Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

574 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.92%—Webfactoryltd Minimal Coming Soon & Maintenance Mode9/1/202017/6/2026
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.
ModificadaCrítica (9)0.86%—Webfactoryltd 301 Redirects19/12/201917/6/2026
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in a…
ModificadaAlta (8.8)1.7%—Wikidsystems TWO Factor Authentication Enterprise Server17/10/201917/6/2026
Multiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticated users to execute arbitrary SQL commands via the source or subString parameter.
ModificadaMedia (6.1)1.7%—Wikidsystems TWO Factor Authentication Enterprise Server17/10/201917/6/2026
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/groups.jsp. The groupName parameter is vulnerable: the reflected cross-site scripting occurs immediately after the group is…
ModificadaMedia (6.1)1.7%—Wikidsystems TWO Factor Authentication Enterprise Server17/10/201917/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML that is triggered when Logs.jsp is visited. The rendered_message column is retrieved and displayed, unsanitized, on Logs.jsp. A remote attack can populate…
ModificadaMedia (6.1)1.7%—Wikidsystems TWO Factor Authentication Enterprise Server17/10/201917/6/2026
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allows remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/userPreregistration.jsp. The preRegistrationData parameter is vulnerable: a reflected cross-site scripting occurs immediately…
ModificadaAlta (8.8)2.1%—Wikidsystems TWO Factor Authentication Enterprise Server17/10/201917/6/2026
WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection through the searchDevices.jsp endpoint. The uid and domain parameters are used, unsanitized, in a SQL query constructed in the buildSearchWhereClause function.
ModificadaMedia (6.1)0.92%—Wpfactory Download Plugins AND Themes From Dashboard7/10/201917/6/2026
includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues.
ModificadaMedia (6.1)0.99%—Simbahosting Two-factor-authentication28/8/201917/6/2026
The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area.
ModificadaCrítica (9.8)2.0%—Wpmadeasy Shortcode Factory22/8/201917/6/2026
The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion.
ModificadaMedia (6.1)0.91%—Wpmadeeasy Shortcode Factory21/8/201917/6/2026
The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.
ModificadaCrítica (9.8)2.3%—Thephpfactory Micro Deal Factory19/6/201917/6/2026
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.
ModificadaCrítica (9.8)2.3%—Thephpfactory Dutch Auction Factory19/6/201917/6/2026
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
ModificadaCrítica (9.8)2.3%—Thephpfactory Auction Factory19/6/201917/6/2026
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.
ModificadaMedia (6.5)0.71%—Jfrog Artifactory31/5/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven…
ModificadaMedia (4.3)1.8%—Jfrog Artifactory31/5/201917/6/2026
A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
ModificadaMedia (4.3)1.8%—Jfrog Artifactory31/5/201917/6/2026
A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in…
ModificadaMedia (4.3)0.84%—Jfrog Artifactory31/5/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials…
ModificadaAlta (8.8)0.59%—Cisco Hx220c M5 FirmwareCisco Hx240c M5 FirmwareCisco Hx240c Large Form Factor FirmwareCisco Hx220c ALL Nvme M5 Firmware+103/5/201917/6/2026
A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based…
ModificadaCrítica (9.8)3.0%—Jfrog Artifactory16/4/201917/6/2026
JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.
ModificadaCrítica (9.8)54%💥 ExploitJfrog Artifactory11/4/201917/6/2026
An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP…
ModificadaAlta (7.3)0.46%—Schneider-electric OPC Factory Server25/3/201917/6/2026
A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20…
ModificadaAlta (7.5)3.9%—Rockwellautomation Factorytalk Services Platform24/1/201917/6/2026
In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated attacker could send numerous crafted packets to service ports resulting in memory consumption that could lead to a partial or complete denial-of-service condition to the affected services.
ModificadaAlta (7.8)0.33%—Jfrog Artifactory9/1/201917/6/2026
An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin.
ModificadaAlta (8.8)1.4%—Simbahosting Two-factor-authentication19/12/201817/6/2026
Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the tfa_enable_tfa parameter due to missing nonce validation.
Orbitaley — Vulnerabilidades