Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.92% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 9/1/2020 | 17/6/2026 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo. | |
| Modificada | Crítica (9) | 0.86% | — | Webfactoryltd 301 Redirects | 19/12/2019 | 17/6/2026 | The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in a… | |
| Modificada | Alta (8.8) | 1.7% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | Multiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticated users to execute arbitrary SQL commands via the source or subString parameter. | |
| Modificada | Media (6.1) | 1.7% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/groups.jsp. The groupName parameter is vulnerable: the reflected cross-site scripting occurs immediately after the group is… | |
| Modificada | Media (6.1) | 1.7% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML that is triggered when Logs.jsp is visited. The rendered_message column is retrieved and displayed, unsanitized, on Logs.jsp. A remote attack can populate… | |
| Modificada | Media (6.1) | 1.7% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allows remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/userPreregistration.jsp. The preRegistrationData parameter is vulnerable: a reflected cross-site scripting occurs immediately… | |
| Modificada | Alta (8.8) | 2.1% | — | Wikidsystems TWO Factor Authentication Enterprise Server | 17/10/2019 | 17/6/2026 | WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection through the searchDevices.jsp endpoint. The uid and domain parameters are used, unsanitized, in a SQL query constructed in the buildSearchWhereClause function. | |
| Modificada | Media (6.1) | 0.92% | — | Wpfactory Download Plugins AND Themes From Dashboard | 7/10/2019 | 17/6/2026 | includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues. | |
| Modificada | Media (6.1) | 0.99% | — | Simbahosting Two-factor-authentication | 28/8/2019 | 17/6/2026 | The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area. | |
| Modificada | Crítica (9.8) | 2.0% | — | Wpmadeasy Shortcode Factory | 22/8/2019 | 17/6/2026 | The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion. | |
| Modificada | Media (6.1) | 0.91% | — | Wpmadeeasy Shortcode Factory | 21/8/2019 | 17/6/2026 | The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg. | |
| Modificada | Crítica (9.8) | 2.3% | — | Thephpfactory Micro Deal Factory | 19/6/2019 | 17/6/2026 | SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/. | |
| Modificada | Crítica (9.8) | 2.3% | — | Thephpfactory Dutch Auction Factory | 19/6/2019 | 17/6/2026 | SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter. | |
| Modificada | Crítica (9.8) | 2.3% | — | Thephpfactory Auction Factory | 19/6/2019 | 17/6/2026 | SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter. | |
| Modificada | Media (6.5) | 0.71% | — | Jfrog Artifactory | 31/5/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven… | |
| Modificada | Media (4.3) | 1.8% | — | Jfrog Artifactory | 31/5/2019 | 17/6/2026 | A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. | |
| Modificada | Media (4.3) | 1.8% | — | Jfrog Artifactory | 31/5/2019 | 17/6/2026 | A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in… | |
| Modificada | Media (4.3) | 0.84% | — | Jfrog Artifactory | 31/5/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials… | |
| Modificada | Alta (8.8) | 0.59% | — | Cisco Hx220c M5 FirmwareCisco Hx240c M5 FirmwareCisco Hx240c Large Form Factor FirmwareCisco Hx220c ALL Nvme M5 Firmware+10 | 3/5/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based… | |
| Modificada | Crítica (9.8) | 3.0% | — | Jfrog Artifactory | 16/4/2019 | 17/6/2026 | JFrog Artifactory Pro 6.5.9 has Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 54% | 💥 Exploit | Jfrog Artifactory | 11/4/2019 | 17/6/2026 | An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP… | |
| Modificada | Alta (7.3) | 0.46% | — | Schneider-electric OPC Factory Server | 25/3/2019 | 17/6/2026 | A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20… | |
| Modificada | Alta (7.5) | 3.9% | — | Rockwellautomation Factorytalk Services Platform | 24/1/2019 | 17/6/2026 | In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated attacker could send numerous crafted packets to service ports resulting in memory consumption that could lead to a partial or complete denial-of-service condition to the affected services. | |
| Modificada | Alta (7.8) | 0.33% | — | Jfrog Artifactory | 9/1/2019 | 17/6/2026 | An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin. | |
| Modificada | Alta (8.8) | 1.4% | — | Simbahosting Two-factor-authentication | 19/12/2018 | 17/6/2026 | Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the tfa_enable_tfa parameter due to missing nonce validation. |