Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

622 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.0%—Getcloudsms JOY OF Text Lite2/1/202317/6/2026
The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using them in SQL statements accessible to unauthenticated users, leading to unauthenticated SQL injection
ModificadaCrítica (9.8)0.75%—Itextpdf Rups30/12/202217/6/2026
A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file src/main/java/com/itextpdf/rups/model/XfaFile.java. The manipulation leads to xml external entity reference. The patch is identified as ac5590925874ef810018a6b60fec216eee54fb32. It is recommended to…
ModificadaAlta (7.5)1.4%—Golang Text26/12/202217/6/2026
golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.
ModificadaMedia (6.1)0.60%—Texthelpers Project Texthelpers22/12/202217/6/2026
A vulnerability was found in ahorner text-helpers up to 1.0.x. It has been declared as critical. This vulnerability affects unknown code of the file lib/text_helpers/translation.rb. The manipulation of the argument link leads to use of web link to untrusted target with window.opener access. The attack can be initiated…
ModificadaAlta (7.5)1.5%—Golang Text14/10/202217/6/2026
An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.
ModificadaCrítica (9.8)100%💥 ExploitApache Commons TextNetapp BluexpJuniper Security Threat Response Manager13/10/202217/6/2026
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with…
ModificadaMedia (4.8)0.70%—Gettext Override Translations Project Gettext Override Translations19/9/202217/6/2026
The Gettext override translations WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (8.8)0.68%—Summitmediaconcepts Ucontext FOR Clickbank6/9/202217/6/2026
The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for…
ModificadaAlta (8.8)0.76%—Summitmediaconcepts Ucontext FOR Amazon6/9/202217/6/2026
The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for…
ModificadaAlta (8.8)0.24%—Redhat Ansible Automation Platform Early AccessRedhat Ansible Automation Platform Text-only AdvisoriesRedhat Ansible TowerRedhat Ansible Automation Platform25/8/202217/6/2026
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.
ModificadaMedia (5.4)0.60%—Jenkins Rich Text Publisher30/6/202217/6/2026
Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
ModificadaMedia (4.3)0.52%—Textpattern29/6/202217/6/2026
Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if…
ModificadaMedia (4.8)0.58%—Textpattern14/6/202217/6/2026
Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.
ModificadaMedia (4.8)0.59%—Easy FAQ With Expanding Text Project Easy FAQ With Expanding Text30/5/202217/6/2026
The Easy FAQ with Expanding Text WordPress plugin through 3.2.8.3.1 does not sanitise and escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks when unfiltered_html is disallowed
ModificadaAlta (7.8)0.51%—Sonicwall Netextender13/5/202217/6/2026
A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attacker to potentially execute arbitrary code in the host windows operating system.
ModificadaMedia (6.1)0.39%—Footer-text Project Footer-text28/4/202217/6/2026
Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on WordPress.
ModificadaMedia (4.8)0.60%—Contextureintl Page Security & Membership18/4/202217/6/2026
The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (4.8)0.81%—Text Hover Project Text Hover18/4/202217/6/2026
The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (8.3)3.0%—Textpattern29/3/202217/6/2026
textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file upload request.
ModificadaMedia (5.4)0.53%—Marktext10/3/202217/6/2026
A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: scheme) inside the document may allow an attacker to execute an arbitrary script on the PC of the user using marktext.
ModificadaCrítica (9.6)2.0%—Marktext5/3/202217/6/2026
Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.
ModificadaAlta (7.8)0.82%—ARM Adaptive Scalable Texture Compression Encoder28/2/202217/6/2026
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow in function encode_ise().
ModificadaCrítica (9.8)1.2%—ARM Adaptive Scalable Texture Compression Encoder28/2/202217/6/2026
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbolic_block_for_partition_2planes() in "/Source/astcenc_compress_symbolic.cpp".
ModificadaAlta (7.8)0.89%—KDE KateKDE Ktexteditor11/2/202217/6/2026
The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the directory of the file that was just opened…
ModificadaMedia (6.5)0.55%—Itextpdf Itext1/2/202217/6/2026
iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NOTE: Vendor does not view this as a vulnerability and has not found it to be exploitable.
Orbitaley — Vulnerabilidades