Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.37% | — | Chatwoot | 17/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0. | |
| Modificada | Crítica (9.8) | 0.99% | — | Chatwoot | 28/10/2022 | 17/6/2026 | Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to identify the output Status Code to… | |
| Modificada | Alta (7.1) | 0.63% | — | Chatwoot | 6/9/2022 | 17/6/2026 | Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8. | |
| Modificada | Media (6.1) | 0.95% | — | Chatwoot | 19/8/2022 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0. | |
| Modificada | Media (5.4) | 0.74% | — | Chatwoot | 19/8/2022 | 17/6/2026 | Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0. | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Pluginus Woot | 27/6/2022 | 17/6/2026 | The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected… | |
| Modificada | Media (5.4) | 4.5% | — | Chatwoot | 21/4/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0. | |
| Modificada | Media (6.5) | 1.1% | — | Chatwoot | 9/2/2022 | 17/6/2026 | Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2. | |
| Modificada | Media (6.1) | 0.85% | — | Chatwoot | 9/2/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0. | |
| Modificada | Media (6.1) | 0.86% | — | Chatwoot | 9/2/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0. | |
| Modificada | Alta (7.5) | 1.2% | — | Chatwoot | 16/7/2021 | 17/6/2026 | chatwoot is vulnerable to Inefficient Regular Expression Complexity | |
| Modificada | Media (4.3) | 2.0% | — | Woothemes Woocommerce | 24/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports page to wp-admin/admin.php. | |
| Modificada | Media (4.3) | 2.0% | — | Woothemes Woocommerce Plugin | 14/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the range parameter on the wc-reports page to wp-admin/admin.php. |