Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.66% | — | Devnewsaggregator Project Devnewsaggregator | 5/1/2023 | 17/6/2026 | A vulnerability was found in stevejagodzinski DevNewsAggregator. It has been rated as critical. Affected by this issue is the function getByName of the file php/data_access/RemoteHtmlContentDataAccess.php. The manipulation of the argument name leads to sql injection. The name of the patch is… | |
| Modificada | Media (4.3) | 0.77% | — | Authenticator Project Authenticator | 2/1/2023 | 17/6/2026 | The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, which may deny other users access to the functionality in certain configurations. | |
| Modificada | Crítica (9.8) | 0.71% | — | DWC Network Server Emulator Project DWC Network Server Emulator | 25/12/2022 | 17/6/2026 | A vulnerability was found in barronwaffles dwc_network_server_emulator. It has been declared as critical. This vulnerability affects the function update_profile of the file gamespy/gs_database.py. The manipulation of the argument firstname/lastname leads to sql injection. The attack can be initiated remotely. The name… | |
| Modificada | Media (5.5) | 0.24% | — | Pig-vector Project Pig-vector | 21/12/2022 | 17/6/2026 | A vulnerability was found in pig-vector and classified as problematic. Affected by this issue is the function LogisticRegression of the file src/main/java/org/apache/mahout/pig/LogisticRegression.java. The manipulation leads to insecure temporary file. The attack needs to be approached locally. The name of the patch… | |
| Modificada | Crítica (9.8) | 1.7% | — | Replicator Project Replicator | 15/12/2022 | 17/6/2026 | A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object. | |
| Modificada | Media (4.2) | 0.20% | — | Osisoft-pi-web-connector Project Osisoft-pi-web-connector | 4/11/2022 | 17/6/2026 | The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that captured authentication requests. This vulnerability is resolved in osisoft-pi-web-connector version 0.44.0. | |
| Modificada | Media (4.8) | 0.61% | — | Flexi Quote Rotator Project Flexi Quote Rotator | 1/8/2022 | 17/6/2026 | The Flexi Quote Rotator WordPress plugin through 0.9.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (7.5) | 1.5% | 💥 PoC | QR Code Generator Project QR Code Generator | 25/7/2022 | 9/7/2026 | A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal. | |
| Modificada | Crítica (9.8) | 0.88% | — | Otp-generator Project Otp-generator | 25/7/2022 | 17/6/2026 | The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack. | |
| Modificada | Crítica (9.3) | 1.3% | — | Solar-system-simulator Project Solar-system-simulator | 11/7/2022 | 17/6/2026 | The jmcginty15/Solar-system-simulator repository through 2021-07-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (7.5) | 1.1% | — | Scniro-validator Project Scniro-validator | 27/6/2022 | 17/6/2026 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating crafted invalid emails. | |
| Modificada | Media (4.3) | 0.43% | — | Cimy Header Image Rotator Project Cimy Header Image Rotator | 27/6/2022 | 17/6/2026 | The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Crítica (9.8) | 4.5% | 💥 PoC | Antminer Monitor Project Antminer Monitor | 17/6/2022 | 17/6/2026 | A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static. | |
| Modificada | Alta (7.5) | 1.1% | — | Markdown-link-extractor Project Markdown-link-extractor | 2/6/2022 | 17/6/2026 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function | |
| Modificada | Alta (8.8) | 0.61% | — | Bulk Page Creator Project Bulk Page Creator | 30/5/2022 | 17/6/2026 | The Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks, which makes them vulnerable to CSRF. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Gwyn's Imagemap Selector Project Gwyn's Imagemap Selector | 23/5/2022 | 17/6/2026 | The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Alta (7.5) | 1.9% | — | Random Password Generator Project Random Password Generator | 18/5/2022 | 17/6/2026 | The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction. | |
| Modificada | Media (6.1) | 0.86% | — | BMI BMR Calculator Project BMI BMR Calculator | 16/5/2022 | 17/6/2026 | The BMI BMR Calculator WordPress plugin through 1.3 does not sanitise and escape arbitrary POST data before outputting it back in the response, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.80% | — | Admin Menu Editor Project Admin Menu Editor | 9/5/2022 | 17/6/2026 | The Admin Menu Editor WordPress plugin through 1.0.4 does not sanitize and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Crítica (9.8) | 43% | 💥 Exploit | Documentor Project Documentor | 2/5/2022 | 17/6/2026 | The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users. | |
| Modificada | Media (5.4) | 0.49% | — | PHP Mysql Admin Panel Generator Project PHP Mysql Admin Panel Generator | 28/4/2022 | 9/7/2026 | A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Automatic Question Paper Generator Project Automatic Question Paper Generator | 18/4/2022 | 17/6/2026 | Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter. | |
| Modificada | Crítica (9.8) | 48% | 💥 Exploit | Narnoo Distributor Project Narnoo Distributor | 28/3/2022 | 17/6/2026 | The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results in the disclosure of arbitrary files as… | |
| Modificada | Media (6.1) | 0.80% | — | Bulk Creator Project Bulk Creator | 28/3/2022 | 17/6/2026 | The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Media (4.9) | 1.4% | — | String Locator Project String Locator | 28/3/2022 | 17/6/2026 | The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowing high privilege users such as admin to query arbitrary files on the web server via a path traversal vector. Furthermore, due to a flaw in the search, allowing a pattern to be provided, which will… |