Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

82 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.19%—Stylemixthemes Pearl Header BuilderAI1/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Stylemix Pearl pearl-header-builder allows Cross Site Request Forgery.This issue affects Pearl: from n/a through <= 1.3.9.
AplazadaAlta (8.1)1.0%—Stylemixthemes Pearl Corporate BusinessAI26/3/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Pearl - Corporate Business pearl allows PHP Local File Inclusion.This issue affects Pearl - Corporate Business: from n/a through < 3.4.8.
AnalizadaCrítica (9.8)0.52%—A54552239 Pearprojectapi21/1/202517/6/2026
pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the organizationCode parameter at project.php.
AnalizadaCrítica (9.8)0.52%—A54552239 Pearprojectapi21/1/202517/6/2026
pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the projectCode parameter at project.php.
AplazadaMedia (4.3)0.17%—PearlAI9/1/202517/6/2026
The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This is due to missing or incorrect nonce validation on the stm_header_builder page. This makes it possible for unauthenticated attackers to delete arbitrary headers…
AplazadaMedia (6.5)0.37%—Sherkspear ADD Ribbon ShortcodeAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SherkSpear Add Ribbon Shortcode add-ribbon allows DOM-Based XSS.This issue affects Add Ribbon Shortcode: from n/a through <= 1.0.1.
ModificadaMedia (5.3)0.52%—Pearadmin Pear Admin Boot23/6/202417/6/2026
A vulnerability classified as critical has been found in Pear Admin Boot up to 2.0.2. Affected is an unknown function of the file /system/dictData/loadDictItem. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.…
ModificadaMedia (5.3)0.52%—Pearadmin Pear Admin Boot21/6/202417/6/2026
A vulnerability was found in Pear Admin Boot up to 2.0.2 and classified as critical. This issue affects the function getDictItems of the file /system/dictData/getDictItems/. The manipulation with the input ,user(),1,1 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
AplazadaMedia (6.5)0.37%—PearlAI12/6/202417/6/2026
The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to unauthorized site option deletion due to a missing validation and capability checks on the stm_hb_delete() function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to delete arbitrary…
AplazadaMedia (6.4)0.49%—PearlAI2/5/202417/6/2026
The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_hb' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
ModificadaAlta (8.8)0.80%—Pearadmin Pear Admin Think11/8/202317/6/2026
SQL Injection in pear-admin-think version 2.1.2, allows attackers to execute arbitrary code and escalate privileges via crafted GET request to Crud.php.
ModificadaAlta (8.8)0.26%—Stylemixthemes Pearl Header Builder25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes WordPress Header Builder Plugin – Pearl plugin <= 1.3.4 versions.
ModificadaMedia (5.4)0.40%—Pearadmin Pear Admin Boot25/4/202317/6/2026
A cross-site scripting (XSS) vulnerability in Pear-Admin-Boot up to v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title of a private message.
ModificadaAlta (7.5)0.64%—Centralite Pearl Firmware17/3/202317/6/2026
A vulnerability in Centralite Pearl Thermostat 0x04075010 allows attackers to cause a Denial of Service (DoS) via a crafted Zigbee message.
ModificadaMedia (6.1)0.55%—Pear Programming Project Pear Programming7/1/202317/6/2026
A vulnerability has been found in ss15-this-is-sparta and classified as problematic. This vulnerability affects unknown code of the file js/roomElement.js of the component Main Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is…
ModificadaCrítica (9.8)1.3%—PHP Pearweb15/4/202217/6/2026
pearweb < 1.32 suffers from Deserialization of Untrusted Data.
ModificadaCrítica (9.8)1.2%—PHP Pearweb15/4/202217/6/2026
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
ModificadaMedia (5.4)0.56%—Pearadmin Pear Admin Think29/3/202217/6/2026
A Cross Site Scripting (XSS) vulnerability exists in pearadmin pear-admin-think <=5.0.6, which allows a login account to access arbitrary functions and cause stored XSS through a fake User-Agent.
ModificadaMedia (5.3)0.85%—Pear Crypt GPG17/2/202217/6/2026
The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environments and GPG versions.
ModificadaCrítica (9.8)1.6%—Pearadmin Think12/8/202117/6/2026
Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can be uploaded via admin.php/index/upload because app/common/service/UploadService.php mishandles fileExt.
ModificadaAlta (7.8)0.45%—Pearson VUE Testing System4/1/202117/6/2026
The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" directory, which allows local users to obtain administrative privileges via a Trojan horse application.
ModificadaMedia (5.4)1.4%—Ipear Project Ipear14/7/202017/6/2026
In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developers" are affected. This function allows executing any PHP code within iPear which may change, damage, or steal data (files) from the PC.
ModificadaMedia (4.8)0.56%—Pearson Esis Enterprise Student Information System8/1/202017/6/2026
Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user input
ModificadaAlta (8.8)19%💥 ExploitPHP Pear Archive TARCanonical Ubuntu LinuxDebian Linux28/12/201817/6/2026
PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific prefix path, we can trigger unserialization…
ModificadaMedia (6.7)0.31%—Pearsonvue Console 8Pearsonvue Iqsystem 73/8/201817/6/2026
The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processes and consequently launches Internet Explorer or Microsoft Edge as Administrator, which allows local users to gain privileges.
Orbitaley — Vulnerabilidades