Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
1223 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 14% | — | Aigital Wireless-n Repeater Mini Router Firmware | 2/5/2023 | 17/6/2026 | An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to bypass login by connecting to the web app after a successful attempt by a legitimate user. | |
| Modificada | Crítica (9.8) | 3.1% | 💥 Exploit | Awesomemotive Easy Digital Downloads | 2/5/2023 | 17/6/2026 | Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1. | |
| Modificada | Media (5.4) | 29% | — | Aigital Wireless-n Repeater Mini Router Firmware | 28/4/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the wl_ssid parameter at /boafrm/formHomeWlanSetup. | |
| Modificada | Crítica (9.8) | 2.2% | — | Aigital Wireless-n Repeater Mini Router Firmware | 26/4/2023 | 9/7/2026 | Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request. | |
| Modificada | Media (4.8) | 0.37% | — | Digitalblue Click TO Call OR Chat Buttons | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DIGITALBLUE Click to Call or Chat Buttons plugin <= 1.4.0 versions. | |
| Modificada | Alta (7.8) | 0.33% | — | Adobe Digital Editions | 12/4/2023 | 17/6/2026 | Adobe Digital Editions version 4.5.11.187303 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (4.8) | 0.42% | — | Mrdigital Simple Image Popup | 29/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mr Digital Simple Image Popup plugin <= 1.3.6 versions. | |
| Modificada | Alta (7.4) | 0.31% | — | Westerndigital Sandisk Privateaccess | 24/3/2023 | 17/6/2026 | SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data. | |
| Modificada | Crítica (9.8) | 0.72% | — | Ibexa Digital Experience PlatformIbexa Ezplatform-http-cache-fastlyIbexa FastlyIbexa EZ Platform Kernel+1 | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled. | |
| Modificada | Baja (3.7) | 0.46% | — | Ibexa CommerceIbexa Digital Experience PlatformIbexa EZ PlatformIbexa Ezplatform-page-builder+3 | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack. | |
| Modificada | Alta (7.2) | 0.86% | — | Ibexa Digital Experience PlatformIbexa EZ PlatformIbexa EZ Platform Kernel | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges. | |
| Modificada | Media (6.5) | 0.57% | — | MV Idigital Clinic Enterprise Project MV Idigital Clinic Enterprise | 27/2/2023 | 17/6/2026 | MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext. | |
| Modificada | Crítica (9.8) | 12% | — | GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+5 | 23/2/2023 | 17/6/2026 | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code. | |
| Modificada | Crítica (9.8) | 2.9% | — | GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+5 | 23/2/2023 | 17/6/2026 | The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code. | |
| Modificada | Media (5.4) | 0.46% | — | Sandhillsdev Easy Digital Downloads | 21/2/2023 | 17/6/2026 | The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Crítica (9.8) | 0.81% | — | Westerndigital MY Cloud OS | 6/2/2023 | 17/6/2026 | Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files. | |
| Modificada | Alta (8.8) | 1.0% | — | Westerndigital MY Cloud OS | 6/2/2023 | 17/6/2026 | Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation. | |
| Modificada | Crítica (9.8) | 1.2% | — | Westerndigital MY Cloud OS | 6/2/2023 | 17/6/2026 | Western Digital My Cloud devices before OS5 have a nobody account with a blank password. | |
| Modificada | Crítica (9.8) | 36% | — | Westerndigital MY Cloud Pr2100 FirmwareWesterndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra Firmware+4 | 26/1/2023 | 17/6/2026 | Una vulnerabilidad en el servicio FTP de los dispositivos Western Digital My Cloud OS 5 que ejecutan versiones de firmware anteriores a la 5.26.119 permite a un atacante leer y escribir archivos arbitrarios. Esto podría provocar un compromiso total del NAS y proporcionaría capacidades de ejecución remota al atacante. | |
| Modificada | Crítica (9.8) | 1.2% | — | Westerndigital MY Cloud Pr2100 FirmwareWesterndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra Firmware+4 | 26/1/2023 | 17/6/2026 | Una vulnerabilidad de inyección de comandos en la configuración del servicio DDNS de dispositivos Western Digital My Cloud OS 5 que ejecutan versiones de firmware anteriores a la 5.26.119 permite a un atacante ejecutar código en el contexto del usuario root. | |
| Modificada | Crítica (9.8) | 11% | 💥 Exploit | Sandhillsdev Easy Digital Downloads | 20/1/2023 | 17/6/2026 | El complemento Easy Digital Downloads de WordPress, versiones 3.1.0.2 y 3.1.0.2. 3.1.0.3, se ve afectado por una vulnerabilidad de inyección SQL no autenticada en el parámetro 's' de su acción 'edd_download_search'. | |
| Modificada | Crítica (9.1) | 0.85% | — | Digitalocean Golang-nanoauth | 27/12/2022 | 17/6/2026 | La autenticación se omite globalmente en github.com/nanobox-io/golang-nanoauth entre v0.0.0-20160722212129-ac0cc4484ad4 y v0.0.0-20200131131040-063a3fb69896 si se llama a ListenAndServe con un token vacío. | |
| Modificada | Media (6.1) | 0.49% | — | Speakdigital Bulk Delete Users BY Email | 26/12/2022 | 17/6/2026 | El complemento Bulk Delete Users by Email de WordPress hasta la versión 1.2 no sanitiza ni escapa un parámetro antes de devolverlo a la página, lo que genera un Cross-Site Scripting (XSS) Reflejado. | |
| Modificada | Media (6.5) | 0.33% | — | Speakdigital Bulk Delete Users BY Email | 26/12/2022 | 17/6/2026 | El complemento Bulk Delete Users by Email de WordPress hasta la versión 1.2 no tiene verificación CSRF al eliminar usuarios, lo que podría permitir a los atacantes hacer que un administrador que haya iniciado sesión elimine a los usuarios que no son administradores conociendo su correo electrónico a través de un… | |
| Modificada | Media (6.1) | 0.37% | — | Hcltech HCL Digital Experience | 19/12/2022 | 17/6/2026 | En HCL Digital Experience, se pueden crear URL para redirigir a los usuarios a sitios que no son de confianza. |