Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.40%—Lara-zeus Dynamic DashboardAILara-zeus Filament DashboardAIApache ArtemisAI7/10/202417/6/2026
Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for the lara-zeus ecosystem. If values passed to a paragraph widget are not valid and contain a specific set of characters, applications are vulnerable to XSS…
AnalizadaMedia (6.1)0.42%—Filamentphp Filament27/9/202417/6/2026
Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a `ColorColumn` or `ColumnEntry` are not valid and contain a specific set of characters, applications are…
AnalizadaAlta (7.5)0.57%—Pxlrbt Filament Excel12/8/202417/6/2026
Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` in the URL. Patched with Version v2.3.3.
ModificadaMedia (4.8)0.37%—Joshua Vandercar Amen14/6/202417/6/2026
The Amen WordPress plugin through 3.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AplazadaMedia (6.3)0.43%—Xiamen Four-faith RMPAI12/4/202417/6/2026
A vulnerability was found in Xiamen Four-Faith RMP Router Management Platform 5.2.2. It has been declared as critical. This vulnerability affects unknown code of the file /Device/Device/GetDeviceInfoList?deviceCode=&searchField=&deviceState=. The manipulation of the argument groupId leads to sql injection. The attack…
AplazadaMedia (5.4)0.32%—Megamenu MAX Mega MenuAI28/3/202417/6/2026
Missing Authorization vulnerability in Megamenu Max Mega Menu.This issue affects Max Mega Menu: from n/a through 3.3.
ModificadaAlta (7.5)0.61%—Soisy Pagamento Rateale21/10/202317/6/2026
The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the parseRemoteRequest function in versions up to, and including, 6.0.1. This makes it possible for unauthenticated attackers with knowledge of an existing WooCommerce Order ID to expose…
ModificadaMedia (6.5)0.60%—Amentotech Workreap26/12/202217/6/2026
The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id.
ModificadaAlta (7.5)0.84%—Amentotech Workreap5/12/202217/6/2026
The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notification ID is brute-forceable.
ModificadaAlta (8.1)1.3%—Amentotech Workreap9/8/202117/6/2026
The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects. This allowed a logged in user to modify or delete objects belonging to other users on the site.
ModificadaAlta (8.1)0.65%—Amentotech Workreap9/8/202117/6/2026
Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting…
ModificadaCrítica (9.8)60%💥 ExploitAmentotech Workreap9/8/202117/6/2026
The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded…
ModificadaMedia (6.1)0.91%—Megamenu MAX Mega Menu21/8/201917/6/2026
The megamenu plugin before 2.4 for WordPress has XSS.
ModificadaMedia (4.3)1.2%—Tournament Project Tournament6/7/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title.
ModificadaMedia (5.4)0.27%—NBA Sacramento Kings19/10/201417/6/2026
The Sacramento Kings (aka com.tibco.gse.sports) application 6.0.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (9.3)4.9%—Epicgames Unreal EngineEpicgames Postal 2Epicgames Raven ShieldEpicgames Swat 4+212/7/201016/6/2026
Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tournament 2003, Postal 2, Raven Shield, and SWAT4, when downloads are enabled, allows remote attackers to execute arbitrary code via a long LEVEL…
ModificadaMedia (6.5)3.1%💥 ExploitDameng DM Database Server8/6/201016/6/2026
Dameng DM Database Server allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors related to the SP_DEL_BAK_EXPIRED procedure in wdm_dll.dll, which triggers memory corruption.
ModificadaMedia (5)2.8%💥 ExploitEpic Games Unreal TournamentFrontlines Fuel OF WAR19/8/200916/6/2026
Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure.
ModificadaMedia (4)2.2%💥 ExploitDigital Extreme PariahEpic Games Unreal TournamentGroove Games WarpathHuman Head Studios Dead Mans Hand+219/8/200916/6/2026
The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the…
ModificadaAlta (7.5)2.7%💥 ExploitSteve Dawson Pokermax Poker League Tournament Script18/10/200816/6/2026
configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie.
ModificadaAlta (7.8)3.7%💥 ExploitEpic Games Unreal Tournament 325/9/200816/6/2026
Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
ModificadaAlta (7.5)11%💥 ExploitEpic Games Unreal Tournament 331/7/200816/6/2026
Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a UDP packet containing a large value in a certain size field, followed by a data string of that size, aka attack 1 in ut3mendo.c.
ModificadaMedia (5)2.6%—Epic Games Unreal Tournament 331/7/200816/6/2026
Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a UDP packet in which the value of a certain size field is greater than the total packet length, aka attack 2 in ut3mendo.c.
ModificadaMedia (5)7.7%💥 ExploitEpic Games Unreal Tournament 200431/7/200816/6/2026
Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malformed packets.
ModificadaAlta (10)4.6%💥 ExploitAmensa-soft K+b-bestellsystem30/11/200716/6/2026
kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) domain or (2) tld parameter in a check_owner action.
Orbitaley — Vulnerabilidades