Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
751 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.50% | — | Checkmk | 26/6/2023 | 17/6/2026 | User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames. | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Add-to-cart-direct-checkout-for-woocommerce | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Direct checkout, Add to cart redirect, Quick purchase button, Buy now button, Quick View button for WooCommerce plugin <= 2.1.48 versions. | |
| Modificada | Alta (8.1) | 0.78% | — | Jenkins Checkmarx | 14/6/2023 | 17/6/2026 | Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default. | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | Wpdesk Flexible Checkout Fields | 7/6/2023 | 17/6/2026 | The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to missing authorization checks on the updateSettingsAction() function which is called via… | |
| Modificada | Media (6.1) | 0.55% | — | Managewp Broken Link Checker | 5/6/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad en el plugin Broken Link Checker hasta la versión 1.10.1 en WordPress. Se ha declarado como problemática. Esta vulnerabilidad afecta a la función "options_page" del archivo "core/core.php" del componente "Settings Page". La manipulación del argumento… | |
| Modificada | Alta (8.8) | 0.27% | — | Wordpress Health Check & Troubleshooting | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions. | |
| Modificada | Media (4.3) | 0.59% | — | CheckmkTribe29 Checkmk | 17/5/2023 | 17/6/2026 | Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs. | |
| Modificada | Alta (8.8) | 0.97% | — | CheckmkTribe29 Checkmk | 17/5/2023 | 17/6/2026 | Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users. | |
| Modificada | Alta (7.5) | 0.54% | — | Tribe29 Checkmk Appliance Firmware | 15/5/2023 | 17/6/2026 | Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5. | |
| Modificada | Media (6.1) | 0.38% | — | Woocommerce Custom Checkout Fields Editor With Drag & Drop Project Woocommerce Custom Checkout Fields Editor With Drag & Drop | 9/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Umair Saleem Woocommerce Custom Checkout Fields Editor With Drag & Drop plugin <= 0.1 versions. | |
| Modificada | Media (5.5) | 0.22% | — | Checkmk | 2/5/2023 | 17/6/2026 | Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log. | |
| Modificada | Media (6.1) | 0.85% | 💥 Exploit | Plainviewplugins Mycryptocheckout | 2/5/2023 | 17/6/2026 | The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.41% | — | Tribe29 Checkmk Appliance Firmware | 20/4/2023 | 17/6/2026 | Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4. | |
| Modificada | Alta (8.8) | 0.39% | — | Checkmk | 20/4/2023 | 17/6/2026 | Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 (EOL) allowing an attacker to perform remote code execution with root privileges… | |
| Modificada | Media (5.5) | 0.22% | — | Tribe29 Checkmk Appliance Firmware | 18/4/2023 | 17/6/2026 | Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files. | |
| Modificada | Alta (8.8) | 0.68% | — | Tribe29 Checkmk | 18/4/2023 | 17/6/2026 | Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions. | |
| Modificada | Media (4.3) | 0.40% | — | Checkmk | 18/4/2023 | 17/6/2026 | Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host. | |
| Modificada | Media (6.1) | 0.56% | — | Wpmudev Broken Link Checker | 8/4/2023 | 17/6/2026 | A vulnerability was found in Broken Link Checker Plugin up to 1.10.5 on WordPress. It has been rated as problematic. Affected by this issue is the function print_module_list/show_warnings_section_notice/status_text/ui_get_action_links. The manipulation leads to cross site scripting. The attack may be launched… | |
| Modificada | Media (5.3) | 0.91% | — | CheckmkTribe29 Checkmk | 4/4/2023 | 17/6/2026 | Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations. | |
| Modificada | Media (5.4) | 0.46% | — | Jenkins Cppcheck | 2/4/2023 | 17/6/2026 | Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control report file contents. | |
| Modificada | Media (6.1) | 0.41% | — | Levantoan Woocommerce Vietnam Checkout | 27/3/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Le Van Toan Woocommerce Vietnam Checkout plugin <= 2.0.4 versions. | |
| Modificada | Media (5.4) | 0.40% | — | CheckmkTribe29 Checkmk | 20/3/2023 | 17/6/2026 | HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails | |
| Modificada | Media (4.8) | 0.37% | — | Plustime Service Area Postcode Checker | 20/3/2023 | 17/6/2026 | Auth. (admin+) vulnerability in Second2none Service Area Postcode Checker plugin <= 2.0.8 versions. | |
| Modificada | Media (4.8) | 0.35% | — | Tipsandtricks-hq WP Express Checkout | 17/3/2023 | 17/6/2026 | The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pec_coupon[code]’ parameter in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access to inject… | |
| Modificada | Crítica (9.8) | 4.4% | 💥 Exploit | Najeebmedia Woocommerce Checkout Field Manager | 6/3/2023 | 17/6/2026 | The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server |