Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

97 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.27%—Freshlightlab WP Mobile Menu7/6/202417/6/2026
The WP Mobile Menu – The Mobile-Friendly Responsive Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 2.8.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level…
AplazadaMedia (4.7)0.38%—Freshworks FreshdeskAI15/4/202417/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Freshworks Freshdesk (official).This issue affects Freshdesk (official): from n/a through 2.3.6.
AnalizadaCrítica (9.8)0.69%—Remyandrade Crud Without Page Reload/refresh12/3/202417/6/2026
A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file add_user.php. The manipulation of the argument city leads to sql injection. The attack can be launched remotely. The exploit has been…
ModificadaAlta (8.8)0.85%—Rymera Auto Refresh Single Page5/3/202417/6/2026
The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1 via deserialization of untrusted input from the arsp_options post meta option. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP…
AnalizadaMedia (6.1)0.57%—Remyandrade Crud Without Page Reload/refresh3/2/202417/6/2026
A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file fetch_data.php. The manipulation of the argument username/city leads to cross site scripting. The attack may be launched remotely. The exploit has…
ModificadaAlta (8.8)0.21%—Borbis Freshmail FOR Wordpress31/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Borbis Media FreshMail For WordPress.This issue affects FreshMail For WordPress: from n/a through 2.3.2.
ModificadaMedia (4.8)0.35%—Freshlightlab Menu Image, Icons Made Easy21/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Freshlight Lab Menu Image, Icons made easy allows Stored XSS.This issue affects Menu Image, Icons made easy: from n/a through 3.10.
ModificadaMedia (6.1)0.29%—Borbis Freshmail FOR Wordpress26/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Borbis Media FreshMail For WordPress plugin <= 2.3.2 versions.
ModificadaMedia (5.3)0.45%—Littlebigfresh Bunkum18/10/202317/6/2026
Bunkum is an open-source protocol-agnostic request server for custom game servers. First, a little bit of background. So, in the beginning, Bunkum's `AuthenticationService` only supported injecting `IUser`s. However, as Refresh and SoundShapesServer implemented permissions systems support for injecting `IToken`s into…
ModificadaCrítica (9.8)2.4%—Freshtomato16/10/202317/6/2026
An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaMedia (4.8)0.39%—8web Read More Without Refresh9/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eightweb Interactive Read More Without Refresh plugin <= 3.1 versions.
ModificadaMedia (6.1)0.45%—Freshworks Freshdesk17/4/202317/6/2026
A vulnerability, which was classified as critical, has been found in Freshdesk Plugin 1.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to open redirect. The attack may be launched remotely. Upgrading to version 1.8 is able to address this issue. The patch is identified as…
ModificadaMedia (5.5)0.47%—Freshrss6/3/202317/6/2026
FreshRSS is a self-hosted RSS feed aggregator. When using the greader API, the provided password is logged in clear in `users/_/log_api.txt` in the case where the authentication fails. The issues occurs in `authorizationToUser()` in `greader.php`. If there is an issue with the request or the credentials,…
ModificadaCrítica (9.8)6.0%—FreshtomatoSiretta Quartz-gold Firmware30/1/202317/6/2026
An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (7.5)2.1%—FreshtomatoSiretta Quartz-gold Firmware30/1/202317/6/2026
A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (7.5)0.88%—Freshrss9/12/202217/6/2026
FreshRSS is a free, self-hostable RSS aggregator. User configuration files can be accessed by a remote user. In addition to user preferences, such configurations contain hashed passwords (brypt with cost 9, salted) of FreshRSS Web interface. If the API is used, the configuration might contain a hashed password (brypt…
ModificadaAlta (8.1)0.52%—Freshworks Freshservice Agent12/9/202217/6/2026
FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulnerable to Broken integrity checking via the FreshAgent client and scheduled update service.
ModificadaAlta (8.1)0.94%—Freshworks Freshservice AgentFreshworks Freshservice Probe12/9/202217/6/2026
FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the FreshAgent client and scheduled update service.
ModificadaCrítica (9.8)1.3%—Freshtomato5/8/202217/6/2026
A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-arm` has a vulnerable URL-decoding feature that can lead to memory…
ModificadaCrítica (9.8)1.5%—Freshtomato5/8/202217/6/2026
A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-mips` has a vulnerable URL-decoding feature that can lead to memory…
ModificadaMedia (5.4)0.60%—Freshlightlab Menu Image, Icons Made Easy28/3/202217/6/2026
The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving menu settings, and does not validate, sanitise and escape them. As a result, any authenticate users, such as subscriber can update the settings or arbitrary menu and put Cross-Site Scripting payloads…
ModificadaCrítica (9.6)2.2%—PHP Crud Without Refresh/reload Using Ajax AND Datatables Tutorial Project PHP Crud Without Refresh/reload Using Ajax AND Datatables Tutorial24/1/202217/6/2026
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud.
ModificadaMedia (5.5)0.28%—Lenovo Thinkcentre E93 FirmwareLenovo Thinkcentre M6500s FirmwareLenovo Thinkcentre M6500t FirmwareLenovo Thinkcentre M73p Firmware+17814/2/202017/6/2026
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.
ModificadaAlta (8.8)2.2%—Freshmail-newsletter22/10/201917/6/2026
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.
ModificadaAlta (7.5)1.1%—Jenkins Codefresh Integration7/8/201917/6/2026
Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
Orbitaley — Vulnerabilidades