Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1221 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.7) | 0.36% | — | Awesomemotive Easy Digital Downloads | 17/12/2024 | 17/6/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ensure the requesting user is the intended recipient of the purchase receipt. This makes it possible… | |
| Aplazada | Media (6.5) | 0.39% | — | Digital Operation Services WifiburadaAI | 17/12/2024 | 17/6/2026 | Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables. This issue affects WiFiBurada: before 1.0.5. | |
| Aplazada | Media (4.3) | 0.40% | — | Digital Operation Services WifiburadaAI | 17/12/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials. This issue affects WiFiBurada: before 1.0.5. | |
| Aplazada | Crítica (10) | 0.66% | — | HK Digital Agency LLC TAX Service Electronic HDMAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK Digital Agency LLC TAX SERVICE Electronic HDM virtual-hdm-for-taxservice-am allows SQL Injection.This issue affects TAX SERVICE Electronic HDM: from n/a through <= 1.2.2. | |
| Aplazada | Media (5.4) | 0.57% | — | Madfishdigital Bulk Noindex AND Nofollow ToolkitAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 1.5. | |
| Modificada | Crítica (9.8) | 0.64% | — | Awesomemotive Easy Digital Downloads | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi Easy Digital Downloads easy-digital-downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through <= 3.1.5. | |
| Aplazada | Alta (7.5) | 0.79% | 💥 PoC | Stratospheredigital WP Courses LMSAI | 12/12/2024 | 17/6/2026 | The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpc_update_user_meta_option() function in all versions up to, and including, 3.2.21. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.42% | — | Library Management System Manage E Digital Books LibraryAI | 12/12/2024 | 17/6/2026 | The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the 'owt7_borrow_books_id' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (6.8) | 0.44% | — | Library Management System Manage E Digital Books LibraryAI | 7/12/2024 | 17/6/2026 | The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the ‘value' parameter of the owt_lib_handler AJAX action in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Alta (8.8) | 0.86% | — | Beijing Digital China Yunke Information Technology YunkeAI | 3/12/2024 | 17/6/2026 | An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via the code/function/dpi/web_auth/customizable.php file | |
| Aplazada | Alta (7.8) | 0.24% | — | Mitsubishi Electric Iconics Digital Solutions Genesis64AIMitsubishi Electric Iconics Digital Solutions Iconics SuiteAIMitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAI+5 | 28/11/2024 | 17/6/2026 | Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric GENESIS32 all versions, Mitsubishi Electric MC Works64 all… | |
| Aplazada | Alta (7.8) | 0.24% | — | Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric Hyper HistorianAIMitsubishielectric Genesis32AI+5 | 28/11/2024 | 17/6/2026 | Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric GENESIS32 all versions, Mitsubishi Electric MC Works64 all… | |
| Aplazada | Media (6.1) | 0.52% | — | Premium Packages Sell Digital Products SecurelyAI | 22/11/2024 | 17/6/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.9.3. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.4) | 0.55% | — | Premium Packages Sell Digital Products SecurelyAI | 21/11/2024 | 17/6/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdmpp_pay_link shortcode in all versions up to, and including, 5.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Aplazada | Media (6.5) | 0.39% | — | Digitalzoomstudio ParallaxerAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio Parallaxer parallaxer-lite-parallax-effects-on-images allows Stored XSS.This issue affects Parallaxer: from n/a through <= 1.00. | |
| Modificada | Alta (7.2) | 0.46% | — | Wpdownloadmanager Premium Packages - Sell Digital Products Securely | 18/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages.This issue affects WPDM – Premium Packages: from n/a through <= 6.0.5. | |
| Aplazada | Media (4.3) | 0.14% | — | Digitalguardian Removable Media EncryptionAI | 15/11/2024 | 17/6/2026 | A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to circumvent encryption controls by modifying metadata on the USB device thereby compromising the confidentiality of the stored data. | |
| Aplazada | Alta (7.1) | 0.27% | — | Digitalfisherman Geotagged MediaAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalfisherman Geotagged Media geotagged-media allows Reflected XSS.This issue affects Geotagged Media: from n/a through <= 0.3.0. | |
| Analizada | Alta (8.8) | 0.49% | — | Awesomemotive Easy Digital Downloads | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.2.12. | |
| Analizada | Media (6.1) | 0.24% | — | Liferay Digital Experience PlatformLiferay Portal | 22/10/2024 | 17/6/2026 | The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA through fix pack 173 does not sufficiently protect against… | |
| Modificada | Alta (8.8) | 0.65% | — | Liferay Digital Experience PlatformLiferay Portal | 22/10/2024 | 17/6/2026 | The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to… | |
| Analizada | Alta (8.8) | 0.38% | — | Liferay Digital Experience PlatformLiferay Portal | 22/10/2024 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 update 29 through update 35 allows remote attackers to (1) change user passwords, (2) shut… | |
| Analizada | Alta (8.8) | 0.38% | — | Liferay Digital Experience PlatformLiferay Portal | 22/10/2024 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 GA through update 35 allows remote attackers to (1) change user passwords, (2) shut down the… | |
| Analizada | Alta (8.8) | 0.38% | — | Liferay Digital Experience PlatformLiferay Portal | 22/10/2024 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2)… | |
| Aplazada | Alta (7.1) | 0.29% | — | Omarfolgheraiter DigitallyAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omarfolghe Digitally digitally allows Reflected XSS.This issue affects Digitally: from n/a through <= 1.0.8. |