2%—Yokogawa Stardom FCJ FirmwareYokogawa Stardom FCN Firmware1/12/202317/6/2026
A vulnerability of Uncontrolled Resource Consumption has been identified in STARDOM provided by Yokogawa Electric Corporation. This vulnerability may allow to a remote attacker to cause a denial-of-service condition to the FCN/FCJ controller by sending a crafted packet. While sending the packet, the maintenance…
ModificadaAlta (8.1)0.40%—YET Another Stars Rating Project YET Another Stars Rating30/11/202317/6/2026
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rating Plugin for WordPress.This issue affects YASR – Yet Another Star Rating Plugin for WordPress: from n/a through 3.3.8.
ModificadaMedia (5.9)0.41%—Kamalkhan KK Star Ratings27/11/202317/6/2026
The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition.
ModificadaCrítica (9.8)1.2%—Fivestarplugins Five Star Restaurant Menu20/11/202317/6/2026
The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.
ModificadaMedia (6.1)0.41%—Star-emea Star Cloudprnt FOR Woocommerce16/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in lawrenceowen, gcubero, acunnningham, fmahmood Star CloudPRNT for WooCommerce plugin <= 2.0.3 versions.
ModificadaMedia (6.1)0.66%—Star-emea Star Cloudprnt FOR Woocommerce13/11/202317/6/2026
The Star CloudPRNT for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'printersettings' parameter in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
ModificadaMedia (6.1)0.21%—Starkdigital Category Post List Widget13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Stark Digital Category Post List Widget allows Stored XSS.This issue affects Category Post List Widget: from n/a through 2.0.
ModificadaMedia (6.1)0.53%—Dstar2018 Agency7/11/202317/6/2026
A vulnerability classified as problematic was found in dstar2018 Agency up to 61. Affected by this vulnerability is an unknown functionality of the file search.php. The manipulation of the argument QSType/QuickSearch leads to cross site scripting. The attack can be launched remotely. The patch is named…
ModificadaMedia (6.1)0.63%—Openknowledgemaps Head Start20/9/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visual Project Explorer 1.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'service' parameter in…
ModificadaMedia (6.1)0.57%—Openknowledgemaps Head Start13/9/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start 7 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'file' parameter in 'displayPDF.php'.
ModificadaAlta (8.8)0.26%—Startrinity Softswitch3/9/202317/6/2026
StarTrinity Softswitch version 2023-02-16 - Multiple CSRF (CWE-352)
ModificadaMedia (6.1)0.36%—Startrinity Softswitch3/9/202317/6/2026
StarTrinity Softswitch version 2023-02-16 - Open Redirect (CWE-601)
ModificadaMedia (5.4)0.38%—Startrinity Softswitch3/9/202317/6/2026
StarTrinity Softswitch version 2023-02-16 - Persistent XSS (CWE-79)
ModificadaMedia (6.1)0.40%—Startrinity Softswitch3/9/202317/6/2026
StarTrinity Softswitch version 2023-02-16 - Multiple Reflected XSS (CWE-79)
ModificadaMedia (4.8)0.36%—Kristarella Exifography3/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Exifography plugin <= 1.3.1 versions.
ModificadaCrítica (9.8)1.1%—Acyba Acymailing Starter17/8/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.
Orbitaley — Vulnerabilidades