Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.39% | — | Kognetiks Chatbot | 13/11/2024 | 17/6/2026 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Analizada | Media (4.3) | 0.54% | — | Kognetiks Chatbot | 13/11/2024 | 17/6/2026 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Analizada | Media (4.3) | 0.45% | — | Kognetiks Chatbot | 13/11/2024 | 17/6/2026 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_new_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Analizada | Media (5.3) | 0.54% | — | Kognetiks Chatbot | 13/11/2024 | 17/6/2026 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Alta (8.5) | 0.40% | — | Zohocorp Zoho CRM Lead MagnetAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows SQL Injection.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.7.9.7. | |
| Analizada | Alta (8) | 1.7% | — | Magnetforensics Axiom | 21/8/2024 | 17/6/2026 | Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Magnet Forensics AXIOM. User interaction is required to exploit this vulnerability in that the target must acquire data from a… | |
| Aplazada | Alta (7.1) | 0.32% | — | Zoho CRM Lead MagnetAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho CRM Zoho CRM Lead Magnet allows Reflected XSS.This issue affects Zoho CRM Lead Magnet: from n/a through 1.7.8.8. | |
| Modificada | Media (5.4) | 0.25% | — | Kognetics Kognetiks Chatbot | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kognetiks Kognetiks Chatbot for WordPress allows Stored XSS.This issue affects Kognetiks Chatbot for WordPress: from n/a through 1.9.8. | |
| Analizada | Alta (8.7) | 23% | — | Oringnet Iap-420 Firmware | 28/5/2024 | 17/6/2026 | Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue affects IAP-420 version 2.01e and below. | |
| Analizada | Alta (8.3) | 14% | — | Oringnet Iap-420 Firmware | 28/5/2024 | 17/6/2026 | Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below. | |
| Aplazada | Crítica (9.8) | 0.91% | — | Kognetiks ChatbotAI | 14/5/2024 | 17/6/2026 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_chatgpt_upload_file_to_assistant function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers, with to upload arbitrary files… | |
| Aplazada | Crítica (10) | 2.6% | 💥 PoC | Kognetiks ChatbotAI | 14/5/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue affects Kognetiks Chatbot for WordPress: from n/a through 2.0.0. | |
| Analizada | Alta (8) | 0.86% | — | Magnetforensics Axiom | 3/5/2024 | 17/6/2026 | Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Magnet Forensics AXIOM. User interaction is required to exploit this vulnerability in that the target must acquire data from a… | |
| Modificada | Media (4.3) | 0.37% | — | Magneticone Magento TO Woocommerce Migration | 17/1/2024 | 17/6/2026 | Missing Authorization vulnerability in MagneticOne Cart2Cart: Magento to WooCommerce Migration.This issue affects Cart2Cart: Magento to WooCommerce Migration: from n/a through 2.0.0. | |
| Modificada | Media (4.8) | 0.39% | — | Magneticlab Homepage Pop-up | 16/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Magneticlab Homepage Pop-up | 2/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions. | |
| Modificada | Media (6.5) | 3.3% | — | Zohocorp Zoho CRM Lead Magnet | 9/11/2022 | 17/6/2026 | Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress. | |
| Modificada | Crítica (9.8) | 0.91% | — | Oringnet Iap-420+ FirmwareOringnet Iap-420 Firmware | 21/10/2022 | 17/6/2026 | On ORing net IAP-420(+) with FW version 2.0m a telnet server is enabled by default and cannot permanently be disabled. You can connect to the device via LAN or WiFi with hardcoded credentials and get an administrative shell. These credentials are reset to defaults with every reboot. | |
| Modificada | Crítica (9.8) | 1.8% | — | Siemens Biograph Horizon Pet/ct Systems FirmwareSiemens Magnetom Numaris X FirmwareSiemens Mammomat Revelation FirmwareSiemens Naeotom Alpha Firmware+14 | 1/6/2022 | 17/6/2026 | A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40… | |
| Modificada | Media (5.4) | 1.1% | — | Zohocorp Zoho CRM Lead Magnet | 5/10/2021 | 17/6/2026 | A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenever… | |
| Modificada | Media (5.5) | 0.38% | — | Magnetic Project Magnetic | 31/12/2020 | 17/6/2026 | An issue was discovered in the magnetic crate before 2.0.1 for Rust. MPMCConsumer and MPMCProducer allow cross-thread sending of a non-Send type. | |
| Modificada | Alta (8.1) | 1.2% | — | Netscout Airmagnet Enterprise | 3/12/2020 | 17/6/2026 | NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be exploited to provide someone with administrative access to a sensor, with credentials to invoke a command to provide root access to the operating system. The attacker must complete a straightforward… | |
| Modificada | Media (5.4) | 1.1% | — | Zoho Lead Magnet | 26/11/2019 | 17/6/2026 | The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName. | |
| Modificada | Crítica (9.8) | 2.3% | — | Vignette Content Management | 31/1/2019 | 17/6/2026 | In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discovering the admin password in the vgn/ccb/user/mgmt/user/edit/0,1628,0,00.html?uid=admin HTML source code, and then creating a privileged user account. NOTE: this product is discontinued. | |
| Modificada | Alta (7.7) | 1.1% | — | Schneider-electric Imt25 Magnetic Flow DTM | 15/11/2015 | 17/6/2026 | Buffer overflow in Schneider Electric IMT25 Magnetic Flow DTM before 1.500.004 for the HART Protocol allows remote authenticated users to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HART reply. |