Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1208 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.36% | — | Vsourz Digital Responsive Slick SliderAI | 4/6/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vsourz Digital Responsive Slick Slider WordPress allows Code Injection.This issue affects Responsive Slick Slider WordPress: from n/a through 1.4. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Minmax Digital Technology Minmax CMSAI | 30/5/2024 | 17/6/2026 | MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access control restrictions and log in to the backend system without being recorded in the… | |
| Modificada | Alta (7.5) | 0.64% | — | Sandhillsdev Easy Digital Downloads | 14/5/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11. | |
| Modificada | Alta (8.8) | 0.22% | — | Sandhillsdev Easy Digital Downloads | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11. | |
| Aplazada | Alta (7.8) | 0.49% | 💥 PoC | Panoramic Corporation Digital Imaging SoftwareAI | 14/5/2024 | 17/6/2026 | An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exe component. | |
| Aplazada | Media (5.3) | 0.42% | — | Supsystic Digital PublicationsAI | 6/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7. | |
| Aplazada | Media (5.9) | 0.38% | — | Mrdigital Simple Image PopupAI | 2/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr Digital Simple Image Popup allows Stored XSS.This issue affects Simple Image Popup: from n/a through 2.4.0. | |
| Aplazada | Media (4.3) | 0.21% | — | Supsystic Digital PublicationsAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7. | |
| Modificada | Alta (8.8) | 0.23% | — | Sandhillsdev Easy Digital Downloads | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.6. | |
| Aplazada | Media (4.3) | 0.44% | — | Digitalbazaar ZcapAI | 10/4/2024 | 17/6/2026 | `@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0.1, when invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the `expires` property is not properly checked against the current date or other `date`… | |
| Modificada | Media (5.3) | 0.60% | — | Awesomemotive Easy Digital Downloads | 9/4/2024 | 17/6/2026 | The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to download the debug log via Directory Listing.… | |
| Aplazada | Media (6.5) | 0.35% | — | Interfacelab Media CloudAIAmazon S3AIImgixAIGoogle Cloud StorageAI+1 | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Interfacelab Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and more allows Stored XSS.This issue affects Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and… | |
| Aplazada | Alta (7.1) | 0.42% | — | Madfishdigital Bulk Noindex AND Nofollow ToolkitAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Reflected XSS.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 2.01. | |
| Aplazada | Media (6.5) | 0.41% | — | Snpdigital SaleskingAI | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15. | |
| Analizada | Alta (7.8) | 0.21% | — | Dell Digital Delivery | 4/3/2024 | 17/6/2026 | Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation. | |
| Analizada | Alta (7.8) | 0.20% | — | Dell Digital Delivery | 4/3/2024 | 17/6/2026 | Dell Digital Delivery, versions prior to 5.2.0.0, contain a Use After Free Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to application crash or execution of arbitrary code. | |
| Analizada | Media (5.4) | 0.61% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's… | |
| Analizada | Media (5.4) | 0.47% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not escape user supplied data in the default notification email template, which allows remote authenticated users to inject… | |
| Analizada | Media (6.1) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML… | |
| Analizada | Media (5.4) | 0.56% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary… | |
| Analizada | Media (6.1) | 0.61% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the… | |
| Analizada | Media (6.1) | 0.61% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the… | |
| Analizada | Media (6.1) | 0.62% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked… | |
| Analizada | Media (5.4) | 0.62% | — | Liferay PortalLiferay Digital Experience Platform | 21/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web… |