Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
1223 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.99% | — | Wpdownloadmanager Premium Packages - Sell Digital Products Securely | 12/8/2023 | 17/6/2026 | The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a… | |
| Modificada | Media (5.4) | 0.45% | — | Digital-ant Digital ANT | 8/8/2023 | 17/6/2026 | La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ("Cross-Site Scripting") en Digital Ant E-Commerce Software permite la existencia de Cross-Site Scripting (XSS) almacenado. Este problema afecta a las versiones de E-Commerce Software antes de la v11. | |
| Modificada | Media (6.1) | 0.48% | — | Digital-ant Digital ANT | 8/8/2023 | 17/6/2026 | Vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web en Digital Ant E-Commerce Software que permite Cross-Site Scripting (XSS) reflejado. Este problema afecta al software E-Commerce antes de la versión 11. | |
| Modificada | Crítica (9.8) | 0.74% | — | Digital-ant Digital ANT | 8/8/2023 | 17/6/2026 | Vulnerabilidad de neutralización inadecuada de elementos especiales utilizados en un comando SQL en el software Digital Ant E-Commerce que permite inyección SQL en versiones anteriores a la 11. | |
| Modificada | Media (4.8) | 0.37% | — | Rigorous-digital Dovetail | 8/8/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) almacenado con necesidad de autenticación (permisos de administrador o superior) en el plugin Rigorous & Factory Pattern Dovetail en versiones anteriores, e incluyendo, la 1.2.13. | |
| Modificada | Media (4.8) | 0.37% | — | Decondigital Decon WP SMS | 8/8/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) Almacenada en el plugin Decon WP SMS de Decon Digital que afecta las versiones 1.1 e inferiores. Para explotar esta vulnerabilidad hace falta estar autenticado y tener permisos de administrador o superior. | |
| Analizada | Media (4.3) | 0.58% | — | Liferay Digital Experience PlatformLiferay Portal | 2/8/2023 | 17/6/2026 | El selector de organizaciones en Liferay Portal v7.4.3.81 a v7.4.3.85 y Liferay DXP v7.4 actualización 81 a 85 no comprueba el permiso del usuario, lo que permite a usuarios remotos autenticados obtener una lista de todas las organizaciones. | |
| Modificada | Alta (8.8) | 0.32% | — | Digitalinspiration Google XML Sitemap FOR Mobile | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions. | |
| Modificada | Crítica (9.8) | 0.69% | — | Westerndigital MY Cloud OS | 1/7/2023 | 17/6/2026 | An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202. | |
| Modificada | Alta (8.8) | 0.87% | — | Westerndigital MY Cloud OS | 30/6/2023 | 17/6/2026 | A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and execute larger payloads. This issue affects My Cloud OS 5 devices: before 5.26.300. | |
| Modificada | Media (6.7) | 1.3% | — | Westerndigital MY Cloud OS | 30/6/2023 | 17/6/2026 | Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in the context of the root user on vulnerable CGI files. This vulnerability can only be exploited over the network and the attacker must already have admin/root privileges to… | |
| Modificada | Alta (8.8) | 0.26% | — | Digitalinspiration Google XML Sitemap FOR Videos | 15/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions. | |
| Analizada | Media (6.1) | 0.45% | — | Liferay Digital Experience PlatformLiferay Portal | 15/6/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 update 70 through 73 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter. | |
| Modificada | Crítica (9.8) | 1.5% | — | HP Laserjet Managed MFP E62665 3gy14a FirmwareHP Laserjet Managed MFP E62665 3gy15a FirmwareHP Laserjet Managed MFP E62665 3gy16a FirmwareHP Laserjet Managed MFP E62665 3gy17a Firmware+953 | 14/6/2023 | 17/6/2026 | A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products. | |
| Modificada | Media (6.5) | 0.66% | — | Jenkins Digital.ai APP Management Publisher | 14/6/2023 | 17/6/2026 | Una verificación de permiso faltante en Jenkins Digital.ai App Management Publisher Plugin 2.6 y versiones anteriores permite a los atacantes con permiso general/de lectura conectarse a una URL especificada por el atacante y capturar las credenciales almacenadas en Jenkins. | |
| Modificada | Media (6.5) | 0.45% | — | Jenkins Digital.ai APP Management Publisher | 14/6/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect to an attacker-specified URL, capturing credentials stored in Jenkins. | |
| Modificada | Media (5.4) | 1.4% | 💥 Exploit | Digitaldruid Hoteldruid | 13/6/2023 | 17/6/2026 | A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data. | |
| Modificada | Alta (8.8) | 1.5% | 💥 PoC | Digitaldruid Hoteldruid | 13/6/2023 | 17/6/2026 | hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability. | |
| Modificada | Media (5.7) | 0.29% | — | SAP Digital ManufacturingSAP Plant Connectivity | 13/6/2023 | 17/6/2026 | SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of the JSON Web Token (JWT) in the HTTP request sent from SAP Digital Manufacturing. Therefore, unauthorized callers from the internal network could send service requests… | |
| Modificada | Alta (7.5) | 0.59% | — | Westerndigital MY Cloud Pr2100 FirmwareWesterndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra Firmware+8 | 12/6/2023 | 17/6/2026 | Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102;… | |
| Modificada | Alta (7.5) | 0.92% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs. | |
| Analizada | Alta (7.5) | 0.82% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property… | |
| Analizada | Alta (7.5) | 0.74% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL. | |
| Analizada | Media (4.3) | 0.61% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view object definition from a second virtual instance by searching for the object… | |
| Analizada | Media (4.3) | 0.61% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a different virtual instance via OAuth 2 scope administration page. |