Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.68% | — | Tribe29 Checkmk | 18/4/2023 | 17/6/2026 | Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions. | |
| Modificada | Alta (8.8) | 0.25% | — | Adtribes Product Feed PRO FOR Woocommerce | 6/4/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AdTribes.Io Product Feed PRO for WooCommerce plugin <= 12.4.4 versions. | |
| Modificada | Media (5.3) | 0.91% | — | CheckmkTribe29 Checkmk | 4/4/2023 | 17/6/2026 | Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations. | |
| Modificada | Media (5.4) | 0.40% | — | CheckmkTribe29 Checkmk | 20/3/2023 | 17/6/2026 | HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails | |
| Modificada | Alta (8.1) | 0.93% | — | CheckmkTribe29 Checkmk | 26/1/2023 | 17/6/2026 | Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk 1.6.0 (EOL) are affected. | |
| Modificada | Alta (7.8) | 0.20% | — | CheckmkTribe29 Checkmk | 17/6/2022 | 17/6/2026 | A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. Using the shipped version of the agents, the maintainer scripts located at /var/lib/dpkg/info/ will be owned by the user and the group… | |
| Modificada | Media (6.7) | 0.40% | — | CheckmkTribe29 Checkmk | 20/5/2022 | 17/6/2026 | In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink. | |
| Modificada | Media (6.1) | 0.99% | — | CheckmkTribe29 Checkmk | 25/3/2022 | 9/7/2026 | CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or… | |
| Modificada | Alta (8.8) | 3.0% | — | CheckmkTribe29 Checkmk | 25/3/2022 | 9/7/2026 | The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible. Successful exploitation requires access to the web management interface, either with valid credentials or… | |
| Modificada | Media (5.4) | 0.65% | — | Adtribes Product Feed PRO FOR Woocommerce | 7/3/2022 | 17/6/2026 | The Product Feed PRO for WooCommerce WordPress plugin before 11.2.3 does not escape the rowCount parameter before outputting it back in an attribute via the woosea_categories_dropdown AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (5.4) | 0.61% | — | Adtribes Product Feed PRO FOR Woocommerce | 24/1/2022 | 17/6/2026 | The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some of its AJAX actions, allowing any authenticated users to call then, which could lead to Stored Cross-Site Scripting issue (which will be triggered in the admin dashboard) due to the lack of escaping. | |
| Modificada | Crítica (9.8) | 3.4% | — | Sharetribe | 19/11/2021 | 17/6/2026 | Sharetribe Go is a source available marketplace software. In affected versions operating system command injection is possible on installations of Sharetribe Go, that do not have a secret AWS Simple Notification Service (SNS) notification token configured via the `sns_notification_token` configuration parameter. This… | |
| Modificada | Alta (7.5) | 1.0% | — | Soundtribetoken Project Soundtribetoken | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for SoundTribeToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Media (5) | 50% | — | Davistribe Google DOC Embedder | 29/5/2014 | 16/6/2026 | Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to libs/pdf.php. | |
| Modificada | Media (5) | 2.1% | — | TrinooAITribe Flood NetworkAITribe Flood Network 2000AIStacheldrahtAI+2 | 2/5/2000 | 16/6/2026 | A system has a distributed denial of service (DDOS) attack master, agent, or zombie installed, such as (1) Trinoo, (2) Tribe Flood Network (TFN), (3) Tribe Flood Network 2000 (TFN2K), (4) stacheldraht, (5) mstream, or (6) shaft. |