Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
150 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.33% | — | Itron WP LoggerAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in iTRON WP Logger wp-data-logger allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Logger: from n/a through <= 2.2. | |
| Analizada | Alta (8.8) | 34% | — | NI Flexlogger | 18/3/2025 | 17/6/2026 | NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of NI FlexLogger. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Modificada | Alta (8.8) | 0.19% | — | Smerriman Login Logger | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in smerriman Login Logger login-logger allows Cross Site Request Forgery.This issue affects Login Logger: from n/a through <= 1.2.1. | |
| Analizada | Alta (8.8) | 1.6% | — | Nhairs Python Json Logger | 7/3/2025 | 17/6/2026 | Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was… | |
| Aplazada | Media (5.9) | 0.29% | — | Themelogger Contact Form 7 Star Rating With Font AwesomeAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelogger Contact Form 7 Star Rating with font Awesome contact-form-7-star-rating-with-font-awersome allows Stored XSS.This issue affects Contact Form 7 Star Rating with font Awesome: from n/a through <= 1.3. | |
| Aplazada | Media (5.9) | 0.29% | — | Themelogger Contact Form 7 Star RatingAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelogger Contact Form 7 Star Rating contact-form-7-star-rating allows Stored XSS.This issue affects Contact Form 7 Star Rating: from n/a through <= 1.10. | |
| Aplazada | Alta (7.5) | 0.57% | — | Eazy-loggerAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the lib.Logger function of eazy-logger v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Analizada | Media (6.1) | 0.26% | — | Suhas93 SEO Blogger TO Wordpress 301 Redirector | 23/1/2025 | 17/6/2026 | The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions up to, and including, 0.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.1) | 0.31% | — | Poco Blogger Image ImportAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poco Blogger Image Import allows Stored XSS.This issue affects Blogger Image Import: from 2.1 through n/a. | |
| Aplazada | Media (4.3) | 0.40% | — | Sparkle Themes Blogger BuzzAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Sparkle Themes Blogger Buzz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blogger Buzz: from n/a through 1.2.2. | |
| Aplazada | Alta (7.5) | 0.47% | — | Blogger 301 RedirectAI | 16/11/2024 | 17/6/2026 | The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (4.8) | 0.40% | — | TeslaloggerAI | 29/10/2024 | 17/6/2026 | Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitrary code via the New Journey field. | |
| Modificada | Media (5.5) | 0.24% | — | NI SystemlinkNI Flexlogger | 22/7/2024 | 17/6/2026 | An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosure via local access. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared… | |
| Modificada | Alta (7.8) | 0.27% | — | NI FlexloggerNI Systemlink | 22/7/2024 | 17/6/2026 | An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including CVE-2022-24834. This affects NI SystemLink Server 2024 Q1 and prior versions. It also affects NI FlexLogger 2023 Q2 and prior versions which installed this shared service. | |
| Aplazada | Alta (8.4) | 0.35% | — | Opentext Arcsight LoggerAI | 11/6/2024 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities could be remotely exploited. | |
| Aplazada | Alta (7.8) | 15% | — | NI FlexloggerAINI InstrumentstudioAI | 14/5/2024 | 17/6/2026 | A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects NI FlexLogger 2024 Q1 and prior… | |
| Analizada | Media (5.5) | 0.24% | — | Zemana Antilogger | 15/3/2024 | 17/6/2026 | Zemana AntiLogger v2.74.204.664 is vulnerable to a Denial of Service (DoS) vulnerability by triggering the 0x80002004 and 0x80002010 IOCTL codes of the zam64.sys and zamguard64.sys drivers. | |
| Analizada | Media (5.5) | 0.28% | — | Zemana Antilogger | 15/3/2024 | 17/6/2026 | Zemana AntiLogger v2.74.204.664 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x80002020 IOCTL code of the zam64.sys and zamguard64.sys drivers | |
| Aplazada | Media (5.5) | 0.20% | — | Zemana AntiloggerAI | 14/3/2024 | 17/6/2026 | Zemana AntiLogger v2.74.204.664 is vulnerable to an Arbitrary Process Termination vulnerability by triggering the 0x80002048 IOCTL code of the zam64.sys and zamguard64.sys drivers. | |
| Analizada | Alta (7.8) | 0.35% | — | Emerson Data Record ADEmerson FlexloggerEmerson G WEB Development SoftwareEmerson Labview NXG+4 | 20/2/2024 | 17/6/2026 | Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges. | |
| Analizada | Alta (7.8) | 0.27% | — | Emerson Data Record ADEmerson FlexloggerEmerson G WEB Development SoftwareEmerson Labview NXG+4 | 20/2/2024 | 17/6/2026 | Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.25% | — | NI Topografix Data PluginNI DiademNI VeristandNI Flexlogger | 8/11/2023 | 17/6/2026 | An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulnerability by getting a user to open a specially crafted data file. | |
| Modificada | Media (6.1) | 0.46% | — | Lanacodes Lana Email Logger | 12/7/2023 | 17/6/2026 | The Lana Email Logger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, Lana Email Logger due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Crítica (9.1) | 0.90% | — | Microfocus Arcsight Logger | 13/6/2023 | 17/6/2026 | Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0. | |
| Modificada | Media (6.1) | 0.47% | — | Microfocus Arcsight Logger | 13/6/2023 | 17/6/2026 | Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0 |