Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
815 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.60% | — | Masterlab | 29/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in gopeak MasterLab up to 3.3.10. Affected is the function base64ImageContent of the file app/ctrl/User.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. VDB-249150 is the identifier… | |
| Modificada | Crítica (9.8) | 0.65% | — | Masterlab | 29/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in gopeak MasterLab up to 3.3.10. This issue affects the function sqlInjectDelete of the file app/ctrl/framework/Feature.php of the component HTTP POST Request Handler. The manipulation of the argument phone leads to sql injection. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.65% | — | Masterlab | 29/12/2023 | 17/6/2026 | A vulnerability classified as critical was found in gopeak MasterLab up to 3.3.10. This vulnerability affects the function sqlInject of the file app/ctrl/Framework.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to sql injection. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 0.57% | — | Masterlab | 29/12/2023 | 17/6/2026 | A vulnerability classified as critical has been found in gopeak MasterLab up to 3.3.10. This affects the function sqlInject of the file app/ctrl/framework/Feature.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to sql injection. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 0.39% | — | Averta Master Slider PRO | 20/12/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro: from n/a through 3.6.5. | |
| Modificada | Alta (8.8) | 0.27% | — | Gravitymaster Product Enquiry FOR Woocommerce | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Gravity Master Product Enquiry for WooCommerce.This issue affects Product Enquiry for WooCommerce: from n/a through 3.0. | |
| Modificada | Alta (8.8) | 0.70% | — | Masterslider Master Slider | 18/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Master slider Master Slider Pro allows SQL Injection.This issue affects Master Slider Pro: from n/a through 3.6.5. | |
| Modificada | Media (5.3) | 0.63% | — | SAP Master Data Governance | 12/12/2023 | 17/6/2026 | SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality. | |
| Modificada | Alta (7.5) | 1.1% | — | Deltaww Infrasuite Device Master | 30/11/2023 | 17/6/2026 | In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying. | |
| Modificada | Crítica (9.8) | 17% | — | Deltaww Infrasuite Device Master | 30/11/2023 | 17/6/2026 | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges. | |
| Modificada | Alta (8.8) | 1.9% | — | Deltaww Infrasuite Device Master | 30/11/2023 | 17/6/2026 | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the filesystem, which could lead to remote code execution. | |
| Modificada | Crítica (9.8) | 1.2% | — | Deltaww Infrasuite Device Master | 30/11/2023 | 17/6/2026 | In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code through a single UDP packet. | |
| Modificada | Alta (8.8) | 0.25% | — | Offshorewebmaster Availability Calendar | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Offshore Web Master Availability Calendar allows Cross Site Request Forgery.This issue affects Availability Calendar: from n/a through 1.2.6. | |
| Modificada | Media (5.4) | 0.30% | — | Addonmaster Bootstrap Shortcodes Ultimate | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akhtarujjaman Shuvo Bootstrap Shortcodes Ultimate allows Stored XSS.This issue affects Bootstrap Shortcodes Ultimate: from n/a through 4.3.1. | |
| Modificada | Media (5.4) | 0.39% | — | Quizandsurveymaster Quiz AND Survey Master | 23/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master plugin <= 8.1.13 versions. | |
| Modificada | Media (6.1) | 0.44% | — | Diywebmastery Footer Putter | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Footer Putter plugin <= 1.17 versions. | |
| Modificada | Alta (7.5) | 1.3% | — | Terra-mater Terra-master | 17/11/2023 | 17/6/2026 | Directory Traversal vulnerability in TerraMaster v.s1.0 through v.2.295 allows a remote attacker to obtain sensitive information via a crafted GET request. | |
| Analizada | Media (6.1) | 0.41% | — | Gravitymaster Product Enquiry FOR Woocommerce | 16/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Averta Master Slider | 16/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Averta Master Slider Pro plugin <= 3.6.5 versions. | |
| Modificada | Media (6.1) | 0.43% | — | Gravitymaster Product Enquiry FOR Woocommerce | 13/11/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Gravity Master Product Enquiry for WooCommerce plugin <= 3.0 versions. | |
| Modificada | Media (6.1) | 0.20% | — | Lionscripts Webmaster Tools | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com Webmaster Tools allows Stored XSS.This issue affects Webmaster Tools: from n/a through 2.0. | |
| Modificada | Alta (8.8) | 0.31% | — | Expresstech Quiz AND Survey Master | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Zixn Original Texts Yandex Webmaster | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Djo Original texts Yandex WebMaster plugin <= 1.18 versions. | |
| Modificada | Media (4.8) | 0.31% | — | Lionscripts Webmaster Tools | 27/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in LionScripts.Com Webmaster Tools plugin <= 2.0 versions. | |
| Modificada | Media (6.5) | 0.48% | — | Grandingteco Utime Master | 13/10/2023 | 17/6/2026 | An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to access sensitive information via a crafted cookie. |