Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.37%—Chatwoot17/4/202317/6/2026
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0.
ModificadaCrítica (9.8)0.99%—Chatwoot28/10/202217/6/2026
Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to identify the output Status Code to…
ModificadaAlta (7.1)0.63%—Chatwoot6/9/202217/6/2026
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
ModificadaMedia (6.1)0.95%—Chatwoot19/8/202217/6/2026
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.
ModificadaMedia (5.4)0.74%—Chatwoot19/8/202217/6/2026
Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.
ModificadaMedia (6.1)1.9%💥 ExploitPluginus Woot27/6/202217/6/2026
The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1.0.5 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected…
ModificadaMedia (5.4)4.5%—Chatwoot21/4/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.
ModificadaMedia (6.5)1.1%—Chatwoot9/2/202217/6/2026
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
ModificadaMedia (6.1)0.85%—Chatwoot9/2/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
ModificadaMedia (6.1)0.86%—Chatwoot9/2/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
ModificadaAlta (7.5)1.2%—Chatwoot16/7/202117/6/2026
chatwoot is vulnerable to Inefficient Regular Expression Complexity
ModificadaMedia (4.3)2.0%—Woothemes Woocommerce24/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports page to wp-admin/admin.php.
ModificadaMedia (4.3)2.0%—Woothemes Woocommerce Plugin14/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the range parameter on the wc-reports page to wp-admin/admin.php.
Orbitaley — Vulnerabilidades