Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

481 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.91%—Limesurvey9/9/201917/6/2026
A clickjacking vulnerability was found in Limesurvey before 3.17.14.
ModificadaAlta (8.8)2.4%—Limesurvey9/9/201917/6/2026
An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.
ModificadaMedia (5.4)3.7%💥 ExploitLimesurvey9/9/201917/6/2026
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
ModificadaMedia (5.4)4.6%💥 ExploitLimesurvey9/9/201917/6/2026
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.
ModificadaAlta (7.5)1.2%—Limesurvey26/8/201917/6/2026
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
ModificadaMedia (6.1)0.87%—Diaowen Dwsurvey16/8/201917/6/2026
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
ModificadaMedia (6.1)0.79%—Diaowen Dwsurvey7/8/201917/6/2026
DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.
ModificadaCrítica (9.8)8.2%—Netgear Readynas Surveillance Firmware11/6/201917/6/2026
In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=writeuploaddir remote command execution.
ModificadaAlta (7.5)10%—Cisco Video Surveillance Manager15/5/201917/6/2026
A vulnerability in the web-based management interface of Cisco Video Surveillance Manager could allow an unauthenticated, remote attacker to access sensitive information. The vulnerability is due to improper validation of parameters handled by the web-based management interface. An attacker could exploit this…
ModificadaCrítica (9.8)13%—Limesurvey24/3/201917/6/2026
The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.
ModificadaMedia (6.1)1.6%—Quizandsurveymaster Quiz AND Survey Master5/3/201917/6/2026
The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS.
ModificadaMedia (6.1)0.95%—Limesurvey15/1/201917/6/2026
LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel.
ModificadaMedia (6.1)1.1%—Limesurvey21/12/201817/6/2026
LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting in Javascript code execution against LimeSurvey administrators. Fixed in version 3.15.6.
ModificadaMedia (6.5)1.7%—Cisco Video Surveillance Media Server8/11/201817/6/2026
A vulnerability in the web-based management interface of Cisco Video Surveillance Media Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by…
ModificadaCrítica (9.8)6.8%—Cisco Video Surveillance Manager5/10/201817/6/2026
A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (UCS) platforms could allow an unauthenticated, remote attacker to log in to an affected system by using the root account, which has default, static user credentials. The…
ModificadaMedia (6.1)1.0%—Limesurvey21/9/201817/6/2026
In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert.
ModificadaCrítica (9.8)26%💥 ExploitTecnick TcpdfLimesurvey14/9/201817/6/2026
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
ModificadaAlta (8.8)3.6%—Limesurvey6/9/201817/6/2026
LimeSurvey version 3.14.4 and earlier contains a directory traversal in file upload that allows upload of webshell vulnerability in file upload functionality that can result in remote code execution as authenticated user. This attack appear to be exploitable via An authenticated user can upload a specially crafted zip…
ModificadaAlta (8.8)2.1%—Limesurvey6/9/201817/6/2026
LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution via webshell. This attack appear to be exploitable via an authenticated user uploading a zip archive which can contains malicious php files that can be called under…
ModificadaMedia (4.9)1.0%—Limesurvey3/9/201817/6/2026
In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an arbitrary file,
ModificadaAlta (7.5)98%💥 ExploitArgussurveillance DVR30/8/201817/6/2026
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.
ModificadaMedia (4.3)0.34%—Limesurvey26/6/201817/6/2026
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Boxes that can result in CSRF admins to delete boxes. This vulnerability appears to have been fixed in 3.6.x.
ModificadaMedia (4.8)0.71%—Limesurvey26/6/201817/6/2026
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross Site Scripting (XSS) vulnerability in Boxes that can result in JS code execution against LimeSurvey admins. This vulnerability appears to have been fixed in 3.6.x.
ModificadaCrítica (9.1)2.0%—LimesurveyDebian Linux28/2/201817/6/2026
LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installation, which allows remote attackers to access the configuration file.
ModificadaMedia (6.5)1.8%—Synology Surveillance Station27/2/201817/6/2026
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensitive files via the filename parameter.