Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

499 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.00%💥 ExploitNchsoftware Express Invoice7/4/202017/6/2026
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
ModificadaAlta (8.8)2.2%—Nchsoftware Express Invoice7/4/202017/6/2026
In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen.
ModificadaMedia (5.3)1.4%—Mitel MicollabMitel Mivoice Business Express12/11/201917/6/2026
A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8.0.2.202), and MiVoice Business Express versions 7.3 PR3 (7.3.1.302) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP1 (8.0.2.202), could allow creation of unauthorized…
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaMedia (6.1)0.92%—Awesomemotive Easy Digital DownloadsEasydigitaldownloads PDF Invoices23/10/201917/6/2026
The Easy Digital Downloads (EDD) PDF Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
ModificadaMedia (6.1)0.92%—Awesomemotive Easy Digital DownloadsEasydigitaldownloads Invoices23/10/201917/6/2026
The Easy Digital Downloads (EDD) Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
ModificadaMedia (5.4)0.58%—Nchsoftware Express Invoice14/10/201917/6/2026
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parameter to inject arbitrary JavaScript.
ModificadaMedia (6.1)2.5%—Eclipse MojarraOracle Mojarra Javaserver FacesOracle Application Testing SuiteOracle Banking Enterprise Product Manufacturing+192/10/201917/6/2026
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
ModificadaMedia (6.5)1.4%—Usabilitydynamics Wp-invoice20/9/201917/6/2026
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
ModificadaMedia (5.3)1.8%—Usabilitydynamics Wp-invoice20/9/201917/6/2026
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.
ModificadaMedia (5.3)1.8%—Usabilitydynamics Wp-invoice20/9/201917/6/2026
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.
ModificadaMedia (5.3)1.8%—Usabilitydynamics Wp-invoice20/9/201917/6/2026
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
ModificadaMedia (5.3)2.0%—Usabilitydynamics Wp-invoice20/9/201917/6/2026
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
ModificadaMedia (5.3)1.8%—Usabilitydynamics Wp-invoice20/9/201917/6/2026
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
ModificadaMedia (6.1)0.95%—Ithemes Invoices28/8/201917/6/2026
Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
ModificadaAlta (7.3)28%—Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+5620/8/201925/8/2026
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
ModificadaMedia (6.1)0.92%—Wpovernight Woocommerce PDF Invoices& Packing Slips12/8/201917/6/2026
The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.
ModificadaCrítica (9.8)1.9%—Google Voice Builder23/7/201917/6/2026
Voice Builder Prior to commit c145d4604df67e6fc625992412eef0bf9a85e26b and f6660e6d8f0d1d931359d591dbdec580fef36d36 is affected by: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'). The impact is: Remote code execution with the same privileges as the servers. The…
ModificadaMedia (6.7)0.61%—Cisco ASA 5500 FirmwareCisco Firepower 2100 FirmwareCisco Firepower 4000 FirmwareCisco Firepower 9000 Firmware+2313/5/201917/6/2026
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based…
ModificadaMedia (5.4)0.67%—Invoiceplane21/3/201917/6/2026
InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice" option. The XSS payload is rendered at an index.php/invoices/view/## URI. NOTE: this is different from CVE-2018-12255.
ModificadaAlta (7.8)0.22%—Qualcomm Snapdragon Auto FirmwareQualcomm Snapdragon Consumer Internet OF Things FirmwareQualcomm Snapdragon Industrial Internet OF Things FirmwareQualcomm Snapdragon Internet OF Things Firmware+3725/2/201917/6/2026
Improper validation of array index can lead to unauthorized access while processing debugFS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in version MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W,…
ModificadaMedia (5.5)0.20%—Qualcomm Snapdragon Auto FirmwareQualcomm Snapdragon Connectivity FirmwareQualcomm Snapdragon Consumer Internet OF Things FirmwareQualcomm Snapdragon Industrial Internet OF Things Firmware+3225/2/201917/6/2026
Arbitrary write issue can occur when user provides kernel address in compat mode in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU,…
ModificadaMedia (6.1)1.1%—Mitel Mivoice Office 40023/10/201817/6/2026
A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack, due to insufficient validation for the start.asp page. A successful exploit could allow the attacker to…
ModificadaCrítica (9.8)4.9%—Mitel Mivoice 5330e Firmware23/10/201817/6/2026
The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this issue remotely, by sending a particular pattern of SIP/SDP packets, to cause a denial of service state in the affected devices and probably remote code execution.