Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

118 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.46%—Dev4press GD Mail Queue12/7/202317/6/2026
The GD Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
ModificadaMedia (4.8)0.53%—Smtp Mailing Queue Project Smtp Mailing Queue2/5/202317/6/2026
The SMTP Mailing Queue WordPress plugin before 2.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaCrítica (9.8)1.3%—Global-workqueue Project Global-workqueueReqmgr2 Project Reqmgr2Reqmon Project ReqmonWmagent Project Wmagent28/7/202217/6/2026
WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.
ModificadaAlta (8.8)0.29%—IBM Security Verify Information Queue26/7/202217/6/2026
IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230814.
ModificadaMedia (6.5)0.73%—IBM Security Verify Information Queue25/7/202217/6/2026
IBM Security Verify Information Queue 10.0.2 could allow a user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 230818.
ModificadaAlta (7.5)0.64%—IBM Security Verify Information Queue25/7/202217/6/2026
IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 230817.
ModificadaAlta (8.8)0.43%—IBM Security Verify Information Queue25/7/202217/6/2026
IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230812.
ModificadaAlta (7.5)0.75%—IBM Security Verify Information Queue25/7/202217/6/2026
IBM Security Verify Information Queue 10.0.2 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 230811.
ModificadaMedia (6.5)1.2%—IBM Security Verify Information Queue14/7/202217/6/2026
IBM Security Verify Information Queue 10.0.2 could allow an authenticated user to cause a denial of service with a specially crafted HTTP request.
ModificadaMedia (4.7)0.53%—Microsoft Azure Storage BlobsMicrosoft Azure Storage Queue12/7/202217/6/2026
Azure Storage Library Information Disclosure Vulnerability
ModificadaMedia (6.5)0.43%—Enqueue Anything Project Enqueue Anything13/6/202217/6/2026
The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure that the item to be deleted is actually an asset. As a result, low privilege users such as subscriber could delete arbitrary assets, as well as put arbitrary posts in the…
ModificadaAlta (8.1)1.3%—Oracle Universal Work Queue20/10/202117/6/2026
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
ModificadaAlta (8.1)1.1%—Multiqueue Project Multiqueue8/8/202117/6/2026
An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of Send for InnerSend<RW, T>, InnerRecv<RW, T>, FutInnerSend<RW, T>, and FutInnerRecv<RW, T>.
ModificadaAlta (8.1)1.1%—Scottqueue Project Scottqueue8/8/202117/6/2026
An issue was discovered in the scottqueue crate through 2020-11-15 for Rust. There are unconditional implementations of Send and Sync for Queue<T>.
ModificadaAlta (8.1)0.85%—Conqueue Project Conqueue8/8/202117/6/2026
An issue was discovered in the conqueue crate before 0.4.0 for Rust. There are unconditional implementations of Send and Sync for QueueSender<T>.
ModificadaAlta (8.1)0.93%—Oracle Universal Work Queue22/4/202117/6/2026
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal…
ModificadaMedia (6.1)0.75%—Symbiote Silverstripe Queued Jobs16/3/202117/6/2026
A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs module. A Cross Site Scripting vulnerability allows an attacker to inject an arbitrary payload in the CreateQueuedJobTask dev task via a specially crafted URL.
ModificadaAlta (7.5)0.94%—IBM Security Verify Information Queue12/2/202117/6/2026
IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 198192.
ModificadaAlta (8.1)0.45%—IBM Security Verify Information Queue12/2/202117/6/2026
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incorrectly updating the session identifier. IBM X-Force ID: 198191.
ModificadaMedia (5.3)0.71%—IBM Security Verify Information Queue12/2/202117/6/2026
IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190.
ModificadaAlta (7.5)0.99%—IBM Security Verify Information Queue12/2/202117/6/2026
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID:…
ModificadaMedia (5.5)0.19%—IBM Security Verify Information Queue12/2/202117/6/2026
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key. IBM X-Force ID: 198187.
ModificadaAlta (7.5)0.73%—IBM Security Verify Information Queue12/2/202117/6/2026
IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used in further attacks against the system. IBM X-Force ID: 196185.
ModificadaMedia (4.9)0.52%—IBM Security Verify Information Queue12/2/202117/6/2026
IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196184.
ModificadaAlta (7.5)0.78%—IBM Security Verify Information Queue11/2/202117/6/2026
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of output. IBM X-Force ID: 196183.