Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
815 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.38% | — | Youhua Windows Master | 29/5/2020 | 17/6/2026 | In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xF1002558 | |
| Modificada | Media (4.3) | 0.63% | — | SAP Master Data Governance | 12/5/2020 | 17/6/2026 | SAP Master Data Governance, versions - 748, 749, 750, 751, 752, 800, 801, 802, 803, 804, allows users to display change request details without having required authorizations, due to Missing Authorization Check. | |
| Modificada | Alta (8.8) | 0.98% | — | SAP Master Data Governance (s4core)SAP Master Data Governance (s4fnd)Master Data Governance (sap BS Fnd) | 12/5/2020 | 17/6/2026 | The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection. | |
| Modificada | Alta (8.8) | 1.6% | 💥 Exploit | Kemptechnologies Load Master | 7/2/2020 | 17/6/2026 | A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages. | |
| Modificada | Media (5.3) | 2.4% | — | Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications BRM - Elastic Charging EngineOracle Communications Diameter Signaling Router+23 | 17/1/2020 | 17/6/2026 | Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and… | |
| Modificada | Alta (7.5) | 89% | 💥 PoC | Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Policy+29 | 17/1/2020 | 17/6/2026 | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input. | |
| Modificada | Alta (8.8) | 8.0% | 💥 Exploit | Progress Loadmaster | 8/1/2020 | 13/7/2026 | A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI). | |
| Modificada | Media (6.1) | 1.7% | — | Expresstech Quiz AND Survey Master | 13/12/2019 | 17/6/2026 | The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php.… | |
| Modificada | Alta (7.2) | 0.81% | — | Inist Ezmaster | 29/11/2019 | 17/6/2026 | The admin sys mode is now conditional and dedicated for the special case. By default, since ezmaster@5.2.11 no instance (container) is launched with advanced capabilities (not launched as root) | |
| Modificada | Alta (8.8) | 1.8% | — | Terra-master F2-210 Firmware | 28/10/2019 | 17/6/2026 | An issue was discovered on TerraMaster FS-210 4.0.19 devices. Normal users can use 1.user.php for privilege elevation. | |
| Modificada | Alta (7.5) | 1.9% | — | Terra-master Fs-210 Firmware | 23/10/2019 | 17/6/2026 | An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring. | |
| Modificada | Media (6.5) | 1.4% | — | Terra-master Fs-210 Firmware | 23/10/2019 | 17/6/2026 | An issue was discovered on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read unauthorized shared files, as demonstrated by the filename=*public*%25252Fadmin_OnlyRead.txt substring. | |
| Modificada | Alta (7.5) | 1.6% | — | Terra-master Fs-210 Firmware | 23/10/2019 | 17/6/2026 | An issue was discovered on TerraMaster FS-210 4.0.19 devices. One can download backup files remotely from terramaster_TNAS-00E43A_config_backup.bin without permission. | |
| Modificada | Media (5.4) | 0.68% | — | Tibco Master Data Management | 9/10/2019 | 17/6/2026 | The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks. This issue affects TIBCO Software Inc.'s TIBCO MDM version 9.0.1 and prior versions; version 9.1.0. | |
| Modificada | Alta (7.5) | 0.95% | — | Jenkins Inedo Buildmaster | 25/9/2019 | 17/6/2026 | Jenkins Inedo BuildMaster Plugin 2.4.0 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. | |
| Modificada | Media (6.5) | 0.65% | — | Prospecta Master Data Online | 20/9/2019 | 17/6/2026 | Prospecta Master Data Online (MDO) allows CSRF. | |
| Modificada | Alta (8.8) | 1.9% | — | Webmaster-source Gocodes | 20/9/2019 | 17/6/2026 | The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection. | |
| Modificada | Media (5.4) | 1.0% | — | Webmaster-source Gocodes | 20/9/2019 | 17/6/2026 | The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php deletegc XSS. | |
| Modificada | Media (5.4) | 0.94% | — | Prospecta Master Data Online | 15/8/2019 | 17/6/2026 | Prospecta Master Data Online (MDO) 2.0 has Stored XSS. | |
| Modificada | Crítica (9.8) | 56% | 💥 Exploit | Barni Master IP Camera01 Firmware | 8/5/2019 | 17/6/2026 | MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component. | |
| Modificada | Media (6.5) | 1.3% | — | Omron Poweract PRO Master Agent | 27/3/2019 | 17/6/2026 | PowerAct Pro Master Agent for Windows Version 5.13 and earlier allows authenticated attackers to bypass access restriction to alter or edit unauthorized files via unspecified vectors. | |
| Modificada | Media (5.9) | 1.4% | — | Mastercard Qkr! With Masterpass | 21/3/2019 | 17/6/2026 | The MasterCard Qkr! app before 5.0.8 for iOS has Missing SSL Certificate Validation. NOTE: this CVE only applies to obsolete versions from 2016 or earlier. | |
| Modificada | Media (6.1) | 1.6% | — | Quizandsurveymaster Quiz AND Survey Master | 5/3/2019 | 17/6/2026 | The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS. | |
| Modificada | Media (5.4) | 0.70% | — | Averta Master Slider | 23/12/2018 | 17/6/2026 | The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback. | |
| Modificada | Alta (7.5) | 1.2% | — | Asustor Data Master | 4/12/2018 | 17/6/2026 | Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title. |