Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

107 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)2.0%—Logsign Unified Secops Platform21/8/202417/6/2026
Logsign Unified SecOps Platform Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaMedia (6.5)1.2%—Logsign Unified Secops Platform6/8/202417/6/2026
Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within…
AnalizadaMedia (6.1)0.36%—Masdiblogs WP Ajax Contact Form30/7/202417/6/2026
The WP Ajax Contact Form WordPress plugin through 2.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin users
AnalizadaMedia (4.3)0.22%—Masdiblogs WP Ajax Contact Form30/7/202417/6/2026
The WP Ajax Contact Form WordPress plugin through 2.2.2 does not have CSRF check in place when deleting emails from the email list, which could allow attackers to make a logged in admin perform such action via a CSRF attack
ModificadaMedia (5.4)0.31%—Onetarek WP Logs Book21/6/202417/6/2026
The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting
ModificadaMedia (4.3)0.18%—Onetarek WP Logs Book21/6/202417/6/2026
The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check when clearing logs, which could allow attackers to make a logged in admin clear the logs them via a CSRF attack
ModificadaMedia (4.3)6.0%—Onetarek WP Logs Book21/6/202417/6/2026
The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaCrítica (9.8)0.52%—Sunnytoo Stblogsearch19/1/202417/6/2026
SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via the StBlogSearchClass::prepareSearch component.
ModificadaAlta (8.8)0.35%—Wp-blogs-planetarium Project Wp-blogs-planetarium8/1/202417/6/2026
The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaAlta (7.2)0.73%—Wpvibes Redirect 404 Error Page TO Homepage OR Custom Page With Logs18/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPVibes Redirect 404 Error Page to Homepage or Custom Page with Logs allows SQL Injection.This issue affects Redirect 404 Error Page to Homepage or Custom Page with Logs: from n/a through 1.8.7.
ModificadaMedia (5.5)0.34%—Elastic Logstash15/11/202317/6/2026
An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances. The prerequisites for the manifestation of this issue are:
AnalizadaCrítica (9.8)0.72%—Vareille Tinyfiledialogs30/10/202317/6/2026
tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered single and double quote characters.
ModificadaAlta (7.5)0.44%—Vareille Tinyfiledialogs30/10/202317/6/2026
tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data.
ModificadaAlta (7.8)0.20%—Vmware Aria Operations FOR Logs20/10/202317/6/2026
VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.
ModificadaCrítica (9.8)45%💥 PoCVmware Aria Operations FOR Logs20/10/202317/6/2026
VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
ModificadaMedia (6.1)0.98%💥 PoCMrpeng Mpoperationlogs18/10/202317/6/2026
The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
ModificadaAlta (7.2)1.6%—Vmware Aria Operations FOR LogsVmware Cloud Foundation20/4/202317/6/2026
VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.
ModificadaCrítica (9.8)70%💥 ExploitVmware Aria Operations FOR LogsVmware Cloud Foundation20/4/202317/6/2026
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
ModificadaCrítica (9.3)1.3%—Logstash-management-api Project Logstash-management-api11/7/202217/6/2026
The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaMedia (4.9)14%💥 ExploitEthercreative Logs31/1/202217/6/2026
The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.
ModificadaMedia (6.5)0.55%—Wpvibes Redirect 404 Error Page TO Homepage OR Custom Page With Logs8/11/202117/6/2026
The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attack
ModificadaMedia (4.9)1.1%—Ethercreative Logs9/7/202117/6/2026
Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found in versions prior to 3.0.4 that allowed authenticated admin users to access any file on the server. The vulnerability has been fixed in version 3.0.4. As a workaround, one may disable the plugin if…
ModificadaBaja (3.7)0.46%—Elastic Logstash13/5/202117/6/2026
In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitoring feature. When specifying a trusted server CA certificate Logstash would not properly verify the certificate returned by the monitoring server. This could result in a man in the middle style…
ModificadaMedia (5.4)0.70%—Nextcloud/dialogs Project Nextcloud/dialogs13/4/202117/6/2026
The Nextcloud dialogs library (npm package @nextcloud/dialogs) before 3.1.2 insufficiently escaped text input passed to a toast. If your application displays toasts with user-supplied input, this could lead to a XSS vulnerability. The vulnerability has been patched in version 3.1.2 If you need to display HTML in the…
ModificadaAlta (8.8)2.2%—Infoscience ELC AnalyticsInfoscience Logstorage28/1/202117/6/2026
Logstorage version 8.0.0 and earlier, and ELC Analytics version 3.0.0 and earlier allow remote attackers to execute arbitrary OS commands via a specially crafted log file.
Orbitaley — Vulnerabilidades