Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 2.0% | — | Logsign Unified Secops Platform | 21/8/2024 | 17/6/2026 | Logsign Unified SecOps Platform Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (6.5) | 1.2% | — | Logsign Unified Secops Platform | 6/8/2024 | 17/6/2026 | Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Media (6.1) | 0.36% | — | Masdiblogs WP Ajax Contact Form | 30/7/2024 | 17/6/2026 | The WP Ajax Contact Form WordPress plugin through 2.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin users | |
| Analizada | Media (4.3) | 0.22% | — | Masdiblogs WP Ajax Contact Form | 30/7/2024 | 17/6/2026 | The WP Ajax Contact Form WordPress plugin through 2.2.2 does not have CSRF check in place when deleting emails from the email list, which could allow attackers to make a logged in admin perform such action via a CSRF attack | |
| Modificada | Media (5.4) | 0.31% | — | Onetarek WP Logs Book | 21/6/2024 | 17/6/2026 | The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting | |
| Modificada | Media (4.3) | 0.18% | — | Onetarek WP Logs Book | 21/6/2024 | 17/6/2026 | The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check when clearing logs, which could allow attackers to make a logged in admin clear the logs them via a CSRF attack | |
| Modificada | Media (4.3) | 6.0% | — | Onetarek WP Logs Book | 21/6/2024 | 17/6/2026 | The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Crítica (9.8) | 0.52% | — | Sunnytoo Stblogsearch | 19/1/2024 | 17/6/2026 | SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via the StBlogSearchClass::prepareSearch component. | |
| Modificada | Alta (8.8) | 0.35% | — | Wp-blogs-planetarium Project Wp-blogs-planetarium | 8/1/2024 | 17/6/2026 | The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Alta (7.2) | 0.73% | — | Wpvibes Redirect 404 Error Page TO Homepage OR Custom Page With Logs | 18/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPVibes Redirect 404 Error Page to Homepage or Custom Page with Logs allows SQL Injection.This issue affects Redirect 404 Error Page to Homepage or Custom Page with Logs: from n/a through 1.8.7. | |
| Modificada | Media (5.5) | 0.34% | — | Elastic Logstash | 15/11/2023 | 17/6/2026 | An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances. The prerequisites for the manifestation of this issue are: | |
| Analizada | Crítica (9.8) | 0.72% | — | Vareille Tinyfiledialogs | 30/10/2023 | 17/6/2026 | tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered single and double quote characters. | |
| Modificada | Alta (7.5) | 0.44% | — | Vareille Tinyfiledialogs | 30/10/2023 | 17/6/2026 | tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data. | |
| Modificada | Alta (7.8) | 0.20% | — | Vmware Aria Operations FOR Logs | 20/10/2023 | 17/6/2026 | VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass. | |
| Modificada | Crítica (9.8) | 45% | 💥 PoC | Vmware Aria Operations FOR Logs | 20/10/2023 | 17/6/2026 | VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. | |
| Modificada | Media (6.1) | 0.98% | 💥 PoC | Mrpeng Mpoperationlogs | 18/10/2023 | 17/6/2026 | The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Modificada | Alta (7.2) | 1.6% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 20/4/2023 | 17/6/2026 | VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root. | |
| Modificada | Crítica (9.8) | 70% | 💥 Exploit | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 20/4/2023 | 17/6/2026 | VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root. | |
| Modificada | Crítica (9.3) | 1.3% | — | Logstash-management-api Project Logstash-management-api | 11/7/2022 | 17/6/2026 | The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (4.9) | 14% | 💥 Exploit | Ethercreative Logs | 31/1/2022 | 17/6/2026 | The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php. | |
| Modificada | Media (6.5) | 0.55% | — | Wpvibes Redirect 404 Error Page TO Homepage OR Custom Page With Logs | 8/11/2021 | 17/6/2026 | The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attack | |
| Modificada | Media (4.9) | 1.1% | — | Ethercreative Logs | 9/7/2021 | 17/6/2026 | Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found in versions prior to 3.0.4 that allowed authenticated admin users to access any file on the server. The vulnerability has been fixed in version 3.0.4. As a workaround, one may disable the plugin if… | |
| Modificada | Baja (3.7) | 0.46% | — | Elastic Logstash | 13/5/2021 | 17/6/2026 | In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitoring feature. When specifying a trusted server CA certificate Logstash would not properly verify the certificate returned by the monitoring server. This could result in a man in the middle style… | |
| Modificada | Media (5.4) | 0.70% | — | Nextcloud/dialogs Project Nextcloud/dialogs | 13/4/2021 | 17/6/2026 | The Nextcloud dialogs library (npm package @nextcloud/dialogs) before 3.1.2 insufficiently escaped text input passed to a toast. If your application displays toasts with user-supplied input, this could lead to a XSS vulnerability. The vulnerability has been patched in version 3.1.2 If you need to display HTML in the… | |
| Modificada | Alta (8.8) | 2.2% | — | Infoscience ELC AnalyticsInfoscience Logstorage | 28/1/2021 | 17/6/2026 | Logstorage version 8.0.0 and earlier, and ELC Analytics version 3.0.0 and earlier allow remote attackers to execute arbitrary OS commands via a specially crafted log file. |