Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.40%—Geminilabs Site Reviews22/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions.
ModificadaMedia (4.8)0.50%—Geminilabs Site Reviews2/5/202317/6/2026
The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (6.1)0.79%—Resi Gemini-net2/6/202217/6/2026
resi-calltrace in RESI Gemini-Net 4.2 is affected by Multiple XSS issues. Unauthenticated remote attackers can inject arbitrary web script or HTML into an HTTP GET parameter that reflects user input without sanitization. This exists on numerous application endpoints,
ModificadaCrítica (9.8)1.7%—Resi Gemini-net12/5/202217/6/2026
resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are processed on the server. Due to the lack of validation of user input, an unauthenticated attacker can bypass the syntax intended by the software (e.g., concatenate `&|;\r\…
ModificadaMedia (5.3)0.88%—Resi Gemini-net12/5/202217/6/2026
RESI Gemini-Net Web 4.2 is affected by Improper Access Control in authorization logic. An unauthenticated user is able to access some critical resources.
ModificadaBaja (2.4)0.24%—Phillips Gemini 882300 FirmwarePhillips Gemini 882160 FirmwarePhillips Gemini 882400 FirmwarePhillips Gemini 882390 Firmware+723/3/202217/6/2026
Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control.
ModificadaMedia (6.1)1.3%—Geminilabs Site Reviews3/1/202217/6/2026
The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin
ModificadaMedia (5.4)0.62%—Geminilabs Site Reviews6/9/202117/6/2026
The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed
ModificadaMedia (6.1)1.3%—Geminilabs Site Reviews26/6/201817/6/2026
Cross-site scripting vulnerability in Site Reviews versions prior to 2.15.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)2.5%💥 ExploitArzdev Gemini LiteArzdev Gemini Portal21/8/200916/6/2026
admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to "admin" and setting the name parameter to "users."
ModificadaAlta (9.3)3.0%💥 ExploitArzdev Gemini Portal23/10/200816/6/2026
Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) page/forums/bottom.php and (2) page/forums/category.php.
ModificadaMedia (4.3)1.2%—Countersoft Gemini15/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in issue/createissue.aspx in Gemini 2.0 allows remote attackers to inject arbitrary web script or HTML via the rtcDescription$RadEditor1 field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Orbitaley — Vulnerabilidades