Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.37% | — | Jobair JB Horizontal Scroller News TickerAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jobair JB Horizontal Scroller News Ticker jb-horizontal-scroller-news-ticker allows DOM-Based XSS.This issue affects JB Horizontal Scroller News Ticker: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.37% | — | Mikakaltoft Horizontal Line ShortcodeAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mikakaltoft Horizontal Line Shortcode horizontal-line-shortcode allows Stored XSS.This issue affects Horizontal Line Shortcode: from n/a through <= 1.0. | |
| Aplazada | Media (6.4) | 0.45% | — | Horizontal Scroll Image SlideshowAI | 12/12/2024 | 17/6/2026 | The Horizontal scroll image slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'horizontal-scroll-image-slideshow' shortcode in all versions up to, and including, 10.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (5.9) | 0.32% | — | Gopiplus Image Horizontal Reel Scroll SlideshowAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Image horizontal reel scroll slideshow image-horizontal-reel-scroll-slideshow allows Stored XSS.This issue affects Image horizontal reel scroll slideshow: from n/a through <= 13.4. | |
| Aplazada | Alta (7.1) | 0.29% | — | Exthemes WP Timeline Vertical AND Horizontal TimelineAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin wp-timelines allows Reflected XSS.This issue affects WP Timeline – Vertical and Horizontal timeline plugin: from n/a through <= 3.6.7. | |
| Aplazada | Alta (7.5) | 0.51% | — | Exthemes WP Timeline Vertical AND Horizontal TimelineAI | 5/10/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin wp-timelines.This issue affects WP Timeline – Vertical and Horizontal timeline plugin: from n/a through <= 3.6.7. | |
| Aplazada | Alta (8.8) | 0.61% | — | Horizontal Scrolling AnnouncementsAI | 6/8/2024 | 17/6/2026 | The Horizontal scrolling announcements plugin for WordPress is vulnerable to SQL Injection via the plugin's 'hsas-shortcode' shortcode in versions up to, and including, 2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Modificada | Alta (7.5) | 0.44% | — | Horizoncloud Caterease | 2/8/2024 | 5/7/2026 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information. | |
| Modificada | Crítica (9.8) | 1.5% | — | Horizoncloud Caterease | 2/8/2024 | 5/7/2026 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges. | |
| Modificada | Crítica (9.8) | 0.78% | — | Horizoncloud Caterease | 2/8/2024 | 5/7/2026 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command. | |
| Modificada | Media (6.8) | 0.19% | — | Horizoncloud Caterease | 2/8/2024 | 5/7/2026 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform a Password Brute Forcing attack due to improper restriction of excessive authentication attempts. | |
| Modificada | Crítica (9.8) | 0.65% | — | Horizoncloud Caterease | 2/8/2024 | 5/7/2026 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel. | |
| Modificada | Alta (7.5) | 0.53% | — | Horizoncloud Caterease | 2/8/2024 | 5/7/2026 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using known operating system credentials due to hardcoded SQL user credentials in the client application. | |
| Modificada | Alta (7.8) | 0.18% | — | Horizoncloud Caterease | 2/8/2024 | 5/7/2026 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack due to improperly implemented security checks for standard authentication mechanisms | |
| Modificada | Crítica (9.1) | 0.35% | — | Horizoncloud Caterease | 2/8/2024 | 5/7/2026 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation. | |
| Modificada | Crítica (9.8) | 0.82% | — | Horizoncloud Caterease | 2/8/2024 | 5/7/2026 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command. | |
| Modificada | Alta (7.5) | 0.44% | — | Horizoncloud Caterease | 2/8/2024 | 5/7/2026 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Rainbow Table Password cracking attack due to the use of one-way hashes without salts when storing user passwords. | |
| Analizada | Alta (8.4) | 0.21% | — | Horizoncloud Caterease | 2/8/2024 | 17/6/2026 | An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks. | |
| Aplazada | Alta (7.7) | 0.60% | — | OpencomputersAIGregtech NEW HorizonsAI | 16/4/2024 | 17/6/2026 | OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. A user can use OpenComputers to get a Computer thread stuck in the Lua VM, which eventually blocks the Server thread, requiring the server to be forcibly shut down. This can be accomplished using any device in the mod and can be… | |
| Aplazada | Media (6.5) | 0.31% | — | I13websolution WP Responsive Tabs Horizontal Vertical AND Accordion TabsAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs allows Stored XSS.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17. | |
| Modificada | Media (5.4) | 0.45% | — | Gopiplus Image Horizontal Reel Scroll Slideshow | 19/12/2023 | 17/6/2026 | The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ihrss-gallery' shortcode in versions up to, and including, 13.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Modificada | Media (6.1) | 0.43% | — | Opennms HorizonOpennms Meridian | 16/11/2023 | 17/6/2026 | Cross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session information. The solution is to upgrade to Horizon 32.0.5 or newer and Meridian 2023.1.9 or newer Meridian and Horizon installation instructions state that they are intended for… | |
| Modificada | Media (6.5) | 1.5% | 💥 PoC | Gopiplus Image Horizontal Reel Scroll Slideshow | 31/10/2023 | 17/6/2026 | The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.91% | — | Gopiplus Horizontal Scrolling Announcement | 20/10/2023 | 17/6/2026 | The Horizontal scrolling announcement plugin for WordPress is vulnerable to SQL Injection via the plugin's [horizontal-scrolling] shortcode in versions up to, and including, 9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Modificada | Media (4.8) | 0.39% | — | Gopiplus Tiny Carosel Horizontal Slider | 16/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Tiny Carousel Horizontal Slider plugin <= 8.1 versions. |