Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

815 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.60%—Masterlab29/12/202317/6/2026
A vulnerability, which was classified as critical, was found in gopeak MasterLab up to 3.3.10. Affected is the function base64ImageContent of the file app/ctrl/User.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. VDB-249150 is the identifier…
ModificadaCrítica (9.8)0.65%—Masterlab29/12/202317/6/2026
A vulnerability, which was classified as critical, has been found in gopeak MasterLab up to 3.3.10. This issue affects the function sqlInjectDelete of the file app/ctrl/framework/Feature.php of the component HTTP POST Request Handler. The manipulation of the argument phone leads to sql injection. The exploit has been…
ModificadaCrítica (9.8)0.65%—Masterlab29/12/202317/6/2026
A vulnerability classified as critical was found in gopeak MasterLab up to 3.3.10. This vulnerability affects the function sqlInject of the file app/ctrl/Framework.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to sql injection. The exploit has been disclosed to the public…
ModificadaCrítica (9.8)0.57%—Masterlab29/12/202317/6/2026
A vulnerability classified as critical has been found in gopeak MasterLab up to 3.3.10. This affects the function sqlInject of the file app/ctrl/framework/Feature.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to sql injection. The exploit has been disclosed to the public…
ModificadaCrítica (9.8)0.39%—Averta Master Slider PRO20/12/202317/6/2026
Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro: from n/a through 3.6.5.
ModificadaAlta (8.8)0.27%—Gravitymaster Product Enquiry FOR Woocommerce18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Gravity Master Product Enquiry for WooCommerce.This issue affects Product Enquiry for WooCommerce: from n/a through 3.0.
ModificadaAlta (8.8)0.70%—Masterslider Master Slider18/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Master slider Master Slider Pro allows SQL Injection.This issue affects Master Slider Pro: from n/a through 3.6.5.
ModificadaMedia (5.3)0.63%—SAP Master Data Governance12/12/202317/6/2026
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality.
ModificadaAlta (7.5)1.1%—Deltaww Infrasuite Device Master30/11/202317/6/2026
In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying.
ModificadaCrítica (9.8)17%—Deltaww Infrasuite Device Master30/11/202317/6/2026
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges.
ModificadaAlta (8.8)1.9%—Deltaww Infrasuite Device Master30/11/202317/6/2026
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the filesystem, which could lead to remote code execution.
ModificadaCrítica (9.8)1.2%—Deltaww Infrasuite Device Master30/11/202317/6/2026
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code through a single UDP packet.
ModificadaAlta (8.8)0.25%—Offshorewebmaster Availability Calendar30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Offshore Web Master Availability Calendar allows Cross Site Request Forgery.This issue affects Availability Calendar: from n/a through 1.2.6.
ModificadaMedia (5.4)0.30%—Addonmaster Bootstrap Shortcodes Ultimate30/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akhtarujjaman Shuvo Bootstrap Shortcodes Ultimate allows Stored XSS.This issue affects Bootstrap Shortcodes Ultimate: from n/a through 4.3.1.
ModificadaMedia (5.4)0.39%—Quizandsurveymaster Quiz AND Survey Master23/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master plugin <= 8.1.13 versions.
ModificadaMedia (6.1)0.44%—Diywebmastery Footer Putter22/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Footer Putter plugin <= 1.17 versions.
ModificadaAlta (7.5)1.3%—Terra-mater Terra-master17/11/202317/6/2026
Directory Traversal vulnerability in TerraMaster v.s1.0 through v.2.295 allows a remote attacker to obtain sensitive information via a crafted GET request.
AnalizadaMedia (6.1)0.41%—Gravitymaster Product Enquiry FOR Woocommerce16/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.
ModificadaMedia (6.1)0.41%—Averta Master Slider16/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Averta Master Slider Pro plugin <= 3.6.5 versions.
ModificadaMedia (6.1)0.43%—Gravitymaster Product Enquiry FOR Woocommerce13/11/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions.
ModificadaMedia (6.1)0.20%—Lionscripts Webmaster Tools13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com Webmaster Tools allows Stored XSS.This issue affects Webmaster Tools: from n/a through 2.0.
ModificadaAlta (8.8)0.31%—Expresstech Quiz AND Survey Master13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions.
ModificadaAlta (8.8)0.21%—Zixn Original Texts Yandex Webmaster6/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Djo Original texts Yandex WebMaster plugin <= 1.18 versions.
ModificadaMedia (4.8)0.31%—Lionscripts Webmaster Tools27/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in LionScripts.Com Webmaster Tools plugin <= 2.0 versions.
ModificadaMedia (6.5)0.48%—Grandingteco Utime Master13/10/202317/6/2026
An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to access sensitive information via a crafted cookie.
Orbitaley — Vulnerabilidades