Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
815 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.35% | — | Grandingteco Utime Master | 13/10/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Create A New Employee function of Granding UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter. | |
| Modificada | Alta (7.5) | 6.2% | 💥 Exploit | Stylemixthemes Masterstudy LMS | 11/9/2023 | 17/6/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts. | |
| Modificada | Media (5.5) | 0.18% | — | Asustor Data Master | 22/8/2023 | 17/6/2026 | An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below. | |
| Modificada | Media (5.5) | 0.16% | — | Asustor Data Master | 22/8/2023 | 17/6/2026 | An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below. | |
| Modificada | Crítica (9.8) | 32% | 💥 Exploit | Terra-master Terramaster Operating System | 20/8/2023 | 17/6/2026 | TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed in raidtype because popen is used without any sanitization.) The credentials… | |
| Modificada | Alta (8.1) | 0.64% | — | Asustor Data Master | 17/8/2023 | 17/6/2026 | Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below. | |
| Modificada | Alta (8.8) | 0.66% | — | Asustor Data Master | 17/8/2023 | 17/6/2026 | Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below. | |
| Modificada | Alta (8.8) | 1.6% | — | Asustor Data Master | 17/8/2023 | 17/6/2026 | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified vectors. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below… | |
| Modificada | Media (6.7) | 0.30% | 💥 PoC | AMD Ryzen MasterAMD Ryzen Master Monitoring SDK | 15/8/2023 | 17/6/2026 | Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privileged attacker to perform memory reads/writes potentially leading to a loss of confidentiality or arbitrary kernel execution. | |
| Modificada | Media (4.4) | 0.22% | — | AMD Ryzen MasterAMD Ryzen Master Monitoring SDK | 15/8/2023 | 17/6/2026 | Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may allow a privileged attacker to provide a null value potentially resulting in a Windows crash leading to denial of service. | |
| Modificada | Media (5.4) | 0.55% | — | Expresstech Quiz AND Survey Master | 7/8/2023 | 17/6/2026 | The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.5) | 2.0% | 💥 Exploit | Themegrill Masteriyo | 31/7/2023 | 17/6/2026 | The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students | |
| Modificada | Media (6.1) | 0.36% | — | Creativeitem Mastery LMS | 19/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Creativeitem Mastery LMS 1.2. This affects an unknown part of the file /browse. The manipulation of the argument search/featured/recommended/skill leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this… | |
| Modificada | Alta (7.5) | 0.61% | — | Deltaww Infrasuite Device Master | 10/7/2023 | 17/6/2026 | An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents. | |
| Modificada | Crítica (9.8) | 2.0% | 💥 PoC | Deltaww Infrasuite Device Master | 10/7/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege management configurations, resulting in privilege escalation. | |
| Modificada | Crítica (9.8) | 0.95% | — | Deltaww Infrasuite Device Master | 10/7/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code. | |
| Modificada | Media (6.5) | 0.56% | — | Stylemixthemes Masterstudy LMS | 22/6/2023 | 17/6/2026 | Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more. | |
| Modificada | Media (5.4) | 0.38% | — | Stylemixthemes Masterstudy LMS | 22/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.7 versions. | |
| Modificada | Media (6.1) | 0.22% | — | SAP Master Data Synchronization | 13/6/2023 | 17/6/2026 | An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additional information persisted by the system. | |
| Modificada | Alta (8.1) | 0.79% | — | Expresstech Quiz AND Survey Master | 9/6/2023 | 17/6/2026 | The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated attackers to delete… | |
| Modificada | Crítica (9.1) | 2.0% | — | Expresstech Quiz AND Survey Master | 9/6/2023 | 17/6/2026 | The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files. | |
| Modificada | Crítica (9.8) | 1.0% | — | Joommasters Jmspagebuilder | 6/6/2023 | 17/6/2026 | PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php. | |
| Modificada | Crítica (9.8) | 0.67% | — | Joommasters JMS Slider | 5/6/2023 | 17/6/2026 | PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Joommasters JMS Drop Mega Menu | 5/6/2023 | 17/6/2026 | PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php. | |
| Modificada | Alta (7.8) | 0.34% | — | Dualspace Lock Master | 30/5/2023 | 17/6/2026 | The Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. These files hold data that affects many app functions. Malicious modifications by unauthorized apps can cause security issues, such as functionality manipulation, resulting in a severe escalation of… |