Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1221 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (10)0.51%—Shafiq Digital Digital-lotteryAI16/10/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery digital-lottery allows Upload a Web Shell to a Web Server.This issue affects Digital Lottery: from n/a through <= 3.0.5.
ModificadaCrítica (9.8)5.4%💥 ExploitDigitalzoomstudio Zoomsounds16/10/202417/6/2026
The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code…
AplazadaCrítica (9.2)0.47%—Westerndigital MY CloudAI27/9/202417/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My Cloud: before 5.29.102.
AnalizadaMedia (6.1)0.39%—Madfishdigital Bulk Noindex & Nofollow Toolkit26/9/202417/6/2026
The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.15. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AnalizadaMedia (4.3)0.18%—Wpdownloadmanager Premium Packages - Sell Digital Products Securely25/9/202417/6/2026
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. This is due to missing nonce validation on the addRefund() function. This makes it possible for unauthenticated attackers to perform actions such as…
AnalizadaAlta (7.2)0.69%—Awesomemotive Easy Digital Downloads24/9/202417/6/2026
The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via the 'upload[file]' parameter in versions up to, and including 3.3.3. This makes it possible for authenticated administrative users to call files using a PHAR wrapper,…
AnalizadaMedia (5.3)0.49%—Gitapp Dingfanzu22/9/202417/6/2026
A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected is an unknown function of the file scripts/order.js of the component Order Checkout. The manipulation of the argument address-name leads to cross site scripting. It is possible to launch the…
AplazadaAlta (8.8)0.66%—Takenaka Engineering Digital Video RecorderAI18/9/202417/6/2026
Hidden functionality issue in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
AplazadaAlta (8.8)1.00%—Takenaka Engineering Digital Video RecorderAI18/9/202417/6/2026
OS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
AplazadaAlta (8.8)0.51%—Takenaka Engineering Digital Video RecorderAI18/9/202417/6/2026
Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
AnalizadaMedia (5.4)0.29%—Digitalnature Mystique18/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in digitalnature Mystique allows Stored XSS.This issue affects Mystique: from n/a through 2.5.7.
ModificadaMedia (5.5)0.17%—TI Fusion Digital Power Designer12/9/202417/6/2026
An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials
AnalizadaMedia (6.5)0.67%—Learningdigital Orca HCM9/9/202417/6/2026
Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files.
ModificadaCrítica (9.8)0.68%—Learningdigital Orca HCM9/9/202417/6/2026
Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.
AnalizadaCrítica (9.8)2.6%💥 ExploitAwesomemotive Easy Digital Downloads29/8/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12.
AnalizadaMedia (6.9)0.76%—Gitapp Dingfanzu29/8/202417/6/2026
A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax/checkin.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely.…
AnalizadaMedia (6.9)0.53%—Kitsada8621 Digital Library Management System29/8/202417/6/2026
A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. Affected is the function JwtRefreshAuth of the file middleware/jwt_refresh_token_middleware.go. The manipulation of the argument Authorization leads to improper output neutralization for logs. It is…
AplazadaCrítica (9.8)15%—Beijing Digital China Cloud Technology Dcme-320AI28/8/202417/6/2026
Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device administrator privileges via the getVar function in the code/function/system/tool/ping.php file.
AnalizadaMedia (4.8)0.28%—Starkdigital WP Testimonial Widget26/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Stark Digital WP Testimonial Widget allows Stored XSS.This issue affects WP Testimonial Widget: from n/a through 3.1.
AnalizadaAlta (7.2)0.44%—Starkdigital WP Testimonial Widget26/8/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from n/a through 3.1.
ModificadaMedia (5.3)0.34%—Starkdigital WP Testimonial Widget21/8/202417/6/2026
The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the fnSaveTestimonailOrder function in all versions up to, and including, 3.1. This makes it possible for unauthenticated attackers to change the order of testimonials.
AnalizadaMedia (6.1)0.19%—Cyberfoxdigital Christmasify!12/8/202417/6/2026
The Christmasify! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.5. This is due to missing nonce validation on the 'options' function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a…
AnalizadaBaja (3.1)0.38%—Awesomemotive Easy Digital Downloads12/8/202417/6/2026
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Agreement Text value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it…
AnalizadaMedia (4)0.35%—Awesomemotive Easy Digital Downloads12/8/202417/6/2026
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the currency value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaAlta (7.1)0.26%—NodejsAIElectronAIWesterndigital WD DiscoveryAI2/8/202417/6/2026
WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any malicious application operating with standard user permissions can exploit this vulnerability, enabling code execution…
Orbitaley — Vulnerabilidades