Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1236 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.37%—Tychesoftwares Order Delivery Date FOR WP E-commerce2/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= 1.2 versions.
ModificadaMedia (6.1)0.41%—Tychesoftwares Order Delivery Date FOR Woocommerce25/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Order Delivery Date for WooCommerce plugin <= 3.20.0 versions.
ModificadaCrítica (9.8)0.94%💥 PoCFortra Delivernow19/9/202317/6/2026
SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.
ModificadaAlta (7.8)0.38%💥 PoCFoxconn Live Update Utility11/9/202317/6/2026
An issue was discovered in MmMapIoSpace routine in Foxconn Live Update Utility 2.1.6.26, allows local attackers to escalate privileges.
ModificadaMedia (5.4)0.52%—Turt2live Matrix-media-repo8/9/202317/6/2026
matrix-media-repo is a highly customizable multi-domain media repository for the Matrix chat ecosystem. In affected versions an attacker could upload a malicious piece of media to the media repo, which would then be served with `Content-Disposition: inline` upon download. This vulnerability could be leveraged to…
ModificadaMedia (5.5)0.16%—Dell Digital Delivery8/9/202317/6/2026
Dell Digital Delivery versions prior to 5.0.82.0 contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS).
ModificadaCrítica (9.8)15%—Cisco Broadworks Application Delivery PlatformCisco Broadworks Xtended Services Platform6/9/202317/6/2026
A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This vulnerability is due to the method used to…
ModificadaMedia (4.8)0.44%—Mrdemonwolf Livestream Notice30/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MrDemonWolf Livestream Notice plugin <= 1.2.0 versions.
ModificadaCrítica (9.8)0.89%—Phpjabbers Food Delivery Script28/8/202317/6/2026
User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)3.7%💥 ExploitPhpjabbers Food Delivery Script28/8/202317/6/2026
PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.
ModificadaCrítica (9.8)3.3%💥 ExploitPhpjabbers Food Delivery Script28/8/202317/6/2026
PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.
ModificadaAlta (8.1)0.59%—Bishopfox Sliver28/8/202317/6/2026
Sliver from v1.5.x to v1.5.39 has an improper cryptographic implementation, which allows attackers to execute a man-in-the-middle attack via intercepted and crafted responses.
ModificadaMedia (4.8)0.37%—Davidmichaelross Dave's Wordpress Live Search17/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dave Ross Dave's WordPress Live Search plugin <= 4.8.1 versions.
ModificadaMedia (6.1)0.68%—JBT Live (github-flavored) Markdown Editor11/8/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Rendering Engine in jbt Markdown Editor thru commit 2252418c27dffbb35147acd8ed324822b8919477, allows remote attackers to execute arbirary code via crafted payload or opening malicious .md file.
ModificadaAlta (7.8)0.16%—Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Database ServerCisco Broadworks Execution Server+83/8/202317/6/2026
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability…
ModificadaMedia (5.4)0.45%—Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Xtended Services Platform3/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly…
ModificadaAlta (8)1.3%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/7/202317/6/2026
Privilege Escalation to root administrator (nsroot)
ModificadaMedia (6.1)2.6%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/7/202317/6/2026
Reflected Cross-Site Scripting (XSS)
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/7/20235/8/2026
Unauthenticated remote code execution
ModificadaMedia (6.1)0.32%—Livelyworks Articart16/7/202317/6/2026
A vulnerability was found in LivelyWorks Articart 2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /change-language/de_DE of the component Base64 Encoding Handler. The manipulation of the argument redirectTo leads to open redirect. The attack may be launched…
ModificadaMedia (5.4)0.36%—Livelyworks Articart16/7/202317/6/2026
A vulnerability has been found in LivelyWorks Articart 2.0.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /items/search. The manipulation of the argument search_term leads to cross site scripting. The attack can be launched remotely. The identifier VDB-234229…
ModificadaMedia (6)0.20%—Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+1212/7/202317/6/2026
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected…
ModificadaMedia (4.3)0.30%—Citrix Virtual Apps AND DesktopsCitrix Linux Virtual Delivery Agent10/7/202317/6/2026
Users with only access to launch VDA applications can launch an unauthorized desktop
ModificadaMedia (6.1)81%💥 ExploitCitrix GatewayCitrix Application Delivery Controller10/7/202317/6/2026
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting
ModificadaAlta (7.5)1.1%—Citrix Application Delivery ControllerCitrix Gateway10/7/202317/6/2026
Arbitrary file read in Citrix ADC and Citrix Gateway
Orbitaley — Vulnerabilidades