Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1208 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.18% | — | Wpdownloadmanager Premium Packages - Sell Digital Products Securely | 25/9/2024 | 17/6/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. This is due to missing nonce validation on the addRefund() function. This makes it possible for unauthenticated attackers to perform actions such as… | |
| Analizada | Alta (7.2) | 0.69% | — | Awesomemotive Easy Digital Downloads | 24/9/2024 | 17/6/2026 | The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via the 'upload[file]' parameter in versions up to, and including 3.3.3. This makes it possible for authenticated administrative users to call files using a PHAR wrapper,… | |
| Aplazada | Alta (8.8) | 0.66% | — | Takenaka Engineering Digital Video RecorderAI | 18/9/2024 | 17/6/2026 | Hidden functionality issue in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. | |
| Aplazada | Alta (8.8) | 1.00% | — | Takenaka Engineering Digital Video RecorderAI | 18/9/2024 | 17/6/2026 | OS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. | |
| Aplazada | Alta (8.8) | 0.51% | — | Takenaka Engineering Digital Video RecorderAI | 18/9/2024 | 17/6/2026 | Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. | |
| Analizada | Media (5.4) | 0.29% | — | Digitalnature Mystique | 18/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in digitalnature Mystique allows Stored XSS.This issue affects Mystique: from n/a through 2.5.7. | |
| Modificada | Media (5.5) | 0.17% | — | TI Fusion Digital Power Designer | 12/9/2024 | 17/6/2026 | An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials | |
| Analizada | Media (6.5) | 0.67% | — | Learningdigital Orca HCM | 9/9/2024 | 17/6/2026 | Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files. | |
| Modificada | Crítica (9.8) | 0.68% | — | Learningdigital Orca HCM | 9/9/2024 | 17/6/2026 | Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in. | |
| Analizada | Crítica (9.8) | 2.6% | 💥 Exploit | Awesomemotive Easy Digital Downloads | 29/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12. | |
| Analizada | Media (6.9) | 0.53% | — | Kitsada8621 Digital Library Management System | 29/8/2024 | 17/6/2026 | A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. Affected is the function JwtRefreshAuth of the file middleware/jwt_refresh_token_middleware.go. The manipulation of the argument Authorization leads to improper output neutralization for logs. It is… | |
| Aplazada | Crítica (9.8) | 15% | — | Beijing Digital China Cloud Technology Dcme-320AI | 28/8/2024 | 17/6/2026 | Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device administrator privileges via the getVar function in the code/function/system/tool/ping.php file. | |
| Analizada | Media (4.8) | 0.28% | — | Starkdigital WP Testimonial Widget | 26/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digital WP Testimonial Widget allows Stored XSS.This issue affects WP Testimonial Widget: from n/a through 3.1. | |
| Analizada | Alta (7.2) | 0.44% | — | Starkdigital WP Testimonial Widget | 26/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from n/a through 3.1. | |
| Modificada | Media (5.3) | 0.34% | — | Starkdigital WP Testimonial Widget | 21/8/2024 | 17/6/2026 | The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTestimonailOrder function in all versions up to, and including, 3.1. This makes it possible for unauthenticated attackers to change the order of testimonials. | |
| Analizada | Media (6.1) | 0.19% | — | Cyberfoxdigital Christmasify! | 12/8/2024 | 17/6/2026 | The Christmasify! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.5. This is due to missing nonce validation on the 'options' function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a… | |
| Analizada | Baja (3.1) | 0.38% | — | Awesomemotive Easy Digital Downloads | 12/8/2024 | 17/6/2026 | The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Agreement Text value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it… | |
| Analizada | Media (4) | 0.35% | — | Awesomemotive Easy Digital Downloads | 12/8/2024 | 17/6/2026 | The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the currency value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Alta (7.1) | 0.26% | — | NodejsAIElectronAIWesterndigital WD DiscoveryAI | 2/8/2024 | 17/6/2026 | WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any malicious application operating with standard user permissions can exploit this vulnerability, enabling code execution… | |
| Modificada | Alta (7.5) | 0.40% | — | Digitaldruid Hoteldruid | 30/7/2024 | 17/6/2026 | Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Hangzhou Xiongwei Technology Development Restaurant Digital Comprehensive Management PlatformAI | 26/7/2024 | 17/6/2026 | An issue in Hangzhou Xiongwei Technology Development Co., Ltd. Restaurant Digital Comprehensive Management platform v1 allows an attacker to bypass authentication and perform arbitrary password resets. | |
| Aplazada | Media (6.5) | 0.32% | — | Calendar.onlineAIKalender.digitalAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Calendar.Online Calendar.Online / Kalender.Digital allows Stored XSS.This issue affects Calendar.Online / Kalender.Digital: from n/a through 1.0.8. | |
| Aplazada | Media (5.9) | 0.32% | — | Sandisk IBIAIWesterndigital MY CloudAIWesterndigital MY Cloud HomeAIWesterndigital WD CloudAI | 24/6/2024 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found which could allow an attacker to redirect the user to a crafted domain and reset their credentials, or to execute arbitrary client-side code in the user’s browser session to carry out malicious… | |
| Modificada | Alta (8.8) | 0.21% | — | Blazethemes Digital Newspaper | 21/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in blazethemes Digital Newspaper.This issue affects Digital Newspaper: from n/a through 1.1.5. | |
| Modificada | Crítica (9.8) | 0.54% | — | Wow-company Easy Digital Downloads | 4/6/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Easy Digital Downloads – Recent Purchases allows PHP Remote File Inclusion.This issue affects Easy Digital Downloads – Recent Purchases: from n/a through 1.0.2. |