Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.21% | — | Marckocher Skip TOAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in marckocher Skip To skip-to allows Stored XSS.This issue affects Skip To: from n/a through <= 2.0.0. | |
| Aplazada | Media (5.3) | 0.45% | — | Jeanmarc77 123solarAI | 27/9/2024 | 17/6/2026 | A vulnerability was found in jeanmarc77 123solar up to 1.8.4.5. It has been rated as critical. This issue affects some unknown processing of the file /admin/admin_invt2.php. The manipulation of the argument PROTOCOLx leads to file inclusion. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 1.0% | 💥 Exploit | Jeanmarc77 123solar | 19/9/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the argument date1 leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.3) | 0.69% | — | Jeanmarc77 123solar | 19/9/2024 | 17/6/2026 | A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file config/config_invt1.php. The manipulation of the argument PASSOx leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 0.29% | — | Marcelotorres Simple Responsive Slider | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in marcelotorres Simple Responsive Slider allows Reflected XSS.This issue affects Simple Responsive Slider: from n/a through 0.2.2.5. | |
| Aplazada | Alta (7.1) | 0.35% | — | Marco Gasi Language Switcher FOR TransposhAI | 22/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Gasi Language Switcher for Transposh allows Reflected XSS.This issue affects Language Switcher for Transposh: from n/a through 1.5.9. | |
| Aplazada | Alta (7.5) | 0.46% | — | SAP SCMAISAP ScmarchiivedeventviewertoolAI | 27/3/2024 | 17/6/2026 | An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute the arbitrary code on the same system where SCMArchivedEventViewerTool is installed in the case of SCM Tools. | |
| Analizada | Alta (7.5) | 0.73% | — | Trusteddomain Opendmarc | 26/2/2024 | 17/6/2026 | OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c. | |
| Analizada | Alta (7.5) | 0.52% | — | Comarch ERP XL | 15/2/2024 | 17/6/2026 | Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Comarch ERP XL installations. This issue affects ERP XL: from 2020.2.2 through 2023.2. | |
| Analizada | Media (6.5) | 0.36% | — | Comarch ERP XL | 15/2/2024 | 17/6/2026 | The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords. This issue affects ERP XL: from 2020.2.2… | |
| Analizada | Alta (7.4) | 0.61% | — | Comarch ERP XL | 15/2/2024 | 17/6/2026 | Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects ERP XL: from 2020.2.2 through 2023.2. | |
| Modificada | Alta (8.8) | 0.21% | — | Marcomilesi Browser Theme Color | 31/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Browser Theme Color.This issue affects Browser Theme Color: from n/a through 1.3. | |
| Modificada | Media (6.1) | 0.27% | — | Marcorulicke Coru Lfmember | 16/1/2024 | 17/6/2026 | The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well as escaping in their settings, allowing attacker to make a logged in admin add an arbitrary game with XSS payloads | |
| Modificada | Crítica (9.8) | 0.88% | — | Gmarczynski Dynamic Progress BAR | 15/12/2023 | 17/6/2026 | A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in… | |
| Modificada | Media (4.8) | 0.39% | — | Marcomilesi Anac XML Viewer | 16/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Viewer plugin <= 1.7 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Marcomilesi Anac XML Bandi DI Gara | 16/11/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7.5 versions. | |
| Modificada | Media (5.4) | 0.41% | — | Marcomilesi Anac XML Bandi DI Gara | 14/11/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7.5 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Marcomilesi WP Attachments | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi WP Attachments allows Cross Site Request Forgery.This issue affects WP Attachments: from n/a through 5.0.11. | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modificada | Media (4.8) | 0.37% | — | Marcosteinbrecher WP Browserupdate | 17/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Steinbrecher WP BrowserUpdate plugin <= 4.5 versions. | |
| Modificada | Media (6.1) | 0.66% | — | Techsneeze Dmarc Report | 22/6/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerabiliy in dmarcts-report-viewer dashboard versions 1.1 and thru commit 8a1d882b4c481a05e296e9b38a7961e912146a0f, allows unauthenticated attackers to execute arbitrary code via the org_name or domain values. | |
| Modificada | Media (4.8) | 0.47% | — | Marcomilesi WP Attachments | 16/1/2023 | 17/6/2026 | The WP Attachments WordPress plugin before 5.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.8) | 0.56% | — | Marcomilesi WP Attachments | 14/11/2022 | 17/6/2026 | The WP Attachments WordPress plugin before 5.0.5 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |
| Modificada | Alta (7.5) | 2.7% | — | Trusteddomain OpendmarcFedoraproject Fedora | 10/6/2021 | 17/6/2026 | OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a multi-value From header field. | |
| Modificada | Alta (7.5) | 1.5% | — | Marc Project Marc | 29/1/2021 | 17/6/2026 | An issue was discovered in the marc crate before 2.0.0 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated memory, violating soundness. |