Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.42% | — | Ibphoenix Ibwebadmin | 15/11/2024 | 17/6/2026 | A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /database.php of the component Banco de Dados Tab. The manipulation of the argument db_login_role leads to cross site scripting. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.4) | 0.31% | — | Wpase Admin AND Site EnhancementsAI | 12/11/2024 | 17/6/2026 | The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to… | |
| Aplazada | Media (5.4) | 0.36% | 💥 PoC | Netadmin IAMAI | 11/11/2024 | 17/6/2026 | The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field. | |
| Aplazada | Media (5.5) | 0.20% | — | Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAIAcronis Backup Plugin FOR DirectadminAI | 11/11/2024 | 17/6/2026 | Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build… | |
| Aplazada | Media (6.5) | 0.25% | — | Duogeek Custom Admin MenuAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Custom Admin Menu custom-admin-menu allows Stored XSS.This issue affects Custom Admin Menu: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Aryanduntley Admin AmplifyAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aryanduntley Admin Amplify wpr-admin-amplify allows Reflected XSS.This issue affects Admin Amplify: from n/a through <= 1.3.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Mariandz TeleadminAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mariandz TeleAdmin teleadmin allows Reflected XSS.This issue affects TeleAdmin: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Eewee Admin CustomAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eewee eewee admin custom eewee-admincustom allows Reflected XSS.This issue affects eewee admin custom: from n/a through <= 1.8.2.4. | |
| Aplazada | Alta (8.5) | 0.40% | — | QUY LE 91 Administrator ZAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quý Lê 91 Administrator Z administrator-z allows Blind SQL Injection.This issue affects Administrator Z: from n/a through < 2024.10.21. | |
| Aplazada | Media (5.3) | 0.33% | — | Ibphoenix IbwebadminAI | 6/11/2024 | 17/6/2026 | A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /toggle_fold_panel.php of the component Tabelas Section. The manipulation of the argument p leads to cross site scripting. The attack may be initiated remotely. The… | |
| Analizada | Baja (2.3) | 0.53% | — | Thinkadmin | 4/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script of the file /app/admin/controller/api/Plugs.php. The manipulation of the argument uptoken leads to deserialization. It is possible to launch the attack remotely. The complexity of an attack is… | |
| Modificada | Media (4.3) | 0.34% | — | Church Admin Project Church Admin | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.4. | |
| Analizada | Alta (7.2) | 0.95% | — | Eladmin | 30/10/2024 | 17/6/2026 | The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController.java. | |
| Analizada | Media (6.5) | 0.43% | — | Eladmin | 30/10/2024 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter leads to SSRF. | |
| Aplazada | Alta (8.1) | 0.65% | 💥 PoC | NetadminAI | 29/10/2024 | 17/6/2026 | Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of the browser of a user with greater… | |
| Aplazada | Alta (7.1) | 0.30% | — | Carl Alberto Simple Custom AdminAI | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Carl Alberto Simple Custom Admin simple-custom-admin allows Reflected XSS.This issue affects Simple Custom Admin: from n/a through <= 1.2. | |
| Modificada | Media (6.1) | 0.33% | — | Themoyles Church Admin | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin church-admin allows Reflected XSS.This issue affects Church Admin: from n/a through < 5.0.0. | |
| Analizada | Media (6.1) | 0.29% | — | Funadmin | 25/10/2024 | 17/6/2026 | An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS). | |
| Analizada | Alta (7.2) | 0.49% | — | Funadmin | 25/10/2024 | 17/6/2026 | funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php. | |
| Analizada | Alta (7.2) | 0.45% | — | Funadmin | 25/10/2024 | 17/6/2026 | funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin. | |
| Analizada | Media (4.9) | 0.55% | — | Funadmin | 25/10/2024 | 17/6/2026 | Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS). | |
| Analizada | Alta (7.2) | 0.56% | — | Funadmin | 25/10/2024 | 17/6/2026 | Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield. | |
| Analizada | Media (6.5) | 0.56% | — | Funadmin | 25/10/2024 | 17/6/2026 | Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile. | |
| Analizada | Media (4.9) | 0.65% | — | Funadmin | 25/10/2024 | 17/6/2026 | Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile. | |
| Analizada | Alta (7.2) | 0.56% | — | Funadmin | 25/10/2024 | 17/6/2026 | Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist. |