Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.81% | — | Forcepoint Cloud Security GatewayForcepoint Data Loss PreventionForcepoint Email SecurityForcepoint ONE Endpoint With Policy Engine+1 | 12/9/2022 | 17/6/2026 | Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One Endpoint (F1E), Web Security Content Gateway, Email Security with DLP enabled, and Cloud Security Gateway prior to June 20, 2022. The XML… | |
| Modificada | Media (5.4) | 0.70% | — | Adobe WEB Content Management Core Components | 10/8/2022 | 17/6/2026 | Adobe Experience Manager Core Components version 2.20.6 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.… | |
| Modificada | Alta (7.2) | 0.68% | — | Oracle Webcenter Content | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Search). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the… | |
| Modificada | Alta (7.2) | 3.3% | — | Custom Content Type Manager Project Custom Content Type Manager | 6/7/2022 | 17/6/2026 | custom-content-type-manager Wordpress plugin can be used by an administrator to achieve arbitrary PHP remote code execution. | |
| Modificada | Media (5.4) | 0.80% | — | Jenkins CRX Content Package Deployer | 23/6/2022 | 17/6/2026 | Jenkins CRX Content Package Deployer Plugin 1.9 and earlier does not escape the name and description of CRX Content Package Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (8.8) | 0.56% | — | Global Content Blocks Project Global Content Blocks | 23/6/2022 | 17/6/2026 | A vulnerability was found in Global Content Blocks Plugin 2.1.5. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. | |
| Modificada | Media (4.3) | 0.99% | 💥 PoC | Content Mask Project Content Mask | 30/5/2022 | 17/6/2026 | The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. As a result, any authenticated user, such as subscriber could modify arbitrary blog options | |
| Modificada | Media (6.1) | 0.80% | — | Keywordrush Content EGG | 2/5/2022 | 17/6/2026 | The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (5.3) | 0.69% | — | MI Content Center | 21/4/2022 | 17/6/2026 | A improper permission configuration vulnerability in Xiaomi Content Center APP. This vulnerability is caused by the lack of correct permission verification in the Xiaomi content center APP, and attackers can use this vulnerability to invoke the sensitive component functions of the Xiaomi content center APP. | |
| Modificada | Media (5.4) | 0.50% | — | College Website Content Management System Project College Website Content Management System | 5/4/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields. | |
| Modificada | Media (4.8) | 0.54% | — | Totaljs Content Management System | 1/4/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page. | |
| Modificada | Media (6.1) | 0.80% | — | Obtaininfotech Multisite Content Copier/updater | 14/3/2022 | 17/6/2026 | The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.2 does not sanitise and escape the s parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in the network dashboard | |
| Modificada | Media (6.1) | 0.80% | — | Obtaininfotech Multisite Content Copier/updater | 7/3/2022 | 17/6/2026 | The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.0 does not sanitise and escape the wmcc_content_type, wmcc_source_blog and wmcc_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Media (5.4) | 0.60% | — | Custom Content Shortcode Project Custom Content Shortcode | 7/3/2022 | 17/6/2026 | The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. Please note that such attack is still possible by… | |
| Modificada | Media (4.3) | 0.44% | — | Custom Content Shortcode Project Custom Content Shortcode | 7/3/2022 | 17/6/2026 | The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such as logs, .htaccess etc), as well as perform Local File Inclusion attacks as PHP… | |
| Modificada | Media (4.3) | 0.79% | — | Custom Content Shortcode Project Custom Content Shortcode | 7/3/2022 | 17/6/2026 | The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of… | |
| Modificada | Alta (8.8) | 0.42% | — | Wp-buy WP Content Copy Protection & NO Right Click | 21/2/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability leading to plugin Settings Update discovered in WP Content Copy Protection & No Right Click WordPress plugin (versions <= 3.4.4). | |
| Analizada | Crítica (10) | 98% | ⚠ Explotación activa💥 Exploit | SAP Content ServerSAP Netweaver Application Server AbapSAP WEB Dispatcher | 9/2/2022 | 17/6/2026 | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute… | |
| Modificada | Alta (8.8) | 1.8% | — | IBM Filenet Content Manager | 17/1/2022 | 17/6/2026 | IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 212346. | |
| Modificada | Media (4.3) | 0.81% | — | Page/post Content Shortcode Project Page/post Content Shortcode | 13/12/2021 | 17/6/2026 | The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors. | |
| Modificada | Crítica (9.8) | 79% | 💥 Exploit | Ays-pro Secure Copy Content Protection AND Content Locking | 6/12/2021 | 17/6/2026 | The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection. | |
| Modificada | Alta (7.2) | 1.5% | — | Post Content Xmlrpc Project Post Content Xmlrpc | 8/11/2021 | 17/6/2026 | The Post Content XMLRPC WordPress plugin through 1.0 does not sanitise or escape multiple GET/POST parameters before using them in SQL statements in the admin dashboard, leading to an authenticated SQL Injections | |
| Modificada | Media (5.4) | 0.91% | — | Content Text Slider ON Post Project Content Text Slider ON Post | 1/11/2021 | 17/6/2026 | The Content text slider on post WordPress plugin before 6.9 does not sanitise and escape the Title and Message/Content settings, which could lead to Cross-Site Scripting issues | |
| Modificada | Media (5.4) | 0.57% | — | Macrob7 Macs Framework Content Management System Project Macrob7 Macs Framework Content Management System | 22/10/2021 | 17/6/2026 | Macrob7 Macs Framework Content Management System - 1.14f contains a cross-site scripting (XSS) vulnerability in the account reset function, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the e-mail input field. | |
| Modificada | Media (4.8) | 0.99% | — | Content Staging Project Content Staging | 21/10/2021 | 17/6/2026 | The Content Staging WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via several parameters that are echo'd out via the ~/templates/settings.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to… |