Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.26% | — | Saintsystems Disable User Login | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saint Systems Disable User Login.This issue affects Disable User Login: from n/a through 1.3.7. | |
| Modificada | Alta (8.8) | 0.28% | — | Saas Disabler | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saas Disabler allows Cross Site Request Forgery.This issue affects Disabler: from n/a through 3.0.3. | |
| Modificada | Alta (7.5) | 0.92% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 5/8/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to absolute path traversal. The attack may be… | |
| Modificada | Media (5.3) | 1.1% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 5/8/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file \Service\FileDownload.ashx. The manipulation of the argument Files leads to path traversal: '../filedir'. The attack can be initiated remotely. The… | |
| Modificada | Crítica (9.8) | 0.90% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 21/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file /Service/FileHandler.ashx. The manipulation of the argument userFile leads to unrestricted upload. The exploit has been disclosed to the public and… | |
| Modificada | Baja (3.7) | 0.67% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 21/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This affects an unknown part of the file /Service/ImageStationDataService.asmx of the component File Name Handler. The manipulation leads to insufficiently random values. The complexity of an… | |
| Modificada | Crítica (9.8) | 0.95% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 21/7/2023 | 17/6/2026 | A vulnerability was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Controller/Ajaxfileupload.ashx. The manipulation of the argument file leads to unrestricted upload. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.89% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 20/7/2023 | 17/6/2026 | A vulnerability has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0 and classified as critical. This vulnerability affects unknown code of the file /App_Resource/UEditor/server/upload.aspx. The manipulation of the argument file leads to unrestricted upload. The exploit has been disclosed… | |
| Modificada | Alta (8.8) | 0.88% | — | Istrong Four Mountain Torrent Disaster Prevention, Control Monitoring AND Early Warning System | 20/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System up to 20230712. This affects an unknown part of the file /Duty/AjaxHandle/UploadFloodPlanFileUpdate.ashx. The manipulation of the argument Filedata… | |
| Modificada | Crítica (9.8) | 0.96% | — | Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System | 11/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This issue affects some unknown processing of the file /Duty/AjaxHandle/UpLoadFloodPlanFile.ashx of the component UpLoadFloodPlanFile. The manipulation… | |
| Modificada | Crítica (9.8) | 0.96% | — | Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System | 11/7/2023 | 17/6/2026 | A vulnerability classified as critical was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This vulnerability affects unknown code of the file /Duty/AjaxHandle/Write/UploadFile.ashx of the component Duty Write-UploadFile. The manipulation of the argument… | |
| Modificada | Crítica (9.8) | 0.91% | — | Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System | 11/7/2023 | 17/6/2026 | A vulnerability was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230704. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Duty/AjaxHandle/UploadHandler.ashx of the component Duty Module. The manipulation of the… | |
| Modificada | Media (6.5) | 0.22% | — | Disable Wordpress Update Notifications AND Auto-update Email Notifications Project Disable Wordpress Update Notifications AND Auto-update Email Notifications | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Prem Tiwari Disable WordPress Update Notifications and auto-update Email Notifications plugin <= 2.3.3 versions. | |
| Modificada | Media (6.5) | 0.33% | — | Enable/disable Auto Login When Register Project Enable/disable Auto Login When Register | 8/5/2023 | 17/6/2026 | The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Alta (8.8) | 0.37% | — | Phpredisadmin Project Phpredisadmin | 21/12/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.18.0 is able to address this issue. The name of the patch is… | |
| Modificada | Crítica (9.8) | 0.81% | — | Phpredisadmin Project Phpredisadmin | 19/12/2022 | 17/6/2026 | A vulnerability was found in phpRedisAdmin up to 1.16.1. It has been classified as problematic. This affects the function authHttpDigest of the file includes/login.inc.php. The manipulation of the argument response leads to use of wrong operator in string comparison. Upgrading to version 1.16.2 is able to address this… | |
| Modificada | Media (5.3) | 0.45% | — | Brainvire Disable User Login | 10/10/2022 | 17/6/2026 | The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will. | |
| Modificada | Alta (8.8) | 0.41% | — | Disable Right Click FOR WP Wordpress Disable Right Click FOR WP | 20/5/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Aftab Muni's Disable Right Click For WP plugin <= 1.1.6 at WordPress. | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (6.1) | 0.66% | — | Phpredisadmin Project Phpredisadmin | 16/10/2020 | 17/6/2026 | phpRedisAdmin before 1.13.2 allows XSS via the login.php username parameter. | |
| Modificada | Media (4.3) | 0.53% | — | Freepbx Disa | 20/6/2019 | 17/6/2026 | FreePBX 13 and 14 has SQL Injection in the DISA module via the hangup variable on the /admin/config.php?display=disa&view=form page. | |
| Modificada | Alta (7.8) | 1.2% | — | Cryptic-apps Hopper Disassembler | 4/6/2018 | 17/6/2026 | An exploitable out of bounds write vulnerability exists in the parsing of ELF Section Headers of Hopper Disassembler 3.11.20. A specially crafted ELF file can cause attacker controlled pointer arithmetic resulting in a partially controlled out of bounds write. An attacker can craft an ELF file with specific section… | |
| Modificada | Alta (8.8) | 1.6% | — | Disable Comments Project | 19/3/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that enable comments via a request to the disable_comments_settings page to wp-admin/options-general.php. | |
| Modificada | Media (5.5) | 7.5% | 💥 Exploit | Apng Disassembler Project Apng Disassembler | 20/2/2018 | 17/6/2026 | Buffer overflow in APNGDis 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted image containing a malformed image size descriptor in the IHDR chunk. | |
| Modificada | Media (5.5) | 6.9% | 💥 Exploit | Apng Disassembler Project Apng Disassembler | 20/2/2018 | 17/6/2026 | Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arbitrary code via a crafted image containing a malformed chunk size descriptor. |