Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
109 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.39% | — | Northern.tech Mender ServerAI | 26/6/2025 | 17/6/2026 | Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 0.40% | — | Northernbeacheswebsites Ideapush | 14/2/2025 | 17/6/2026 | Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a through <= 8.71. | |
| Aplazada | Crítica (9.1) | 0.81% | — | Northern.tech Mender ClientAI | 21/1/2025 | 17/6/2026 | Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions. | |
| Aplazada | Media (4.8) | 0.38% | — | Northern.tech Cfengine Enterprise Mission PortalAI | 21/1/2025 | 17/6/2026 | Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allows XSS. The fixed versions are 3.24.1 and 3.21.6. | |
| Modificada | Media (5.4) | 0.48% | — | Northernbeacheswebsites Ideapush | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson IdeaPush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a through n/a. | |
| Aplazada | Media (4.3) | 0.37% | — | Northernbeacheswebsites WP Custom Admin InterfaceAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.31. | |
| Analizada | Media (4.3) | 0.34% | — | Northernbeacheswebsites Ideapush | 3/12/2024 | 17/6/2026 | The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idea_push_taxonomy_save_routine function in all versions up to, and including, 8.71. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete terms… | |
| Aplazada | Baja (2.7) | 0.28% | — | Northern.tech MenderAI | 8/11/2024 | 17/6/2026 | Northern.tech Hosted Mender before 2024.07.11 allows SSRF. | |
| Modificada | Media (4.3) | 0.26% | — | Northern.tech Mender | 8/11/2024 | 17/6/2026 | Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control. | |
| Aplazada | Media (6.5) | 0.39% | — | Northern.tech MenderAI | 8/11/2024 | 17/6/2026 | Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF. | |
| Aplazada | Media (4.3) | 0.40% | — | Northernbeacheswebsites WP GotowebinarAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson WP GoToWebinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP GoToWebinar: from n/a through 15.6. | |
| Modificada | Alta (8.8) | 0.21% | — | Northernbeacheswebsites Ideapush | 20/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Northern Beaches Websites IdeaPush ideapush allows Cross Site Request Forgery.This issue affects IdeaPush: from n/a through <= 8.69. | |
| Modificada | Media (4.8) | 0.28% | — | Northernbeacheswebsites Ideapush | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Northern Beaches Websites IdeaPush ideapush allows Stored XSS.This issue affects IdeaPush: from n/a through <= 8.66. | |
| Aplazada | Alta (7.1) | 0.16% | — | Northernbeacheswebsites WP GotowebinarAI | 2/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson WP GoToWebinar allows Cross-Site Scripting (XSS).This issue affects WP GoToWebinar: from n/a through 15.7. | |
| Modificada | Media (5.4) | 0.26% | — | Northernbeacheswebsites Ideapush | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.60. | |
| Modificada | Media (6.1) | 0.33% | — | Northernbeacheswebsites Ideapush | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.65. | |
| Aplazada | Media (6.5) | 0.34% | — | Northernbeacheswebsites WP GotowebinarAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson WP GoToWebinar allows Stored XSS.This issue affects WP GoToWebinar: from n/a through 15.7. | |
| Aplazada | Alta (8.8) | 0.38% | — | Northern.tech MenderAI | 20/6/2024 | 17/6/2026 | Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only user to a high-privileged user. | |
| Aplazada | Media (6.5) | 0.32% | — | Northern.tech MenderAI | 20/6/2024 | 17/6/2026 | Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information. | |
| Aplazada | Media (4.3) | 0.41% | — | Northernbeacheswebsites WP GotowebinarAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson WP GoToWebinar.This issue affects WP GoToWebinar: from n/a through 14.46. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Northern.tech Mender EnterpriseAI | 3/6/2024 | 17/6/2026 | Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication. | |
| Aplazada | Alta (8.8) | 78% | 💥 Exploit | Egindemirbilek Northstar C2AI | 6/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component. | |
| Modificada | Alta (7.5) | 0.63% | — | 52north WPS | 19/12/2023 | 17/6/2026 | An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network. | |
| Modificada | Alta (7.5) | 0.65% | — | Northern.tech Cfengine | 14/11/2023 | 17/6/2026 | Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub. | |
| Modificada | Media (4.8) | 0.39% | — | Northernbeacheswebsites Ideapush | 8/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson IdeaPush plugin <= 8.52 versions. |