Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1236 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.55% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/7/2024 | 17/6/2026 | Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway | |
| Analizada | Alta (7.2) | 0.76% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/7/2024 | 17/6/2026 | Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler | |
| Analizada | Media (6.5) | 0.52% | — | Livemesh Elementor Addons | 6/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons for Elementor.This issue affects Livemesh Addons for Elementor: from n/a through 8.4.0. | |
| Modificada | Media (5.4) | 0.34% | — | Livemeshelementor Addons FOR Elementor | 4/7/2024 | 17/6/2026 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Posts Grid widget in all versions up to, and including, 8.3.7 due to insufficient input sanitization and output escaping on user supplied attributes like 'grid_skin'. This makes it possible for… | |
| Modificada | Media (5.4) | 0.34% | — | Livemeshelementor Addons FOR Elementor | 4/7/2024 | 17/6/2026 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Marquee Text Widget, Testimonials Widget, and Testimonial Slider widgets in all versions up to, and including, 8.4.1 due to insufficient input sanitization and output escaping on user supplied… | |
| Modificada | Media (5.4) | 0.43% | — | Livemeshelementor Addons FOR Elementor | 4/7/2024 | 17/6/2026 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 8.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.89% | — | Livemeshelementor Addons FOR Elementor | 4/7/2024 | 17/6/2026 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.4 via several of the plugin's widgets through the 'style' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute… | |
| Modificada | Media (6.9) | 0.68% | — | Clive 21 Simple Online Hotel Reservation System | 25/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Aplazada | Crítica (10) | 0.61% | — | Livechatpro Module Live Chat PROAI | 19/6/2024 | 17/6/2026 | In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token, the method `Lcp::saveTranslations()` suffer of a white writer that can inject PHP code into a PHP file. | |
| Aplazada | Alta (8.5) | 0.42% | — | Page Builder Live ComposerAI | 19/6/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.42. | |
| Modificada | Media (6.9) | 0.80% | — | Clive 21 Simple Online Hotel Reservation System | 18/6/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this issue is some unknown functionality of the file edit_room.php. The manipulation of the argument photo leads to unrestricted upload. The attack may be launched remotely. The… | |
| Modificada | Media (6.9) | 0.80% | — | Clive 21 Simple Online Hotel Reservation System | 18/6/2024 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file add_room.php. The manipulation of the argument photo leads to unrestricted upload. The attack can be launched remotely. The exploit has… | |
| Modificada | Media (5.4) | 0.31% | — | Liveboxcloud Vdesk | 10/6/2024 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. Stored Cross-site Scripting (XSS) can occur under the /api/v1/getbodyfile endpoint via the uri parameter. The web application (through its vShare functionality section) doesn't properly check parameters, sent in HTTP requests as input, before saving… | |
| Modificada | Media (6.5) | 0.50% | — | Liveboxcloud Vdesk | 10/6/2024 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application allows a user to generate or regenerate the backup codes before checking the… | |
| Modificada | Alta (7.5) | 0.29% | — | Olivethemes Olive ONE Click Demo Import | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. | |
| Aplazada | Media (5.3) | 0.36% | — | Octolize Usps Shipping FOR Woocommerce Live RatesAI | 9/6/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.This issue affects USPS Shipping for WooCommerce – Live Rates: from n/a through 1.9.4. | |
| Aplazada | Media (6.2) | 0.17% | — | Samsung Live Wallpaper PCAI | 4/6/2024 | 17/6/2026 | Arbitrary directory creation in Samsung Live Wallpaper PC prior to version 3.3.8.0 allows attacker to create arbitrary directory. | |
| Aplazada | Media (4.3) | 0.17% | — | Uploadcare File UploaderAIUploadcare Adaptive DeliveryAI | 1/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uploadcare.This issue affects Uploadcare File Uploader and Adaptive Delivery (beta): from n/a through 3.0.11. | |
| Modificada | Alta (8.8) | 0.75% | — | Liveboxcloud Vdesk | 28/5/2024 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShare web site section. A remote user, authenticated to the product, can arbitrarily upload potentially dangerous files without restrictions. | |
| Aplazada | Media (5.1) | 1.9% | — | Huashi Private Cloud CDN Live Streaming Acceleration ServerAI | 23/5/2024 | 17/6/2026 | A vulnerability was found in Huashi Private Cloud CDN Live Streaming Acceleration Server up to 20240520. It has been classified as critical. Affected is an unknown function of the file /manager/ipconfig_new.php. The manipulation of the argument dev leads to os command injection. It is possible to launch the attack… | |
| Analizada | Alta (7.2) | 0.64% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1. | |
| Aplazada | Crítica (9.8) | 0.54% | — | Powerfulwp Local Delivery Drivers FOR WoocommerceAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in powerfulwp Local Delivery Drivers for WooCommerce allows Privilege Escalation.This issue affects Local Delivery Drivers for WooCommerce: from n/a through 1.9.0. | |
| Aplazada | Media (5.9) | 0.44% | — | Orchestrated Corona Virus Covid-19 Banner AND Live DataAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Orchestrated Corona Virus (COVID-19) Banner & Live Data allows Stored XSS.This issue affects Corona Virus (COVID-19) Banner & Live Data: from n/a through 1.8.0.2. | |
| Aplazada | Media (4.3) | 0.34% | — | Tychesoftwares Print Invoice AND Delivery Notes FOR WoocommerceAITychesoftwares Arconix ShortcodesAITychesoftwares Arconix FAQAI | 8/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ:… | |
| Aplazada | Media (5.9) | 0.36% | — | Wppool Sheets TO WP Table Live SyncAI | 6/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Sheets To WP Table Live Sync allows Stored XSS.This issue affects Sheets To WP Table Live Sync: from n/a through 3.7.0. |