Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.44% | — | Madrasthemes MAS Static Content | 25/9/2024 | 17/6/2026 | The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.8 via the static_content() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract potentially sensitive information from private static… | |
| Analizada | Media (4.7) | 0.63% | — | Openjsf Serve-static | 10/9/2024 | 17/6/2026 | serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0. | |
| Modificada | Media (6.1) | 0.33% | — | Myrecorp Export WP Page TO Static Html/css | 20/6/2024 | 17/6/2026 | The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.2.2. This is due to insufficient validation on the redirect url supplied via the rc_exported_zip_file parameter. This makes it possible for unauthenticated attackers to redirect users to… | |
| Aplazada | Media (5.8) | 0.37% | — | Static-web-server Static WEB ServerAI | 1/5/2024 | 17/6/2026 | Static Web Server (SWS) is a tiny and fast production-ready web server suitable to serve static web files or assets. In affected versions if directory listings are enabled for a directory that an untrusted user has upload privileges for, a malicious file name like `<img src=x onerror=alert(1)>.txt` will allow… | |
| Aplazada | Alta (7.5) | 2.0% | — | Simply StaticAI | 24/4/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Simply Static Simply Static simply-static.This issue affects Simply Static: from n/a through <= 3.1.3. | |
| Aplazada | Media (5.9) | 0.34% | — | Simply StaticAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simply Static Simply Static simply-static.This issue affects Simply Static: from n/a through <= 3.1.3. | |
| Analizada | Alta (7.8) | 0.35% | — | Emerson Data Record ADEmerson FlexloggerEmerson G WEB Development SoftwareEmerson Labview NXG+4 | 20/2/2024 | 17/6/2026 | Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges. | |
| Analizada | Alta (7.8) | 0.27% | — | Emerson Data Record ADEmerson FlexloggerEmerson G WEB Development SoftwareEmerson Labview NXG+4 | 20/2/2024 | 17/6/2026 | Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.55% | — | Palantir Gotham Blackbird-witchcraftPalantir Gotham Static-assets-servlet | 29/1/2024 | 17/6/2026 | Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system. | |
| Modificada | Media (5.4) | 0.45% | — | Myrecorp Export WP Page TO Static Html/css | 11/1/2024 | 17/6/2026 | The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 2.1.9. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Modificada | Alta (8.8) | 0.26% | — | Myrecorp Export WP Page TO Static Html/css | 10/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ReCorp Export WP Page to Static HTML/CSS plugin <= 2.1.9 versions. | |
| Modificada | Alta (7.5) | 1.4% | — | Nbluis Static-server | 3/10/2023 | 17/6/2026 | All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js. | |
| Modificada | Crítica (9.8) | 0.76% | — | Posthemes Posstaticblocks | 16/5/2023 | 17/6/2026 | Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook(). | |
| Modificada | Crítica (9.8) | 32% | — | Prestashop Poststaticfooter | 10/5/2023 | 17/6/2026 | Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). | |
| Modificada | Media (5.3) | 0.99% | — | M.static Project M.static | 10/5/2023 | 17/6/2026 | All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function. | |
| Modificada | Alta (7.5) | 1.4% | — | @nubosoftware/node-static Project @nubosoftware/node-staticNode-static Project Node-static | 6/3/2023 | 17/6/2026 | All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function. | |
| Modificada | Alta (7.5) | 1.4% | — | Easy-static-server Project Easy-static-server | 20/12/2022 | 17/6/2026 | All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code. | |
| Modificada | Alta (7.5) | 1.0% | — | Static-dev-server Project Static-dev-server | 29/11/2022 | 17/6/2026 | This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory. | |
| Modificada | Media (5.4) | 0.30% | — | Static Page Extended Project Static Page Extended | 13/6/2022 | 17/6/2026 | Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings | |
| Modificada | Media (6.1) | 0.56% | — | NI FlexloggerNI G WEB Development SoftwareNI LabviewNI Static Test Software Suite+1 | 21/4/2022 | 17/6/2026 | There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3 or later, install FlexLogger 2022 Q2 or later, install LabVIEW 2021 SP1, install G Web Development… | |
| Modificada | Alta (8.8) | 1.0% | — | Fastify-static | 14/10/2021 | 17/6/2026 | A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox users to arbitrary websites via a double slash `//` followed by a domain: `http://localhost:3000//a//youtube.com/%2e%2e%2f%2e%2e`.A DOS vulnerability is possible if the URL contains… | |
| Modificada | Media (6.1) | 1.2% | — | Fastify-static | 14/10/2021 | 17/6/2026 | A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications that set redirect: true option. By… | |
| Modificada | Alta (7) | 0.36% | — | Late-static Project Late-static | 26/1/2021 | 17/6/2026 | An issue was discovered in the late-static crate before 0.4.0 for Rust. Because Sync is implemented for LateStatic with T: Send, a data race can occur. | |
| Modificada | Media (5.4) | 0.72% | — | Jenkins Static Analysis Utilities | 4/11/2020 | 17/6/2026 | Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. | |
| Modificada | Alta (7.6) | 1.6% | — | Osm-static-maps Project Osm-static-maps | 20/10/2020 | 17/6/2026 | This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as an HTML on the page which gives… |