Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1086 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.75%—SAP CommoncryptolibSAP Content ServerSAP Extended Application Services AND RuntimeSAP Hana Database+512/9/202317/6/2026
SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information.
ModificadaMedia (4.8)0.40%—Wp-buy WP Content Copy Protection & NO Right Click5/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP-buy WP Content Copy Protection & No Right Click plugin <= 3.5.5 versions.
ModificadaMedia (4.8)0.39%—Joedolson MY Content Management5/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joseph C Dolson My Content Management plugin <= 1.7.6 versions.
ModificadaMedia (4.3)0.61%—Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+628/7/202317/6/2026
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers…
ModificadaMedia (6.5)0.69%—Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+728/7/202317/6/2026
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,…
ModificadaMedia (6.1)0.49%—Liquidweb Restrict Content17/7/202317/6/2026
The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.5)0.23%—Target-info Mycurator Content Curation11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mark Tilly MyCurator Content Curation plugin <= 3.74 versions.
ModificadaAlta (8.1)0.97%—SAP Netweaver BI Content11/7/202317/6/2026
An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise.
ModificadaAlta (8.8)0.33%—WP Dummy Content Generator Project WP Dummy Content Generator10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Deepak Anand WP Dummy Content Generator plugin <= 2.3.0 versions.
ModificadaMedia (4.3)0.38%—Wpexpertdeveloper WP Private Content Plus1/7/202317/6/2026
The WP Private Content Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. This is due to missing or incorrect nonce validation on the save_groups() function. This makes it possible for unauthenticated attackers to add new group members via a forged request…
ModificadaAlta (8.1)0.47%—Broadcom Advanced Secure GatewayBroadcom Content Analysis1/6/202317/6/2026
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability.
ModificadaMedia (5.4)0.34%—Broadcom Advanced Secure GatewayBroadcom Content Analysis1/6/202317/6/2026
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability.
ModificadaAlta (7.8)0.19%—Broadcom Advanced Secure GatewayBroadcom Content Analysis1/6/202317/6/2026
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability.
ModificadaCrítica (9.8)1.3%—Broadcom Advanced Secure GatewayBroadcom Content Analysis1/6/202317/6/2026
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.
ModificadaAlta (8.8)0.26%—Wpjoli Joli Table OF Contents25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPJoli Joli Table Of Contents plugin <= 1.3.9 versions.
ModificadaMedia (6.1)0.46%—Content Management System Project Content Management System22/5/202317/6/2026
IT Sourcecode Content Management System Project In PHP and MySQL With Source Code 1.0.0 is vulnerable to Cross Site Scripting (XSS) via /ecodesource/search_list.php.
ModificadaAlta (7.8)0.28%—Opentext Documentum Content Server18/5/202317/6/2026
OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to root. The software comes prepackaged with a root owned SUID binary dm_secure_writer. The binary has security controls in place preventing creation of a file in a non-owned directory,…
ModificadaMedia (4.8)0.37%—WP Content Filter - Censor ALL Offensive Content From Your Site Project WP Content Filter - Censor ALL Offensive Content From Your Site9/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David Gwyer WP Content Filter plugin <= 3.0.1 versions.
ModificadaMedia (4.8)0.37%—Json-content-importer Json Content Importer25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bernhard Kux JSON Content Importer plugin <= 1.3.15 versions.
ModificadaMedia (4.8)0.37%—Wpchill CPO Content Types23/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill CPO Content Types plugin <= 1.1.0 versions.
ModificadaMedia (4.8)0.39%—Content-repeater Project Content-repeater18/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denis Buka Content Repeater – Custom Posts Simplified plugin <= 1.1.13 versions.
ModificadaMedia (5.4)0.39%—Codetides Advanced Floating Content16/4/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Code Tides Advanced Floating Content plugin <= 1.2.1 versions.
ModificadaMedia (6.1)0.58%—Google Analytics TOP Content Widget Project Google Analytics TOP Content Widget15/4/202317/6/2026
A vulnerability classified as problematic was found in Google Analytics Top Content Widget Plugin up to 1.5.6 on WordPress. Affected by this vulnerability is an unknown functionality of the file class-tgm-plugin-activation.php. The manipulation leads to cross site scripting. The attack can be launched remotely.…
ModificadaMedia (5.3)1.0%—Sync Oxygen Content FusionSync Oxygen XML WEB Author14/4/202317/6/2026
A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015 allows an attacker to read files from a WEB-INF directory via a crafted HTTP request. (XML Web Author 24.1.0.3 build 2023021714 and 23.1.1.4 build 2023021715 are also…
ModificadaAlta (8.8)1.0%—Custom Content Shortcode Project Custom Content Shortcode20/3/202317/6/2026
The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be…
Orbitaley — Vulnerabilidades