Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

2298 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.61%—Increase Maximum Upload File Size Increase Execution TimeAI23/11/202417/6/2026
The Increase Maximum Upload File Size | Increase Execution Time plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.3. This is due to returning image upload error messages with full path information. This makes it possible for authenticated attackers, with author-level…
AplazadaMedia (6.5)0.32%—Profit Funnels PF TimerAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Profit Funnels PF Timer pf-timer allows Stored XSS.This issue affects PF Timer: from n/a through <= 1.0.0.
AplazadaAlta (7.1)0.20%—Techdabang World Prayer TimeAI19/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in techdabang World Prayer Time world-prayer-time allows Stored XSS.This issue affects World Prayer Time: from n/a through <= 2.0.
AnalizadaCrítica (9.8)0.51%—Oretnom23 Sentiment Based Movie Rating System19/11/202417/6/2026
SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php.
AnalizadaCrítica (9.8)94%💥 ExploitRevmakx Backup AND Staging BY WP Time Capsule16/11/202417/6/2026
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible for unauthenticated attackers to upload…
AplazadaMedia (5.3)0.62%—Real Time Logic SharksslAI12/11/202417/6/2026
A Heap buffer overflow in the server-site handshake implementation in Real Time Logic SharkSSL from 09/09/24 and earlier allows a remote attacker to trigger a Denial-of-Service via a malformed TLS Client Key Exchange message.
AnalizadaMedia (6.3)0.43%—Zkteco Zkbio Time10/11/202417/6/2026
A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is an unknown function of the file /auth_files/photo/ of the component Image File Handler. The manipulation leads to direct request. It is possible to launch the attack remotely. The complexity of an attack is rather high.…
AplazadaAlta (7.1)0.27%—Gopiplus Twitter Real Time Search ScrollingAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Twitter real time search scrolling twitter-real-time-search-scrolling allows Reflected XSS.This issue affects Twitter real time search scrolling: from n/a through <= 7.0.
AplazadaMedia (4.3)0.31%—Countdown Timer BlockAI9/11/202417/6/2026
The Countdown Timer block – Display the event&#039;s date into a timer. plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.4 via the [ctb] shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers,…
AnalizadaAlta (7.5)0.51%—Bytecodealliance Webassembly Micro Runtime8/11/202417/6/2026
wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types.
AnalizadaAlta (7.8)0.63%—Bytecodealliance Webassembly Micro Runtime8/11/202417/6/2026
An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi_compatibility function.
AplazadaAlta (7.3)65%💥 ExploitSymfony RuntimeAI6/11/202417/6/2026
symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when…
AnalizadaBaja (2.3)0.84%—Bytecodealliance Wasmtime5/11/202417/6/2026
Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "LPT0", "LPT1", and so on, however it did not block access to the special device filenames which use superscript digits, such as "COM¹",…
ModificadaMedia (5.4)0.24%—Timelord ELO Rating Shortcode4/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcel Pol Elo Rating Shortcode elo-rating-shortcode allows Stored XSS.This issue affects Elo Rating Shortcode: from n/a through <= 1.0.3.
AnalizadaCrítica (9.8)0.53%—Arraytics WP Timetics1/11/202417/6/2026
Missing Authorization vulnerability in Arraytics Timetics allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Timetics: from n/a through 1.0.23.
AplazadaMedia (5.3)0.34%—Arraytics TimeticsAI1/11/202417/6/2026
Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.21.
AplazadaMedia (6.5)0.27%—Time Slot Booking Time SlotAI29/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Time Slot Booking Time Slot timeslot allows DOM-Based XSS.This issue affects Time Slot: from n/a through <= 1.3.6.
AnalizadaMedia (5.3)0.48%—Projectworlds Online Time Table Generator28/10/202417/6/2026
A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the file /timetable/staff/staffdashboard.php?info=updateprofile. The manipulation of the argument n leads to sql injection. The attack can be launched…
AnalizadaMedia (5.3)0.54%—Projectworlds Online Time Table Generator28/10/202417/6/2026
A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an unknown function of the file /timetable/admin/admindashboard.php?info=add_course. The manipulation of the argument c leads to sql injection. It is possible to launch the attack remotely. The exploit…
AplazadaCrítica (9.3)1.1%💥 PoCSwit WP Sessions Time Monitoring Full AutomaticAI24/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9.
AplazadaMedia (4.3)0.34%—HurrytimerAI24/10/202417/6/2026
The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized post publication due to a missing capability check on the activateCampaign() function in all versions up to, and including, 2.10.0. This makes it possible for authenticated attackers,…
AplazadaAlta (7.5)4.2%💥 ExploitLawo VSM LTC Time SyncAI24/10/202417/6/2026
The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the…
AnalizadaMedia (5.3)0.24%—Hcltech Sametime23/10/202417/6/2026
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.
AplazadaAlta (7.2)0.53%—Revmakx WP Time CapsuleAI23/10/202417/6/2026
Deserialization of Untrusted Data vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Object Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21.
AnalizadaMedia (4)0.17%—Hcltech Sametime23/10/202417/6/2026
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously.