Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.36% | — | Vertical Scroll Recent Post Project Vertical Scroll Recent Post | 9/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Vertical scroll recent post plugin <= 14.0 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Wpdevart Responsive Vertical Icon Menu | 4/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 versions. | |
| Modificada | Media (5.4) | 0.23% | — | Wpdevart Responsive Vertical Icon Menu | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 can lead to theme deletion. | |
| Modificada | Media (6.1) | 0.80% | — | Vertical Scroll Recent Post Project Vertical Scroll Recent Post | 9/5/2022 | 17/6/2026 | The Vertical scroll recent post WordPress plugin before 14.0 does not sanitise and escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 2.3% | — | Opentext Vertica | 15/2/2018 | 17/6/2026 | A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and later was found. | |
| Modificada | Crítica (9.8) | 3.1% | — | Opentext Vertica | 20/4/2016 | 17/6/2026 | The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2.2-1 allows remote attackers to execute arbitrary commands via the mcPort parameter, aka ZDI-CAN-3417. | |
| Modificada | Alta (7.5) | 4.7% | — | Opentext Vertica | 4/11/2015 | 17/6/2026 | The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote attackers to execute arbitrary commands via a crafted packet, aka ZDI-CAN-2914. | |
| Modificada | Media (5) | 0.99% | — | Enterasys Vertical Horizon-2402s | 16/6/2005 | 16/6/2026 | Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry. | |
| Modificada | Alta (7.5) | 1.3% | — | Enterasys Vertical Horizon-2402s | 16/6/2005 | 16/6/2026 | Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges. |