Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.24% | — | Hcltech Sametime | 23/10/2024 | 17/6/2026 | HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers. | |
| Analizada | Media (5.3) | 0.55% | — | Oretnom23 Sentiment Based Movie Rating System | 20/10/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Sentiment Based Movie Rating System 1.0. It has been classified as critical. Affected is an unknown function of the file /msrps/movie_details.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Alta (8.3) | 12% | 💥 Exploit | Wpplugin Time Clock | 18/10/2024 | 17/6/2026 | The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The… | |
| Aplazada | Alta (7.1) | 0.36% | — | Spacetime Ad-inserterAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spacetime Ad Inserter ad-inserter allows Reflected XSS.This issue affects Ad Inserter: from n/a through <= 2.7.37. | |
| Modificada | Media (6.1) | 0.17% | — | Ahmetimamoglu Ahmeti WP Timeline | 17/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ahmeti Ahmeti Wp Timeline ahmeti-wp-timeline allows Stored XSS.This issue affects Ahmeti Wp Timeline: from n/a through <= 5.1. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Arraytics WP TimeticsAI | 17/10/2024 | 17/6/2026 | The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to missing validation on a user controlled key. This… | |
| Analizada | Crítica (9.8) | 0.41% | — | Motopress Timetable AND Event Schedule | 16/10/2024 | 17/6/2026 | The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function called via a nopriv AJAX action in versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to call that… | |
| Aplazada | Alta (8.5) | 0.49% | — | Revmakx Backup AND Staging BY WP Time CapsuleAI | 11/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows SQL Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21. | |
| Aplazada | Media (6.1) | 0.45% | — | Increase Upload File Size Maximum Execution Time LimitAI | 11/10/2024 | 17/6/2026 | The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Analizada | Baja (2.9) | 0.15% | — | Bytecodealliance Wasmtime | 9/10/2024 | 17/6/2026 | Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistration bugs due to a race condition, leading to panics and potentially type registry corruption. That registry corruption could, following an… | |
| Analizada | Media (5.5) | 0.24% | — | Bytecodealliance Wasmtime | 9/10/2024 | 17/6/2026 | Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with stack traces can result in a runtime crash in certain WebAssembly modules. The runtime crash may be undefined behavior if Wasmtime was compiled with Rust 1.80 or prior. The runtime crash is a… | |
| Aplazada | Media (6.1) | 0.84% | 💥 Exploit | Elaines Realtime CRM AutomationAI | 7/10/2024 | 5/7/2026 | A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at wrapper_dialog.php. | |
| Aplazada | Alta (7.1) | 0.29% | — | Exthemes WP Timeline Vertical AND Horizontal TimelineAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin wp-timelines allows Reflected XSS.This issue affects WP Timeline – Vertical and Horizontal timeline plugin: from n/a through <= 3.6.7. | |
| Aplazada | Alta (7.5) | 0.51% | — | Exthemes WP Timeline Vertical AND Horizontal TimelineAI | 5/10/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin wp-timelines.This issue affects WP Timeline – Vertical and Horizontal timeline plugin: from n/a through <= 3.6.7. | |
| Aplazada | Alta (8.1) | 0.61% | — | Exthemes WP TimelineAI | 5/10/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin wp-timelines.This issue affects WP Timeline – Vertical and Horizontal timeline plugin: from n/a through <= 3.6.7. | |
| Analizada | Alta (8.5) | 16% | 💥 Exploit | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | |
| Analizada | Media (6.3) | 0.84% | 💥 Exploit | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | |
| Analizada | Alta (7.7) | 0.83% | 💥 Exploit | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | |
| Analizada | Media (5.4) | 13% | — | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | |
| Analizada | Alta (8.7) | 0.44% | — | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7. | |
| Modificada | Alta (8.7) | 0.21% | — | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0. | |
| Modificada | Alta (8.7) | 0.23% | — | Microchip Timeprovider 4100 Firmware | 4/10/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects TimeProvider 4100: from 1.0. | |
| Analizada | Media (5.3) | 0.44% | — | Rems Online Timesheet APP | 29/9/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /endpoint/add-timesheet.php of the component Add Timesheet Form. The manipulation of the argument day/task leads to cross site scripting. The attack can be… | |
| Analizada | Media (5.3) | 0.53% | — | Rems Online Timesheet APP | 29/9/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Timesheet App 1.0. This affects an unknown part of the file /endpoint/delete-timesheet.php. The manipulation of the argument timesheet leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.53% | — | Mmrs151 Daily Prayer Time | 25/9/2024 | 17/6/2026 | The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, and including, 2024.08.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… |