Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.32% | — | Official Saleswizard CRMAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SalesWizard.pl Official SalesWizard CRM Plugin official-saleswizard-crm allows Stored XSS.This issue affects Official SalesWizard CRM Plugin: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.9) | 0.25% | — | KDE KmailAIKDE Kmail-account-wizardAI | 28/10/2024 | 17/6/2026 | ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is used for a URL such as http://autoconfig.example.com or http://example.com/.well-known/autoconfig for retrieving the configuration. This is related to… | |
| Aplazada | Crítica (9.8) | 0.58% | — | Webwizards SaleskingAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in WebWizards SalesKing allows Privilege Escalation.This issue affects SalesKing: from n/a through 1.6.15. | |
| Aplazada | Alta (8.8) | 0.64% | — | Coderevolution WP Setup WizardAI | 25/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodeRevolution WP Setup Wizard.This issue affects WP Setup Wizard: from n/a through 1.0.8.1. | |
| Modificada | Alta (7.5) | 1.3% | — | Upredsun File Sharing Wizard | 11/1/2024 | 17/6/2026 | A vulnerability has been found in iSharer and upRedSun File Sharing Wizard up to 1.5.0 and classified as problematic. This vulnerability affects unknown code of the component GET Request Handler. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 0.44% | — | Saleswizard NSC | 20/10/2023 | 17/6/2026 | The nsc theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can… | |
| Modificada | Alta (8.1) | 0.77% | — | Minitool Partition Wizard | 19/9/2023 | 17/6/2026 | MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack. | |
| Modificada | Alta (8.1) | 0.77% | — | Minitool Partition Wizard | 19/9/2023 | 17/6/2026 | MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack. | |
| Modificada | Crítica (9.8) | 2.0% | — | Wibu Codemeter RuntimeTrumpf OseonTrumpf ProgrammingtubeTrumpf Teczonebend+20 | 13/9/2023 | 17/6/2026 | A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Easy Streaming Wizard | 11/8/2023 | 17/6/2026 | Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.3) | 0.69% | — | Webwizards B2bking | 7/6/2023 | 17/6/2026 | The B2BKing plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'b2bkingdownloadpricelist' function in versions up to, and including, 4.6.00. This makes it possible for Authenticated attackers with subscriber or customer-level permissions to retrieve the full… | |
| Modificada | Media (6.5) | 0.73% | — | Webwizards B2bking | 7/6/2023 | 17/6/2026 | The B2BKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'b2bking_save_price_import' function in versions up to, and including, 4.6.00. This makes it possible for Authenticated attackers with subscriber or customer-level permissions to modify the… | |
| Modificada | Alta (7.8) | 0.42% | — | Minitool Partition Wizard | 20/5/2022 | 17/6/2026 | MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level. | |
| Modificada | Crítica (9.8) | 2.9% | — | Nagios XI Docker Wizard | 13/8/2021 | 17/6/2026 | Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php. | |
| Modificada | Crítica (9.8) | 74% | — | Nagios XI Watchguard Wizard | 13/8/2021 | 17/6/2026 | Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection). | |
| Modificada | Crítica (9.8) | 97% | — | Nagios XI Switch Wizard | 13/8/2021 | 17/6/2026 | Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection). | |
| Modificada | Media (5.5) | 0.32% | — | ABB Device Library Wizard | 29/5/2020 | 17/6/2026 | Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data | |
| Modificada | Alta (8.8) | 5.2% | — | Dropwizard Validation | 10/4/2020 | 17/6/2026 | dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in the self-validating feature enabling attackers to inject arbitrary Java EL expressions, leading to Remote Code Execution (RCE) vulnerability. If you are using a… | |
| Modificada | Alta (8.8) | 3.0% | — | Dropwizard ValidationOracle Blockchain Platform | 24/2/2020 | 17/6/2026 | Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. The issue has been fixed in dropwizard-validation 1.3.19 and… | |
| Modificada | Crítica (9.8) | 15% | — | Upredsun File Sharing Wizard | 12/11/2019 | 17/6/2026 | File Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnerability. An unauthenticated attacker is able to perform remote command execution and obtain a command shell by sending a HTTP GET request including the malicious payload in the URL. A similar issue to… | |
| Modificada | Crítica (9.8) | 4.4% | — | Upredsun File Sharing Wizard | 9/10/2019 | 17/6/2026 | A Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthenticated attackers to execute arbitrary code via the HTTP DELETE method, a similar issue to CVE-2019-16724 and CVE-2010-2331. | |
| Modificada | Crítica (9.8) | 72% | — | Upredsun File Sharing Wizard | 24/9/2019 | 17/6/2026 | File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar issue to CVE-2010-2330 and CVE-2010-2331. | |
| Modificada | Media (6.7) | 0.32% | — | Intel Easy Streaming Wizard | 16/9/2019 | 17/6/2026 | Improper file permissions in the installer for Intel(R) Easy Streaming Wizard before version 2.1.0731 may allow an authenticated user to potentially enable escalation of privilege via local attack. | |
| Modificada | Alta (7.8) | 0.31% | — | Intel ACU Wizard | 17/5/2019 | 17/6/2026 | Improper directory permissions in Intel(R) ACU Wizard version 12.0.0.129 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 1.1% | — | Wizardmac Readstat | 22/5/2018 | 17/6/2026 | sas/readstat_sas7bcat_read.c in libreadstat.a in ReadStat 0.1.1 has an infinite loop. |