Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
1209 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.45% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form's `name` field. | |
| Modificada | Media (4.9) | 0.77% | — | Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware | 18/5/2023 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords, users and device configurations was discovered in Western Digital My Cloud Home, My Cloud Home Duo,… | |
| Modificada | Crítica (9.8) | 1.5% | — | Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware | 18/5/2023 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesystem types leading to remote code execution was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western… | |
| Modificada | Media (4.9) | 0.57% | — | Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware | 18/5/2023 | 17/6/2026 | An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My… | |
| Modificada | Alta (7.8) | 0.21% | — | Digitalpersona Fpsensor Project Digitalpersona Fpsensor | 11/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in DigitalPersona FPSensor 1.0.0.1. This issue affects some unknown processing of the file C:\Program Files (x86)\FPSensor\bin\DpHost.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement. The identifier VDB-228773… | |
| Modificada | Media (5.5) | 0.14% | — | Westerndigital MY Cloud OS | 10/5/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices. This could allow the URL to exploit other vulnerabilities on the local server.This issue affects My Cloud… | |
| Modificada | Crítica (9.8) | 1.4% | — | Westerndigital MY Cloud OS | 10/5/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This command could be triggered by an attacker remotely to cause code execution… | |
| Modificada | Crítica (9.8) | 1.8% | — | Westerndigital MY Cloud OS | 10/5/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119. | |
| Modificada | Alta (7.5) | 0.30% | — | Westerndigital MY Cloud Home FirmwareWesterndigital MY Cloud Home DUO FirmwareWesterndigital Sandisk IBI Firmware | 10/5/2023 | 17/6/2026 | An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191. | |
| Modificada | Alta (8.1) | 0.56% | — | Westerndigital MY Cloud Home DUO FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home Firmware | 10/5/2023 | 17/6/2026 | A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to… | |
| Modificada | Media (4.8) | 0.37% | — | Blackandwhitedigital Treepress | 9/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Black and White Digital Ltd TreePress – Easy Family Trees & Ancestor Profiles plugin <= 2.0.22 versions. | |
| Modificada | Media (4.3) | 0.46% | — | Westerndigital MY CloudWesterndigital MY Cloud HomeWesterndigital MY Cloud OS 5Westerndigital Sandisk IBI | 8/5/2023 | 17/6/2026 | A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy and missing… | |
| Modificada | Media (5.4) | 0.44% | — | Topdigitaltrends Ultimate Carousel FOR Elementor | 8/5/2023 | 17/6/2026 | The Ultimate Carousel For Elementor WordPress plugin through 2.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.44% | — | Topdigitaltrends Mega Addons FOR Wpbakery Page Builder | 8/5/2023 | 17/6/2026 | The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.44% | — | Topdigitaltrends Ultimate Carousel FOR Wpbakery Page Builder | 8/5/2023 | 17/6/2026 | The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | Virtualreception Digital Reciptie | 4/5/2023 | 17/6/2026 | Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allows attacker to gain sensitive information via a crafted GET request. | |
| Modificada | Media (5.4) | 0.66% | 💥 PoC | Digitaldruid Hoteldruid | 3/5/2023 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function. | |
| Modificada | Crítica (9.8) | 3.1% | 💥 Exploit | Awesomemotive Easy Digital Downloads | 2/5/2023 | 17/6/2026 | Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1. | |
| Modificada | Media (4.8) | 0.37% | — | Digitalblue Click TO Call OR Chat Buttons | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DIGITALBLUE Click to Call or Chat Buttons plugin <= 1.4.0 versions. | |
| Modificada | Alta (7.8) | 0.33% | — | Adobe Digital Editions | 12/4/2023 | 17/6/2026 | Adobe Digital Editions version 4.5.11.187303 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (4.8) | 0.42% | — | Mrdigital Simple Image Popup | 29/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mr Digital Simple Image Popup plugin <= 1.3.6 versions. | |
| Modificada | Alta (7.4) | 0.31% | — | Westerndigital Sandisk Privateaccess | 24/3/2023 | 17/6/2026 | SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data. | |
| Modificada | Crítica (9.8) | 0.72% | — | Ibexa Digital Experience PlatformIbexa Ezplatform-http-cache-fastlyIbexa FastlyIbexa EZ Platform Kernel+1 | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled. | |
| Modificada | Baja (3.7) | 0.46% | — | Ibexa CommerceIbexa Digital Experience PlatformIbexa EZ PlatformIbexa Ezplatform-page-builder+3 | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack. | |
| Modificada | Alta (7.2) | 0.86% | — | Ibexa Digital Experience PlatformIbexa EZ PlatformIbexa EZ Platform Kernel | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges. |