Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.2% | — | Swit WP Sessions Time Monitoring Full Automatic | 26/12/2023 | 17/6/2026 | The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an… | |
| Modificada | Media (4.8) | 0.39% | — | Ternstyle Automatic Youtube Video Posts | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ternstyle LLC Automatic Youtube Video Posts Plugin allows Stored XSS.This issue affects Automatic Youtube Video Posts Plugin: from n/a through 5.2.2. | |
| Modificada | Alta (8.8) | 0.30% | — | Wbolt All-in-one Search Automatic Push Management | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in 闪电博 多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 allows Cross Site Request Forgery.This issue affects 多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条: from n/a through 4.2.7. | |
| Modificada | Media (6.1) | 0.46% | — | Autochat Automatic Conversation | 17/7/2023 | 17/6/2026 | The Autochat Automatic Conversation WordPress plugin through 1.1.7 does not sanitise and escape user input before outputting it back on the page, leading to a cross-site Scripting attack. | |
| Modificada | Crítica (9.8) | 4.5% | — | Valvepress Pinterest Automatic PIN | 7/6/2023 | 17/6/2026 | The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for unauthenticated attackers to update arbitrary… | |
| Modificada | Crítica (9.8) | 16% | — | Valvepress Wordpress Automatic Plugin | 7/6/2023 | 17/6/2026 | The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to arbitrarily update the settings of a… | |
| Modificada | Crítica (9.8) | 0.74% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 27/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. This vulnerability affects unknown code of the file users/classes/view_class.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can… | |
| Modificada | Media (6.1) | 0.39% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 23/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Automatic Question Paper Generator System 1.0. This issue affects some unknown processing of the file classes/Master.php?f=save_class. The manipulation of the argument description leads to cross site scripting. The attack may be… | |
| Modificada | Crítica (9.8) | 0.54% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 23/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file admin/courses/view_class.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be… | |
| Modificada | Crítica (9.8) | 0.54% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 23/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Automatic Question Paper Generator System 1.0. This affects an unknown part of the file classes/Users.php?f=save_ruser. The manipulation of the argument id/email leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Modificada | Crítica (9.8) | 0.84% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 17/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file users/question_papers/manage_question_paper.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The… | |
| Modificada | Crítica (9.8) | 0.82% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 17/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/courses/view_course.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql… | |
| Modificada | Alta (8.8) | 0.78% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 17/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Automatic Question Paper Generator System 1.0. Affected is an unknown function of the file users/user/manage_user.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to… | |
| Modificada | Media (4.8) | 0.41% | — | Zkteco Automatic Data Master Server | 9/12/2022 | 17/6/2026 | ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Baja (3.3) | 0.17% | — | Hitachi Jp1/automatic Operation | 6/12/2022 | 17/6/2026 | Generation of Error Message Containing Sensitive Information vulnerability in Hitachi JP1/Automatic Operation allows local users to gain sensitive information. This issue affects JP1/Automatic Operation: from 10-00 through 10-54-03, from 11-00 before 11-51-09, from 12-00 before 12-60-01. | |
| Modificada | Media (6.5) | 0.36% | — | Addify Automatic User Roles Switcher | 31/10/2022 | 17/6/2026 | The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator | |
| Modificada | Alta (7.2) | 1.5% | — | Wpsocket Automatic Grid Image Listing | 16/5/2022 | 17/6/2026 | The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE | |
| Modificada | Crítica (9.8) | 1.2% | — | Automatic Question Paper Generator Project Automatic Question Paper Generator | 18/4/2022 | 17/6/2026 | Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter. | |
| Modificada | Media (6.1) | 0.56% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 29/3/2022 | 17/6/2026 | A vulnerability was found in Automatic Question Paper Generator System 1.0. It has been classified as problematic. This affects the file /aqpg/users/login.php of the component My Account Page. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. It is possible to initiate… | |
| Modificada | Crítica (9.8) | 0.81% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 29/3/2022 | 17/6/2026 | A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely. | |
| Modificada | Crítica (9.8) | 1.4% | — | Trixie TX9 Automatic Food Dispenser Firmware | 26/7/2021 | 17/6/2026 | TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet service is used on port 23 with the default password of 059AnkJ for the root account. The user can then download the filesystem through preinstalled BusyBox utilities (e.g.,… | |
| Modificada | Alta (7.5) | 2.2% | — | Invigo Automatic Device Management | 25/3/2021 | 17/6/2026 | A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to read arbitrary server files accessible to the user running the application. | |
| Modificada | Alta (8.8) | 2.8% | — | Invigo Automatic Device Management | 25/3/2021 | 17/6/2026 | The /admin/admapi.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary OS commands on the server as the user running the application. | |
| Modificada | Crítica (9.8) | 1.6% | — | Invigo Automatic Device Management | 25/3/2021 | 17/6/2026 | A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database. | |
| Modificada | Alta (7.5) | 1.3% | — | Invigo Automatic Device Management | 25/3/2021 | 17/6/2026 | Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (ADM) through 5.0 allow remote attackers to read potentially sensitive data hosted by the application. |