Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1208 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.36%—Vsourz Digital Responsive Slick SliderAI4/6/202417/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vsourz Digital Responsive Slick Slider WordPress allows Code Injection.This issue affects Responsive Slick Slider WordPress: from n/a through 1.4.
AplazadaCrítica (9.8)0.65%—Minmax Digital Technology Minmax CMSAI30/5/202417/6/2026
MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access control restrictions and log in to the backend system without being recorded in the…
ModificadaAlta (7.5)0.64%—Sandhillsdev Easy Digital Downloads14/5/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.
ModificadaAlta (8.8)0.22%—Sandhillsdev Easy Digital Downloads14/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.
AplazadaAlta (7.8)0.49%💥 PoCPanoramic Corporation Digital Imaging SoftwareAI14/5/202417/6/2026
An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exe component.
AplazadaMedia (5.3)0.42%—Supsystic Digital PublicationsAI6/5/202417/6/2026
Missing Authorization vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.
AplazadaMedia (5.9)0.38%—Mrdigital Simple Image PopupAI2/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr Digital Simple Image Popup allows Stored XSS.This issue affects Simple Image Popup: from n/a through 2.4.0.
AplazadaMedia (4.3)0.21%—Supsystic Digital PublicationsAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.
ModificadaAlta (8.8)0.23%—Sandhillsdev Easy Digital Downloads12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.6.
AplazadaMedia (4.3)0.44%—Digitalbazaar ZcapAI10/4/202417/6/2026
`@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0.1, when invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the `expires` property is not properly checked against the current date or other `date`…
ModificadaMedia (5.3)0.60%—Awesomemotive Easy Digital Downloads9/4/202417/6/2026
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to download the debug log via Directory Listing.…
AplazadaMedia (6.5)0.35%—Interfacelab Media CloudAIAmazon S3AIImgixAIGoogle Cloud StorageAI+127/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Interfacelab Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and more allows Stored XSS.This issue affects Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and…
AplazadaAlta (7.1)0.42%—Madfishdigital Bulk Noindex AND Nofollow ToolkitAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Reflected XSS.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 2.01.
AplazadaMedia (6.5)0.41%—Snpdigital SaleskingAI26/3/202417/6/2026
Missing Authorization vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15.
AnalizadaAlta (7.8)0.21%—Dell Digital Delivery4/3/202417/6/2026
Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation.
AnalizadaAlta (7.8)0.20%—Dell Digital Delivery4/3/202417/6/2026
Dell Digital Delivery, versions prior to 5.2.0.0, contain a Use After Free Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to application crash or execution of arbitrary code.
AnalizadaMedia (5.4)0.61%—Liferay PortalLiferay Digital Experience Platform21/2/202417/6/2026
Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's…
AnalizadaMedia (5.4)0.47%—Liferay PortalLiferay Digital Experience Platform21/2/202417/6/2026
The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not escape user supplied data in the default notification email template, which allows remote authenticated users to inject…
AnalizadaMedia (6.1)0.56%—Liferay PortalLiferay Digital Experience Platform21/2/202417/6/2026
Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor…
AnalizadaMedia (5.4)0.56%—Liferay PortalLiferay Digital Experience Platform21/2/202417/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML…
AnalizadaMedia (5.4)0.56%—Liferay PortalLiferay Digital Experience Platform21/2/202417/6/2026
Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary…
AnalizadaMedia (6.1)0.61%—Liferay PortalLiferay Digital Experience Platform21/2/202417/6/2026
Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the…
AnalizadaMedia (6.1)0.61%—Liferay PortalLiferay Digital Experience Platform21/2/202417/6/2026
Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the…
AnalizadaMedia (6.1)0.62%—Liferay PortalLiferay Digital Experience Platform21/2/202417/6/2026
Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked…
AnalizadaMedia (5.4)0.62%—Liferay PortalLiferay Digital Experience Platform21/2/202417/6/2026
Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web…
Orbitaley — Vulnerabilidades