Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 67% | 💥 PoC | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+24 | 18/1/2022 | 17/6/2026 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or… | |
| Modificada | Alta (8.8) | 64% | — | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+22 | 18/1/2022 | 17/6/2026 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink… | |
| Modificada | Media (4.8) | 0.64% | — | Flat Preloader Project Flat Preloader | 1/11/2021 | 17/6/2026 | The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | |
| Modificada | Media (5.4) | 0.51% | — | Flat Preloader Project Flat Preloader | 1/11/2021 | 17/6/2026 | The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the frontend or backend depending on the… | |
| Modificada | Crítica (9.8) | 4.6% | — | Apache ChainsawApache Log4jQOS Reload4j | 16/6/2021 | 17/6/2026 | A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution. | |
| Modificada | Media (4.8) | 0.54% | — | Easy Preloader Project Easy Preloader | 7/6/2021 | 17/6/2026 | The Easy Preloader WordPress plugin through 1.0.0 does not sanitise its setting fields, leading to authenticated (admin+) Stored Cross-Site scripting issues | |
| Modificada | Crítica (9.8) | 4.3% | 💥 PoC | Limitloginattempts Limit Login Attempts Reloaded | 21/12/2020 | 17/6/2026 | LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address, a malicious user is not limited… | |
| Modificada | Media (5.4) | 0.78% | — | Limitloginattempts Limit Login Attempts Reloaded | 21/12/2020 | 17/6/2026 | The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-login-attempts&tab= XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The… | |
| Modificada | Baja (3.7) | 8.1% | 💥 PoC | Apache Log4jOracle Communications Application Session ControllerOracle Communications Billing AND Revenue ManagementOracle Communications Eagle FTP Table Base Retrieval+42 | 27/4/2020 | 17/6/2026 | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1 | |
| Modificada | Media (5.3) | 0.92% | — | Huawei Alp-al00b FirmwareHuawei Alp-tl00b FirmwareHuawei Bla-al00b FirmwareHuawei Bla-tl00b Firmware+46 | 14/12/2019 | 17/6/2026 | Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal. | |
| Modificada | Alta (8.8) | 0.91% | — | Subscribe TO Comments Reloaded Project Subscribe TO Comments Reloaded | 19/3/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the… | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Allvideos Reloaded Project Allvideos Reloaded | 17/2/2018 | 17/6/2026 | SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter. | |
| Modificada | Media (4.3) | 7.0% | 💥 Exploit | Wp-table Reloaded Project Wp-table Reloaded | 7/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module before 1.9.4 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be the same vulnerability as CVE-2013-1808. If so, it is likely that CVE-2013-1463… | |
| Modificada | Alta (7.5) | 1.5% | — | Creloaded CRE Loaded | 8/6/2011 | 16/6/2026 | CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) includes/application_top.php and (2) admin/includes/application_top.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Creloaded CRE Loaded | 8/6/2011 | 16/6/2026 | CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator privileges via a request with (1) login.php or (2) password_forgotten.php appended as the PATH_INFO, which bypasses a check that uses PHP_SELF, which is not properly handled by… | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Creloaded CRE Loaded | 24/4/2009 | 16/6/2026 | SQL injection vulnerability in product_info.php in CRE Loaded 6.2 allows remote attackers to execute arbitrary SQL commands via the products_id parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Reloadcms | 23/10/2007 | 16/6/2026 | Directory traversal vulnerability in system.php in ReloadCMS 1.2.7 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter to index.php. | |
| Modificada | Media (4.3) | 2.0% | — | Uapplication Ublog Reload | 6/2/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) login.asp; and allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (2) badword.asp, (3) polls.asp,… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Matteolucarelli Pgmreloaded | 23/12/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang parameter to (a) index.php, the (2) CFG[libdir] and (3) CFG[localedir] parameters to (b) common.inc.php, and the CFG[localelangdir] parameter to (c)… | |
| Modificada | Media (5) | 47% | 💥 Exploit | Swsoft PleskSwsoft Plesk Reload | 27/9/2006 | 16/6/2026 | Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file parameter in a chdir action. | |
| Modificada | Alta (7.5) | 1.5% | — | THE Address BookTHE Address Book Reloaded | 10/8/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in the authentication process in katzlbt (a) The Address Book 1.04e and earlier and (b) The Address Book Reloaded before 2.0-rc4 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. NOTE: portions of these details are obtained… | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Reloadcms | 6/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Anton Vlasov and Rostislav Gaitkuloff ReloadCMS 1.2.5 and earlier allows remote attackers to inject arbitrary web script or HTML and gain leverage to execute arbitrary PHP code via the User-Agent HTTP header, which is displayed by admin/modules/general/statistic.php in the… | |
| Modificada | Alta (7.5) | 1.4% | — | Help Desk Reloaded Free Help DeskAI | 5/12/2005 | 16/6/2026 | Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navigating to accountsetup.php and creating a new user. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Ublog Reload | 20/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Uapplication Ublog Reload | 20/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter. |