Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.40% | — | Lara-zeus Dynamic DashboardAILara-zeus Filament DashboardAIApache ArtemisAI | 7/10/2024 | 17/6/2026 | Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for the lara-zeus ecosystem. If values passed to a paragraph widget are not valid and contain a specific set of characters, applications are vulnerable to XSS… | |
| Analizada | Media (6.1) | 0.42% | — | Filamentphp Filament | 27/9/2024 | 17/6/2026 | Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a `ColorColumn` or `ColumnEntry` are not valid and contain a specific set of characters, applications are… | |
| Analizada | Alta (7.5) | 0.57% | — | Pxlrbt Filament Excel | 12/8/2024 | 17/6/2026 | Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` in the URL. Patched with Version v2.3.3. | |
| Modificada | Media (4.8) | 0.37% | — | Joshua Vandercar Amen | 14/6/2024 | 17/6/2026 | The Amen WordPress plugin through 3.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (6.3) | 0.43% | — | Xiamen Four-faith RMPAI | 12/4/2024 | 17/6/2026 | A vulnerability was found in Xiamen Four-Faith RMP Router Management Platform 5.2.2. It has been declared as critical. This vulnerability affects unknown code of the file /Device/Device/GetDeviceInfoList?deviceCode=&searchField=&deviceState=. The manipulation of the argument groupId leads to sql injection. The attack… | |
| Aplazada | Media (5.4) | 0.32% | — | Megamenu MAX Mega MenuAI | 28/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Megamenu Max Mega Menu.This issue affects Max Mega Menu: from n/a through 3.3. | |
| Modificada | Alta (7.5) | 0.61% | — | Soisy Pagamento Rateale | 21/10/2023 | 17/6/2026 | The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the parseRemoteRequest function in versions up to, and including, 6.0.1. This makes it possible for unauthenticated attackers with knowledge of an existing WooCommerce Order ID to expose… | |
| Modificada | Media (6.5) | 0.60% | — | Amentotech Workreap | 26/12/2022 | 17/6/2026 | The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id. | |
| Modificada | Alta (7.5) | 0.84% | — | Amentotech Workreap | 5/12/2022 | 17/6/2026 | The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notification ID is brute-forceable. | |
| Modificada | Alta (8.1) | 1.3% | — | Amentotech Workreap | 9/8/2021 | 17/6/2026 | The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects. This allowed a logged in user to modify or delete objects belonging to other users on the site. | |
| Modificada | Alta (8.1) | 0.65% | — | Amentotech Workreap | 9/8/2021 | 17/6/2026 | Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting… | |
| Modificada | Crítica (9.8) | 60% | 💥 Exploit | Amentotech Workreap | 9/8/2021 | 17/6/2026 | The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded… | |
| Modificada | Media (6.1) | 0.91% | — | Megamenu MAX Mega Menu | 21/8/2019 | 17/6/2026 | The megamenu plugin before 2.4 for WordPress has XSS. | |
| Modificada | Media (4.3) | 1.2% | — | Tournament Project Tournament | 6/7/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title. | |
| Modificada | Media (5.4) | 0.27% | — | NBA Sacramento Kings | 19/10/2014 | 17/6/2026 | The Sacramento Kings (aka com.tibco.gse.sports) application 6.0.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 4.9% | — | Epicgames Unreal EngineEpicgames Postal 2Epicgames Raven ShieldEpicgames Swat 4+2 | 12/7/2010 | 16/6/2026 | Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tournament 2003, Postal 2, Raven Shield, and SWAT4, when downloads are enabled, allows remote attackers to execute arbitrary code via a long LEVEL… | |
| Modificada | Media (6.5) | 3.1% | 💥 Exploit | Dameng DM Database Server | 8/6/2010 | 16/6/2026 | Dameng DM Database Server allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors related to the SP_DEL_BAK_EXPIRED procedure in wdm_dll.dll, which triggers memory corruption. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Epic Games Unreal TournamentFrontlines Fuel OF WAR | 19/8/2009 | 16/6/2026 | Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure. | |
| Modificada | Media (4) | 2.2% | 💥 Exploit | Digital Extreme PariahEpic Games Unreal TournamentGroove Games WarpathHuman Head Studios Dead Mans Hand+2 | 19/8/2009 | 16/6/2026 | The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the… | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Steve Dawson Pokermax Poker League Tournament Script | 18/10/2008 | 16/6/2026 | configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie. | |
| Modificada | Alta (7.8) | 3.7% | 💥 Exploit | Epic Games Unreal Tournament 3 | 25/9/2008 | 16/6/2026 | Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Epic Games Unreal Tournament 3 | 31/7/2008 | 16/6/2026 | Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a UDP packet containing a large value in a certain size field, followed by a data string of that size, aka attack 1 in ut3mendo.c. | |
| Modificada | Media (5) | 2.6% | — | Epic Games Unreal Tournament 3 | 31/7/2008 | 16/6/2026 | Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a UDP packet in which the value of a certain size field is greater than the total packet length, aka attack 2 in ut3mendo.c. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Epic Games Unreal Tournament 2004 | 31/7/2008 | 16/6/2026 | Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malformed packets. | |
| Modificada | Alta (10) | 4.6% | 💥 Exploit | Amensa-soft K+b-bestellsystem | 30/11/2007 | 16/6/2026 | kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) domain or (2) tld parameter in a check_owner action. |