Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

128 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.66%—Devnewsaggregator Project Devnewsaggregator5/1/202317/6/2026
A vulnerability was found in stevejagodzinski DevNewsAggregator. It has been rated as critical. Affected by this issue is the function getByName of the file php/data_access/RemoteHtmlContentDataAccess.php. The manipulation of the argument name leads to sql injection. The name of the patch is…
ModificadaMedia (4.3)0.77%—Authenticator Project Authenticator2/1/202317/6/2026
The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, which may deny other users access to the functionality in certain configurations.
ModificadaCrítica (9.8)0.71%—DWC Network Server Emulator Project DWC Network Server Emulator25/12/202217/6/2026
A vulnerability was found in barronwaffles dwc_network_server_emulator. It has been declared as critical. This vulnerability affects the function update_profile of the file gamespy/gs_database.py. The manipulation of the argument firstname/lastname leads to sql injection. The attack can be initiated remotely. The name…
ModificadaMedia (5.5)0.24%—Pig-vector Project Pig-vector21/12/202217/6/2026
A vulnerability was found in pig-vector and classified as problematic. Affected by this issue is the function LogisticRegression of the file src/main/java/org/apache/mahout/pig/LogisticRegression.java. The manipulation leads to insecure temporary file. The attack needs to be approached locally. The name of the patch…
ModificadaCrítica (9.8)1.7%—Replicator Project Replicator15/12/202217/6/2026
A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object.
ModificadaMedia (4.2)0.20%—Osisoft-pi-web-connector Project Osisoft-pi-web-connector4/11/202217/6/2026
The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that captured authentication requests. This vulnerability is resolved in osisoft-pi-web-connector version 0.44.0.
ModificadaMedia (4.8)0.61%—Flexi Quote Rotator Project Flexi Quote Rotator1/8/202217/6/2026
The Flexi Quote Rotator WordPress plugin through 0.9.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (7.5)1.5%💥 PoCQR Code Generator Project QR Code Generator25/7/20229/7/2026
A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.
ModificadaCrítica (9.8)0.88%—Otp-generator Project Otp-generator25/7/202217/6/2026
The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.
ModificadaCrítica (9.3)1.3%—Solar-system-simulator Project Solar-system-simulator11/7/202217/6/2026
The jmcginty15/Solar-system-simulator repository through 2021-07-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (7.5)1.1%—Scniro-validator Project Scniro-validator27/6/202217/6/2026
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating crafted invalid emails.
ModificadaMedia (4.3)0.43%—Cimy Header Image Rotator Project Cimy Header Image Rotator27/6/202217/6/2026
The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaCrítica (9.8)4.5%💥 PoCAntminer Monitor Project Antminer Monitor17/6/202217/6/2026
A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.
ModificadaAlta (7.5)1.1%—Markdown-link-extractor Project Markdown-link-extractor2/6/202217/6/2026
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function
ModificadaAlta (8.8)0.61%—Bulk Page Creator Project Bulk Page Creator30/5/202217/6/2026
The Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks, which makes them vulnerable to CSRF.
ModificadaMedia (6.1)2.2%💥 ExploitGwyn's Imagemap Selector Project Gwyn's Imagemap Selector23/5/202217/6/2026
The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.
ModificadaAlta (7.5)1.9%—Random Password Generator Project Random Password Generator18/5/202217/6/2026
The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction.
ModificadaMedia (6.1)0.86%—BMI BMR Calculator Project BMI BMR Calculator16/5/202217/6/2026
The BMI BMR Calculator WordPress plugin through 1.3 does not sanitise and escape arbitrary POST data before outputting it back in the response, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)0.80%—Admin Menu Editor Project Admin Menu Editor9/5/202217/6/2026
The Admin Menu Editor WordPress plugin through 1.0.4 does not sanitize and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
ModificadaCrítica (9.8)43%💥 ExploitDocumentor Project Documentor2/5/202217/6/2026
The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.
ModificadaMedia (5.4)0.49%—PHP Mysql Admin Panel Generator Project PHP Mysql Admin Panel Generator28/4/20229/7/2026
A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php.
ModificadaCrítica (9.8)1.2%—Automatic Question Paper Generator Project Automatic Question Paper Generator18/4/202217/6/2026
Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter.
ModificadaCrítica (9.8)48%💥 ExploitNarnoo Distributor Project Narnoo Distributor28/3/202217/6/2026
The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results in the disclosure of arbitrary files as…
ModificadaMedia (6.1)0.80%—Bulk Creator Project Bulk Creator28/3/202217/6/2026
The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
ModificadaMedia (4.9)1.4%—String Locator Project String Locator28/3/202217/6/2026
The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will…
Orbitaley — Vulnerabilidades