Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.61% | — | Increase Maximum Upload File Size Increase Execution TimeAI | 23/11/2024 | 17/6/2026 | The Increase Maximum Upload File Size | Increase Execution Time plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.3. This is due to returning image upload error messages with full path information. This makes it possible for authenticated attackers, with author-level… | |
| Aplazada | Media (6.5) | 0.32% | — | Profit Funnels PF TimerAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Profit Funnels PF Timer pf-timer allows Stored XSS.This issue affects PF Timer: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.20% | — | Techdabang World Prayer TimeAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in techdabang World Prayer Time world-prayer-time allows Stored XSS.This issue affects World Prayer Time: from n/a through <= 2.0. | |
| Analizada | Crítica (9.8) | 0.51% | — | Oretnom23 Sentiment Based Movie Rating System | 19/11/2024 | 17/6/2026 | SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php. | |
| Analizada | Crítica (9.8) | 94% | 💥 Exploit | Revmakx Backup AND Staging BY WP Time Capsule | 16/11/2024 | 17/6/2026 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible for unauthenticated attackers to upload… | |
| Aplazada | Media (5.3) | 0.62% | — | Real Time Logic SharksslAI | 12/11/2024 | 17/6/2026 | A Heap buffer overflow in the server-site handshake implementation in Real Time Logic SharkSSL from 09/09/24 and earlier allows a remote attacker to trigger a Denial-of-Service via a malformed TLS Client Key Exchange message. | |
| Analizada | Media (6.3) | 0.43% | — | Zkteco Zkbio Time | 10/11/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is an unknown function of the file /auth_files/photo/ of the component Image File Handler. The manipulation leads to direct request. It is possible to launch the attack remotely. The complexity of an attack is rather high.… | |
| Aplazada | Alta (7.1) | 0.27% | — | Gopiplus Twitter Real Time Search ScrollingAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Twitter real time search scrolling twitter-real-time-search-scrolling allows Reflected XSS.This issue affects Twitter real time search scrolling: from n/a through <= 7.0. | |
| Aplazada | Media (4.3) | 0.31% | — | Countdown Timer BlockAI | 9/11/2024 | 17/6/2026 | The Countdown Timer block – Display the event's date into a timer. plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.4 via the [ctb] shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers,… | |
| Analizada | Alta (7.5) | 0.51% | — | Bytecodealliance Webassembly Micro Runtime | 8/11/2024 | 17/6/2026 | wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types. | |
| Analizada | Alta (7.8) | 0.63% | — | Bytecodealliance Webassembly Micro Runtime | 8/11/2024 | 17/6/2026 | An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi_compatibility function. | |
| Aplazada | Alta (7.3) | 65% | 💥 Exploit | Symfony RuntimeAI | 6/11/2024 | 17/6/2026 | symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when… | |
| Analizada | Baja (2.3) | 0.84% | — | Bytecodealliance Wasmtime | 5/11/2024 | 17/6/2026 | Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "LPT0", "LPT1", and so on, however it did not block access to the special device filenames which use superscript digits, such as "COM¹",… | |
| Modificada | Media (5.4) | 0.24% | — | Timelord ELO Rating Shortcode | 4/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcel Pol Elo Rating Shortcode elo-rating-shortcode allows Stored XSS.This issue affects Elo Rating Shortcode: from n/a through <= 1.0.3. | |
| Analizada | Crítica (9.8) | 0.53% | — | Arraytics WP Timetics | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Arraytics Timetics allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Timetics: from n/a through 1.0.23. | |
| Aplazada | Media (5.3) | 0.34% | — | Arraytics TimeticsAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.21. | |
| Aplazada | Media (6.5) | 0.27% | — | Time Slot Booking Time SlotAI | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Time Slot Booking Time Slot timeslot allows DOM-Based XSS.This issue affects Time Slot: from n/a through <= 1.3.6. | |
| Analizada | Media (5.3) | 0.48% | — | Projectworlds Online Time Table Generator | 28/10/2024 | 17/6/2026 | A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the file /timetable/staff/staffdashboard.php?info=updateprofile. The manipulation of the argument n leads to sql injection. The attack can be launched… | |
| Analizada | Media (5.3) | 0.54% | — | Projectworlds Online Time Table Generator | 28/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an unknown function of the file /timetable/admin/admindashboard.php?info=add_course. The manipulation of the argument c leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Crítica (9.3) | 1.1% | 💥 PoC | Swit WP Sessions Time Monitoring Full AutomaticAI | 24/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9. | |
| Aplazada | Media (4.3) | 0.34% | — | HurrytimerAI | 24/10/2024 | 17/6/2026 | The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized post publication due to a missing capability check on the activateCampaign() function in all versions up to, and including, 2.10.0. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.5) | 4.2% | 💥 Exploit | Lawo VSM LTC Time SyncAI | 24/10/2024 | 17/6/2026 | The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the… | |
| Analizada | Media (5.3) | 0.24% | — | Hcltech Sametime | 23/10/2024 | 17/6/2026 | HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack. | |
| Aplazada | Alta (7.2) | 0.53% | — | Revmakx WP Time CapsuleAI | 23/10/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Object Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21. | |
| Analizada | Media (4) | 0.17% | — | Hcltech Sametime | 23/10/2024 | 17/6/2026 | HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was enabled by default using the HTTP protocol. An attacker could potentially use this service endpoint maliciously. |