Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1221 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.40%—Digitaldruid Hoteldruid30/7/202417/6/2026
Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.
AplazadaCrítica (9.8)0.51%—Hangzhou Xiongwei Technology Development Restaurant Digital Comprehensive Management PlatformAI26/7/202417/6/2026
An issue in Hangzhou Xiongwei Technology Development Co., Ltd. Restaurant Digital Comprehensive Management platform v1 allows an attacker to bypass authentication and perform arbitrary password resets.
AplazadaMedia (6.5)0.32%—Calendar.onlineAIKalender.digitalAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Calendar.Online Calendar.Online / Kalender.Digital allows Stored XSS.This issue affects Calendar.Online / Kalender.Digital: from n/a through 1.0.8.
AplazadaMedia (5.9)0.32%—Sandisk IBIAIWesterndigital MY CloudAIWesterndigital MY Cloud HomeAIWesterndigital WD CloudAI24/6/202417/6/2026
A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found which could allow an attacker to redirect the user to a crafted domain and reset their credentials, or to execute arbitrary client-side code in the user’s browser session to carry out malicious…
ModificadaAlta (8.8)0.21%—Blazethemes Digital Newspaper21/6/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in blazethemes Digital Newspaper.This issue affects Digital Newspaper: from n/a through 1.1.5.
ModificadaCrítica (9.8)0.54%—Wow-company Easy Digital Downloads4/6/202417/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Easy Digital Downloads – Recent Purchases allows PHP Remote File Inclusion.This issue affects Easy Digital Downloads – Recent Purchases: from n/a through 1.0.2.
AplazadaMedia (6.5)0.36%—Vsourz Digital Responsive Slick SliderAI4/6/202417/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vsourz Digital Responsive Slick Slider WordPress allows Code Injection.This issue affects Responsive Slick Slider WordPress: from n/a through 1.4.
AplazadaCrítica (9.8)0.65%—Minmax Digital Technology Minmax CMSAI30/5/202417/6/2026
MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access control restrictions and log in to the backend system without being recorded in the…
ModificadaAlta (7.5)0.64%—Sandhillsdev Easy Digital Downloads14/5/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.
ModificadaAlta (8.8)0.22%—Sandhillsdev Easy Digital Downloads14/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.
AplazadaAlta (7.8)0.49%💥 PoCPanoramic Corporation Digital Imaging SoftwareAI14/5/202417/6/2026
An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exe component.
AplazadaMedia (5.3)0.42%—Supsystic Digital PublicationsAI6/5/202417/6/2026
Missing Authorization vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.
AplazadaMedia (5.9)0.38%—Mrdigital Simple Image PopupAI2/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr Digital Simple Image Popup allows Stored XSS.This issue affects Simple Image Popup: from n/a through 2.4.0.
AplazadaMedia (4.3)0.21%—Supsystic Digital PublicationsAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.
ModificadaAlta (8.8)0.23%—Sandhillsdev Easy Digital Downloads12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.6.
AplazadaMedia (4.3)0.44%—Digitalbazaar ZcapAI10/4/202417/6/2026
`@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0.1, when invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the `expires` property is not properly checked against the current date or other `date`…
ModificadaMedia (5.3)0.60%—Awesomemotive Easy Digital Downloads9/4/202417/6/2026
The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to download the debug log via Directory Listing.…
AplazadaMedia (6.5)0.35%—Interfacelab Media CloudAIAmazon S3AIImgixAIGoogle Cloud StorageAI+127/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Interfacelab Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and more allows Stored XSS.This issue affects Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and…
AplazadaAlta (7.1)0.42%—Madfishdigital Bulk Noindex AND Nofollow ToolkitAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Reflected XSS.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 2.01.
AplazadaMedia (6.5)0.41%—Snpdigital SaleskingAI26/3/202417/6/2026
Missing Authorization vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15.
AnalizadaAlta (7.8)0.21%—Dell Digital Delivery4/3/202417/6/2026
Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary code execution and/or privilege escalation.
AnalizadaAlta (7.8)0.20%—Dell Digital Delivery4/3/202417/6/2026
Dell Digital Delivery, versions prior to 5.2.0.0, contain a Use After Free Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to application crash or execution of arbitrary code.
AnalizadaMedia (5.4)0.61%—Liferay PortalLiferay Digital Experience Platform21/2/202417/6/2026
Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's…
AnalizadaMedia (5.4)0.47%—Liferay PortalLiferay Digital Experience Platform21/2/202417/6/2026
The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not escape user supplied data in the default notification email template, which allows remote authenticated users to inject…
AnalizadaMedia (6.1)0.56%—Liferay PortalLiferay Digital Experience Platform21/2/202417/6/2026
Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor…