Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.21%—Catchsquare WP Social Widget22/9/202530/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget wp-social-widget allows Stored XSS.This issue affects WP Social Widget: from n/a through <= 2.3.1.
AnalizadaBaja (2.1)7.6%—Telesquare Tlr-2005ksh Firmware29/8/202517/6/2026
A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file /cgi-bin/internet.cgi?Command=lanCfg. Executing manipulation of the argument Hostname can lead to command injection. The attack may be performed from a remote location. The exploit has been publicly…
AplazadaMedia (4.3)0.13%—AJ Square INC RSS ReaderAI23/8/202517/6/2026
The Silencesoft RSS Reader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.6. This is due to missing or incorrect nonce validation on the 'sil_rss_edit_page' page. This makes it possible for unauthenticated attackers to delete RSS feeds via a forged request…
ModificadaMedia (5.4)0.25%—Catchsquare WP Social Widget6/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget wp-social-widget allows Stored XSS.This issue affects WP Social Widget: from n/a through <= 2.3.
AnalizadaAlta (7.5)0.46%—Telesquare Tlr-2005ksh Firmware26/3/202517/6/2026
Unauthorized stack overflow vulnerability in Telesquare TLR-2005KSH v.1.1.4 allows a remote attacker to obtain sensitive information via the systemutil.cgi component.
AnalizadaCrítica (9.8)0.44%—Telesquare Tlr-2005ksh Firmware26/3/202517/6/2026
Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setUsernamePassword.
AnalizadaCrítica (9.8)0.40%—Telesquare Tlr-2005ksh Firmware26/3/202517/6/2026
Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setUserNamePassword.
AnalizadaAlta (7.5)0.37%—Telesquare Tlr-2005ksh Firmware26/3/202517/6/2026
Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.
AnalizadaCrítica (9.8)0.44%—Telesquare Tlr-2005ksh Firmware26/3/202517/6/2026
In Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter with setSyncTimeHost.
AnalizadaCrítica (9.8)0.44%—Telesquare Tlr-2005ksh Firmware26/3/202517/6/2026
Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi.
AnalizadaCrítica (9.8)0.44%—Telesquare Tlr-2005ksh Firmware26/3/202517/6/2026
Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest.
AnalizadaCrítica (9.8)0.44%—Telesquare Tlr-2005ksh Firmware26/3/202517/6/2026
Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp.
AnalizadaCrítica (9.8)0.44%—Telesquare Tlr-2005ksh Firmware26/3/202517/6/2026
Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDdns.
AnalizadaCrítica (9.8)0.69%—Telesquare Tlr-2005ksh Firmware26/3/202517/6/2026
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.
AnalizadaCrítica (9.8)0.49%—Telesquare Tlr-2005ksh Firmware26/3/202517/6/2026
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost.
AnalizadaAlta (7.5)0.38%—Telesquare Tlr-2005ksh Firmware26/3/202517/6/2026
Telesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.
ModificadaMedia (5.4)0.28%—Catchsquare WP Social Widget24/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget wp-social-widget allows Stored XSS.This issue affects WP Social Widget: from n/a through <= 2.2.7.
AnalizadaCrítica (9.3)0.56%—Centralsquare Etrakit.net20/3/202517/6/2026
A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote unauthenticated attacker can run arbitrary commands as the current MS SQL server account. It is recommended that the CRM feature is turned off while on eTRAKiT.net release 3.2.1.77. eTRAKiT.Net is no…
AplazadaMedia (5.8)0.44%—Square WireAI16/3/202517/6/2026
Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReader.kt.
ModificadaMedia (6.1)0.37%—Nsquared Appointment Booking Calendar7/3/202517/6/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping. This makes it…
AplazadaAlta (7.1)0.39%—Dotsquaresltd Migrate PostsAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DotsquaresLtd Migrate Posts migrate-post allows Reflected XSS.This issue affects Migrate Posts: from n/a through <= 1.0.
AnalizadaMedia (6.5)0.43%—Wpexperts Givewp Square21/2/202517/6/2026
The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
AnalizadaMedia (5.4)0.41%—Vcita Online Payments - GET Paid With Paypal, Square & Stripe18/2/202517/6/2026
The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.20.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaAlta (7.1)0.37%—Limesquare Lime Developer LoginAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in limesquare Lime Developer Login lime-developer-login allows Reflected XSS.This issue affects Lime Developer Login: from n/a through <= 1.4.0.
AplazadaMedia (6.5)0.21%—Vcita Online Payments - GET Paid With Paypal Square AND StripeAI21/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Payments – Get Paid with PayPal, Square & Stripe paypal-payment-button-by-vcita allows Stored XSS.This issue affects Online Payments – Get Paid with PayPal, Square & Stripe: from n/a through <= 3.20.0.
Orbitaley — Vulnerabilidades