Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

109 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.39%—Northern.tech Mender ServerAI26/6/202517/6/2026
Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.
ModificadaCrítica (9.8)0.40%—Northernbeacheswebsites Ideapush14/2/202517/6/2026
Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a through <= 8.71.
AplazadaCrítica (9.1)0.81%—Northern.tech Mender ClientAI21/1/202517/6/2026
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
AplazadaMedia (4.8)0.38%—Northern.tech Cfengine Enterprise Mission PortalAI21/1/202517/6/2026
Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allows XSS. The fixed versions are 3.24.1 and 3.21.6.
ModificadaMedia (5.4)0.48%—Northernbeacheswebsites Ideapush9/12/202417/6/2026
Missing Authorization vulnerability in Martin Gibson IdeaPush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a through n/a.
AplazadaMedia (4.3)0.37%—Northernbeacheswebsites WP Custom Admin InterfaceAI9/12/202417/6/2026
Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.31.
AnalizadaMedia (4.3)0.34%—Northernbeacheswebsites Ideapush3/12/202417/6/2026
The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idea_push_taxonomy_save_routine function in all versions up to, and including, 8.71. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete terms…
AplazadaBaja (2.7)0.28%—Northern.tech MenderAI8/11/202417/6/2026
Northern.tech Hosted Mender before 2024.07.11 allows SSRF.
ModificadaMedia (4.3)0.26%—Northern.tech Mender8/11/202417/6/2026
Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.
AplazadaMedia (6.5)0.39%—Northern.tech MenderAI8/11/202417/6/2026
Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF.
AplazadaMedia (4.3)0.40%—Northernbeacheswebsites WP GotowebinarAI1/11/202417/6/2026
Missing Authorization vulnerability in Martin Gibson WP GoToWebinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP GoToWebinar: from n/a through 15.6.
ModificadaAlta (8.8)0.21%—Northernbeacheswebsites Ideapush20/10/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Northern Beaches Websites IdeaPush ideapush allows Cross Site Request Forgery.This issue affects IdeaPush: from n/a through <= 8.69.
ModificadaMedia (4.8)0.28%—Northernbeacheswebsites Ideapush6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Northern Beaches Websites IdeaPush ideapush allows Stored XSS.This issue affects IdeaPush: from n/a through <= 8.66.
AplazadaAlta (7.1)0.16%—Northernbeacheswebsites WP GotowebinarAI2/8/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson WP GoToWebinar allows Cross-Site Scripting (XSS).This issue affects WP GoToWebinar: from n/a through 15.7.
ModificadaMedia (5.4)0.26%—Northernbeacheswebsites Ideapush22/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.60.
ModificadaMedia (6.1)0.33%—Northernbeacheswebsites Ideapush21/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.65.
AplazadaMedia (6.5)0.34%—Northernbeacheswebsites WP GotowebinarAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson WP GoToWebinar allows Stored XSS.This issue affects WP GoToWebinar: from n/a through 15.7.
AplazadaAlta (8.8)0.38%—Northern.tech MenderAI20/6/202417/6/2026
Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only user to a high-privileged user.
AplazadaMedia (6.5)0.32%—Northern.tech MenderAI20/6/202417/6/2026
Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.
AplazadaMedia (4.3)0.41%—Northernbeacheswebsites WP GotowebinarAI9/6/202417/6/2026
Missing Authorization vulnerability in Martin Gibson WP GoToWebinar.This issue affects WP GoToWebinar: from n/a through 14.46.
AplazadaCrítica (9.8)0.58%—Northern.tech Mender EnterpriseAI3/6/202417/6/2026
Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.
AplazadaAlta (8.8)78%💥 ExploitEgindemirbilek Northstar C2AI6/4/202417/6/2026
Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.
ModificadaAlta (7.5)0.63%—52north WPS19/12/202317/6/2026
An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.
ModificadaAlta (7.5)0.65%—Northern.tech Cfengine14/11/202317/6/2026
Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.
ModificadaMedia (4.8)0.39%—Northernbeacheswebsites Ideapush8/11/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson IdeaPush plugin <= 8.52 versions.
Orbitaley — Vulnerabilidades