Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.44%—Madrasthemes MAS Static Content25/9/202417/6/2026
The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.8 via the static_content() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract potentially sensitive information from private static…
AnalizadaMedia (4.7)0.63%—Openjsf Serve-static10/9/202417/6/2026
serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.
ModificadaMedia (6.1)0.33%—Myrecorp Export WP Page TO Static Html/css20/6/202417/6/2026
The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.2.2. This is due to insufficient validation on the redirect url supplied via the rc_exported_zip_file parameter. This makes it possible for unauthenticated attackers to redirect users to…
AplazadaMedia (5.8)0.37%—Static-web-server Static WEB ServerAI1/5/202417/6/2026
Static Web Server (SWS) is a tiny and fast production-ready web server suitable to serve static web files or assets. In affected versions if directory listings are enabled for a directory that an untrusted user has upload privileges for, a malicious file name like `<img src=x onerror=alert(1)>.txt` will allow…
AplazadaAlta (7.5)2.0%—Simply StaticAI24/4/202417/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Simply Static Simply Static simply-static.This issue affects Simply Static: from n/a through <= 3.1.3.
AplazadaMedia (5.9)0.34%—Simply StaticAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simply Static Simply Static simply-static.This issue affects Simply Static: from n/a through <= 3.1.3.
AnalizadaAlta (7.8)0.35%—Emerson Data Record ADEmerson FlexloggerEmerson G WEB Development SoftwareEmerson Labview NXG+420/2/202417/6/2026
Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.
AnalizadaAlta (7.8)0.27%—Emerson Data Record ADEmerson FlexloggerEmerson G WEB Development SoftwareEmerson Labview NXG+420/2/202417/6/2026
Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.55%—Palantir Gotham Blackbird-witchcraftPalantir Gotham Static-assets-servlet29/1/202417/6/2026
Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
ModificadaMedia (5.4)0.45%—Myrecorp Export WP Page TO Static Html/css11/1/202417/6/2026
The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 2.1.9. This makes it possible for authenticated attackers, with subscriber-level access and…
ModificadaAlta (8.8)0.26%—Myrecorp Export WP Page TO Static Html/css10/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ReCorp Export WP Page to Static HTML/CSS plugin <= 2.1.9 versions.
ModificadaAlta (7.5)1.4%—Nbluis Static-server3/10/202317/6/2026
All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.
ModificadaCrítica (9.8)0.76%—Posthemes Posstaticblocks16/5/202317/6/2026
Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().
ModificadaCrítica (9.8)32%—Prestashop Poststaticfooter10/5/202317/6/2026
Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().
ModificadaMedia (5.3)0.99%—M.static Project M.static10/5/202317/6/2026
All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.
ModificadaAlta (7.5)1.4%—@nubosoftware/node-static Project @nubosoftware/node-staticNode-static Project Node-static6/3/202317/6/2026
All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.
ModificadaAlta (7.5)1.4%—Easy-static-server Project Easy-static-server20/12/202217/6/2026
All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.
ModificadaAlta (7.5)1.0%—Static-dev-server Project Static-dev-server29/11/202217/6/2026
This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory.
ModificadaMedia (5.4)0.30%—Static Page Extended Project Static Page Extended13/6/202217/6/2026
Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings
ModificadaMedia (6.1)0.56%—NI FlexloggerNI G WEB Development SoftwareNI LabviewNI Static Test Software Suite+121/4/202217/6/2026
There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3 or later, install FlexLogger 2022 Q2 or later, install LabVIEW 2021 SP1, install G Web Development…
ModificadaAlta (8.8)1.0%—Fastify-static14/10/202117/6/2026
A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox users to arbitrary websites via a double slash `//` followed by a domain: `http://localhost:3000//a//youtube.com/%2e%2e%2f%2e%2e`.A DOS vulnerability is possible if the URL contains…
ModificadaMedia (6.1)1.2%—Fastify-static14/10/202117/6/2026
A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications that set redirect: true option. By…
ModificadaAlta (7)0.36%—Late-static Project Late-static26/1/202117/6/2026
An issue was discovered in the late-static crate before 0.4.0 for Rust. Because Sync is implemented for LateStatic with T: Send, a data race can occur.
ModificadaMedia (5.4)0.72%—Jenkins Static Analysis Utilities4/11/202017/6/2026
Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
ModificadaAlta (7.6)1.6%—Osm-static-maps Project Osm-static-maps20/10/202017/6/2026
This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as an HTML on the page which gives…