Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 2.2% | 💥 PoC | Spicethemes Newscrunch | 4/3/2025 | 17/6/2026 | The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload… | |
| Analizada | Alta (8.8) | 0.53% | 💥 PoC | Spicethemes Newscrunch | 4/3/2025 | 17/6/2026 | The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation on the newscrunch_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files via a… | |
| Analizada | Baja (2.4) | 0.32% | — | Authzed Spicedb | 14/10/2024 | 17/6/2026 | SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have enabled `LookupResources2` and have caveats in the evaluation path for their requests can return a permissionship of `CONDITIONAL` with context… | |
| Aplazada | Media (5.3) | 0.33% | — | Spicethemes Spice Starter SitesAI | 1/10/2024 | 17/6/2026 | The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to import demo content. | |
| Analizada | Media (5.3) | 0.29% | — | Authzed Spicedb | 18/9/2024 | 17/6/2026 | spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple caveats over the same indirect subject type on the same relation can result in no permission being returned when permission is expected. If the resource has multiple groups,… | |
| Modificada | Media (6.1) | 0.27% | — | Spicethemes Spice Starter Sites | 18/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spicethemes Spice Starter Sites spice-starter-sites allows Reflected XSS.This issue affects Spice Starter Sites: from n/a through <= 1.2.5. | |
| Analizada | Media (5.3) | 0.40% | — | Authzed Spicedb | 20/6/2024 | 17/6/2026 | Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Use of an exclusion under an arrow that has multiple resources may resolve to `NO_PERMISSION` when permission is expected. If the resource exists under *multiple* folders and the… | |
| Analizada | Media (4.3) | 0.58% | — | Authzed Spicedb | 10/4/2024 | 17/6/2026 | SpiceDB is a graph database purpose-built for storing and evaluating access control data. Use of a relation of the form: `relation folder: folder | folder#parent` with an arrow such as `folder->view` can cause LookupSubjects to only return the subjects found under subjects for either `folder` or `folder#parent`. This… | |
| Analizada | Crítica (9.1) | 0.46% | — | Authzed Spicedb | 1/3/2024 | 17/6/2026 | SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Integer overflow in chunking helper causes dispatching to miss elements or panic. Any SpiceDB cluster with any schema where a resource being checked has more than 65535 relationships for… | |
| Modificada | Alta (8.8) | 2.0% | 💥 PoC | Spiceworks Help Desk Server | 9/11/2023 | 17/6/2026 | An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort parameter. This can be leveraged to leak… | |
| Modificada | Media (6.5) | 0.40% | — | Authzed Spicedb | 31/10/2023 | 17/6/2026 | SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.27.0-rc1, when the provided datastore URI is malformed (e.g. by having a password which contains `:`) the full URI (including the provided password) is printed, so that… | |
| Modificada | Media (5.4) | 0.52% | — | Spicethemes Carousel, Recent Post Slider AND Banner Slider | 30/10/2023 | 17/6/2026 | The Carousel, Recent Post Slider and Banner Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'spice_post_slider' shortcode in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.34% | — | Hallowelt Bluespice | 30/10/2023 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context. | |
| Modificada | Alta (8.6) | 0.84% | — | Spice-space Spice-server | 22/8/2023 | 17/6/2026 | An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects. | |
| Modificada | Media (5.3) | 0.45% | — | Authzed Spicedb | 26/6/2023 | 17/6/2026 | SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. Any user making a negative authorization decision based on the results of a `LookupResources` request with 1.22.0 is affected. For example, using `LookupResources` to find a list of… | |
| Modificada | Alta (7.5) | 0.76% | — | Authzed Spicedb | 14/4/2023 | 17/6/2026 | SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. The `spicedb serve` command contains a flag named `--grpc-preshared-key` which is used to protect the gRPC API from being accessed by unauthorized requests. The values of this flag… | |
| Modificada | Media (5.4) | 0.27% | — | Hallowelt Bluespice | 15/11/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in BlueSpiceBookshelf extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the book navigation. | |
| Modificada | Media (5.4) | 0.27% | — | Hallowelt Bluespice | 15/11/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in BlueSpiceSocialProfile extension of BlueSpice allows user with comment permissions to inject arbitrary HTML into the comment section of a wikipage. | |
| Modificada | Media (5.4) | 0.27% | — | Hallowelt Bluespice | 15/11/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in BlueSpiceFoundation extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the history view of a wikipage. | |
| Modificada | Media (5.4) | 0.27% | — | Hallowelt Bluespice | 15/11/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows logged in user with edit permissions to inject arbitrary HTML into the default page header of a wikipage. | |
| Modificada | Media (4.8) | 0.28% | — | Hallowelt Bluespice | 15/11/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows user with admin privileges to inject arbitrary HTML into the main navigation of the application. | |
| Modificada | Media (5.4) | 0.27% | — | Hallowelt Bluespice | 15/11/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the personal menu navigation of their own and other users. This allows for targeted attacks. | |
| Modificada | Media (6.1) | 0.29% | — | Hallowelt BluespiceHallowelt Common User Interface | 15/11/2022 | 17/6/2026 | Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output arbitrary HTML (XSS). | |
| Modificada | Media (4.8) | 0.28% | — | Hallowelt Bluespice | 15/11/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in BlueSpiceCustomMenu extension of BlueSpice allows user with admin permissions to inject arbitrary HTML into the custom menu navigation of the application. | |
| Modificada | Media (6.1) | 0.45% | — | Hallowelt Bluespice | 22/7/2022 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to inject arbitrary HTML into a page using the title parameter of the call URL. |