Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.75% | — | SAP CommoncryptolibSAP Content ServerSAP Extended Application Services AND RuntimeSAP Hana Database+5 | 12/9/2023 | 17/6/2026 | SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information. | |
| Modificada | Media (4.8) | 0.40% | — | Wp-buy WP Content Copy Protection & NO Right Click | 5/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP-buy WP Content Copy Protection & No Right Click plugin <= 3.5.5 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Joedolson MY Content Management | 5/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joseph C Dolson My Content Management plugin <= 1.7.6 versions. | |
| Modificada | Media (4.3) | 0.61% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+6 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (6.5) | 0.69% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+7 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,… | |
| Modificada | Media (6.1) | 0.49% | — | Liquidweb Restrict Content | 17/7/2023 | 17/6/2026 | The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.5) | 0.23% | — | Target-info Mycurator Content Curation | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mark Tilly MyCurator Content Curation plugin <= 3.74 versions. | |
| Modificada | Alta (8.1) | 0.97% | — | SAP Netweaver BI Content | 11/7/2023 | 17/6/2026 | An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise. | |
| Modificada | Alta (8.8) | 0.33% | — | WP Dummy Content Generator Project WP Dummy Content Generator | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Deepak Anand WP Dummy Content Generator plugin <= 2.3.0 versions. | |
| Modificada | Media (4.3) | 0.38% | — | Wpexpertdeveloper WP Private Content Plus | 1/7/2023 | 17/6/2026 | The WP Private Content Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. This is due to missing or incorrect nonce validation on the save_groups() function. This makes it possible for unauthenticated attackers to add new group members via a forged request… | |
| Modificada | Alta (8.1) | 0.47% | — | Broadcom Advanced Secure GatewayBroadcom Content Analysis | 1/6/2023 | 17/6/2026 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability. | |
| Modificada | Media (5.4) | 0.34% | — | Broadcom Advanced Secure GatewayBroadcom Content Analysis | 1/6/2023 | 17/6/2026 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability. | |
| Modificada | Alta (7.8) | 0.19% | — | Broadcom Advanced Secure GatewayBroadcom Content Analysis | 1/6/2023 | 17/6/2026 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability. | |
| Modificada | Crítica (9.8) | 1.3% | — | Broadcom Advanced Secure GatewayBroadcom Content Analysis | 1/6/2023 | 17/6/2026 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability. | |
| Modificada | Alta (8.8) | 0.26% | — | Wpjoli Joli Table OF Contents | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPJoli Joli Table Of Contents plugin <= 1.3.9 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Content Management System Project Content Management System | 22/5/2023 | 17/6/2026 | IT Sourcecode Content Management System Project In PHP and MySQL With Source Code 1.0.0 is vulnerable to Cross Site Scripting (XSS) via /ecodesource/search_list.php. | |
| Modificada | Alta (7.8) | 0.28% | — | Opentext Documentum Content Server | 18/5/2023 | 17/6/2026 | OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to root. The software comes prepackaged with a root owned SUID binary dm_secure_writer. The binary has security controls in place preventing creation of a file in a non-owned directory,… | |
| Modificada | Media (4.8) | 0.37% | — | WP Content Filter - Censor ALL Offensive Content From Your Site Project WP Content Filter - Censor ALL Offensive Content From Your Site | 9/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David Gwyer WP Content Filter plugin <= 3.0.1 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Json-content-importer Json Content Importer | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bernhard Kux JSON Content Importer plugin <= 1.3.15 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Wpchill CPO Content Types | 23/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill CPO Content Types plugin <= 1.1.0 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Content-repeater Project Content-repeater | 18/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denis Buka Content Repeater – Custom Posts Simplified plugin <= 1.1.13 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Codetides Advanced Floating Content | 16/4/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Code Tides Advanced Floating Content plugin <= 1.2.1 versions. | |
| Modificada | Media (6.1) | 0.58% | — | Google Analytics TOP Content Widget Project Google Analytics TOP Content Widget | 15/4/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Google Analytics Top Content Widget Plugin up to 1.5.6 on WordPress. Affected by this vulnerability is an unknown functionality of the file class-tgm-plugin-activation.php. The manipulation leads to cross site scripting. The attack can be launched remotely.… | |
| Modificada | Media (5.3) | 1.0% | — | Sync Oxygen Content FusionSync Oxygen XML WEB Author | 14/4/2023 | 17/6/2026 | A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015 allows an attacker to read files from a WEB-INF directory via a crafted HTTP request. (XML Web Author 24.1.0.3 build 2023021714 and 23.1.1.4 build 2023021715 are also… | |
| Modificada | Alta (8.8) | 1.0% | — | Custom Content Shortcode Project Custom Content Shortcode | 20/3/2023 | 17/6/2026 | The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be… |