Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.53% | — | Limesurvey Community EditionAI | 14/8/2026 | 28/8/2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer and then rendered without context-appropriate output encoding. | |
| Aplazada | Alta (7.1) | 0.25% | — | Ays-pro Survey MakerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. | |
| Aplazada | Media (4.8) | 0.24% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 4/8/2026 | 26/8/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the browser of any user viewing the affected quiz. | |
| Aplazada | Baja (2.1) | 0.35% | — | Diaowen DwsurveyAI | 4/8/2026 | 12/8/2026 | A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey Status Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.36% | — | Diaowen DwsurveyAI | 4/8/2026 | 12/8/2026 | A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. The manipulation results in authorization bypass. The attack can be launched remotely. The exploit… | |
| Aplazada | Media (4.3) | 0.34% | — | Survey Form BlockAI | 29/7/2026 | 30/7/2026 | The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_data() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all survey… | |
| Aplazada | Baja (2.7) | 0.28% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 28/7/2026 | 28/7/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates. | |
| Aplazada | Media (5.3) | 0.37% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 27/7/2026 | 27/7/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to… | |
| Aplazada | Alta (8.5) | 0.36% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 23/7/2026 | 23/7/2026 | Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. | |
| Aplazada | Media (6.3) | 0.35% | — | LimesurveyAI | 20/7/2026 | 23/7/2026 | LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the server to issue arbitrary HTTP requests by supplying a manipulated Host header. Attackers can exploit the unsanitized use of the HTTP Host… | |
| Aplazada | Media (4.3) | 0.49% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 3/7/2026 | 6/7/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Ays-pro Survey MakerAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions. | |
| Aplazada | Media (4.3) | 0.47% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 27/6/2026 | 29/6/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Analizada | Alta (8.8) | 0.49% | — | Joomplace Survey Force Deluxe | 19/6/2026 | 19/8/2026 | Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the invite parameter. Attackers can send GET requests to the component with crafted SQL payloads in the invite parameter to extract… | |
| Aplazada | Alta (7.1) | 0.25% | — | Expressionengine Quiz AND Survey MasterAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Expressionengine Quiz AND Survey MasterAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions. | |
| Aplazada | Alta (8.7) | 0.60% | — | LimesurveyAI | 9/6/2026 | 23/7/2026 | The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into TokenDynamic::findUninvited(), which concatenates the values directly into a tid IN ('...') SQL clause without parameterization or input validation. A remote, authenticated attacker holding the… | |
| Aplazada | Alta (8.7) | 0.66% | — | LimesurveyAI | 9/6/2026 | 23/7/2026 | LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation. A remote,… | |
| Aplazada | Media (4.9) | 0.60% | — | Expressionengine Quiz AND Survey MasterAI | 6/6/2026 | 23/7/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Analizada | Baja (2.7) | 0.25% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. | |
| Analizada | Media (4.9) | 0.34% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. | |
| Analizada | Baja (2.7) | 0.25% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. | |
| Analizada | Media (4.9) | 0.23% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. | |
| Analizada | Media (4.9) | 0.34% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. | |
| Analizada | Baja (2.7) | 0.33% | — | Synology Surveillance Station | 27/5/2026 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. |