Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2610▼ 308 respecto a la semana anterior
Críticas / altas1345▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.26% | — | Bowo Debug LOG Manager | 30/11/2023 | 17/6/2026 | The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the clear_log() function. This makes it possible for unauthenticated attackers to clear the debug log via a forged request granted… | |
| Modificada | Alta (8.8) | 0.39% | — | Wpindeed Debug Assistant | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions. | |
| Modificada | Alta (7.8) | 0.14% | — | Intel Server Debug AND Provisioning Tool | 11/8/2023 | 17/6/2026 | Incorrect default permissions in some Intel(R) SDP Tool software before version 1.4 build 5 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.26% | — | Template Debugger Project Template Debugger | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Danny Hearnah - ChubbyNinjaa Template Debugger plugin <= 3.1.2 versions. | |
| Modificada | Media (5.3) | 0.27% | — | Madefornet Http Debugger | 5/7/2023 | 17/6/2026 | In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it is possible for an unprivileged application to obtain a handle to the NetFilterSDK wrapper before the service obtains exclusive access. | |
| Modificada | Media (4.8) | 0.44% | — | Wpindeed Debug Assistant | 16/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions. | |
| Modificada | Media (5.5) | 0.19% | — | Edb-debugger Project Edb-debugger | 4/4/2023 | 17/6/2026 | An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp. | |
| Modificada | Media (6.1) | 0.56% | — | Wordpress Debug BAR | 11/3/2023 | 16/6/2026 | A vulnerability was found in dd32 Debug Bar Plugin up to 0.8 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function render of the file panels/class-debug-bar-queries.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version… | |
| Modificada | Alta (7.5) | 2.0% | — | Debug Project Debug | 9/1/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in debug-js debug up to 3.0.x. This affects the function useColors of the file src/node.js. The manipulation of the argument str leads to inefficient regular expression complexity. Upgrading to version 3.1.0 is able to address this issue. The identifier of the… | |
| Modificada | Alta (7.5) | 0.54% | — | Intel Server Debug AND Provisioning Tool | 11/11/2022 | 17/6/2026 | Improper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information disclosure via network access. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa | Apache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+51 | 14/12/2021 | 17/6/2026 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,… | |
| Modificada | Media (5.4) | 0.98% | — | Debug Meta Data Project Debug Meta Data | 7/12/2021 | 17/6/2026 | The debug-meta-data plugin 1.1.2 for WordPress allows XSS. | |
| Modificada | Media (6.5) | 0.57% | — | WP Debugging Project WP Debugging | 25/10/2021 | 17/6/2026 | The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF checks, as a result, the settings can be updated by unauthenticated users. | |
| Modificada | Alta (7.1) | 0.39% | — | Lrzsz Project LrzszSuse Linux Enterprise DebuginfoSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 2/6/2021 | 17/6/2026 | lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around. | |
| Modificada | Crítica (9.8) | 1.9% | — | Jazzband Django Debug Toolbar | 14/4/2021 | 17/6/2026 | A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form. | |
| Modificada | Crítica (9.1) | 1.3% | — | Chameleon Mini Live Debugger Project Chameleon Mini Live Debugger | 28/8/2020 | 17/6/2026 | Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending all users upgrade to v1.1.8 as soon as possible. For more information, review the referenced GitHub Security Advisory. | |
| Modificada | Crítica (9.8) | 1.0% | — | Octobercms Debugbar | 4/6/2020 | 17/6/2026 | The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each request including session data) whenever it is enabled. This presents a problem if the plugin is ever enabled on a system that is open to untrusted users as the potential… | |
| Modificada | Baja (3.5) | 0.98% | — | QemuFedoraproject FedoraNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+7 | 31/1/2020 | 17/6/2026 | The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors. | |
| Modificada | Media (6.5) | 3.6% | — | QemuFedoraproject FedoraCanonical Ubuntu LinuxSuse Linux Enterprise Debuginfo+4 | 23/1/2020 | 17/6/2026 | Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop. | |
| Modificada | Media (5.3) | 4.3% | — | LibgdPHPCanonical Ubuntu LinuxDebian Linux+9 | 19/6/2019 | 17/6/2026 | When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead… | |
| Modificada | Media (5.3) | 7.1% | — | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing. | |
| Modificada | Media (5.3) | 7.1% | — | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing. | |
| Modificada | Media (5.3) | 7.1% | — | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing. | |
| Modificada | Media (5.3) | 7.1% | — | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing. | |
| Modificada | Media (5.3) | 2.9% | — | Debug Project Debug | 7/6/2018 | 17/6/2026 | The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue. |