Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
179 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.31% | — | Vollstart Event Tickets With Ticket ScannerAI | 6/12/2024 | 17/6/2026 | The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping and missing authorization on the functionality to manage tickets. This makes it… | |
| Analizada | Alta (7.3) | 0.41% | — | Radmin Advanced IP Scanner | 22/11/2024 | 17/6/2026 | Famatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Famatech Advanced IP Scanner. An attacker must first obtain the ability to execute low-privileged code on the target… | |
| Modificada | Alta (8.8) | 0.74% | — | Vollstart Event Tickets With Ticket Scanner | 18/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.3.11. | |
| Modificada | Media (6.1) | 0.17% | — | Cookie-scanner Cookie Scanner | 17/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nikel Cookie Scanner cookie-scanner allows Cross Site Request Forgery.This issue affects Cookie Scanner: from n/a through <= 1.1. | |
| Modificada | Alta (8.8) | 0.46% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 22/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from… | |
| Analizada | Alta (7.5) | 0.41% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3. | |
| Modificada | Media (6.1) | 0.29% | — | Vollstart Event Tickets With Ticket Scanner | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Reflected XSS.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.1. | |
| Aplazada | Media (5.3) | 0.40% | — | Miniorange Malware ScannerAI | 4/6/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in miniorange Malware Scanner allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Malware Scanner: from n/a through 4.7.1. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Ukrsolution Barcode Scanner With Inventory AND Order ManagerAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Privilege Escalation.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3. | |
| Aplazada | Media (4.3) | 0.25% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.5.4. | |
| Aplazada | Media (5.3) | 0.58% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 14/5/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.5.4. | |
| Aplazada | Alta (8.8) | 0.61% | — | Barcode Scanner Inventory Manager POSAI | 2/5/2024 | 17/6/2026 | The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plugin for WordPress is vulnerable to blind SQL Injection via the ‘currentIds’ parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack… | |
| Aplazada | Alta (7.1) | 0.38% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & Order Manager: from… | |
| Aplazada | Media (5.3) | 0.34% | — | Brother Industries PrinterAIBrother Industries ScannerAI | 18/3/2024 | 17/6/2026 | Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. If this vulnerability is exploited, a network-adjacent user who can access the product may impersonate an administrative user. As for the details of affected… | |
| Aplazada | Crítica (9.8) | 1.7% | — | Miniorange Malware ScannerAIMiniorange WEB Application FirewallAI | 13/3/2024 | 17/6/2026 | The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This… | |
| Modificada | Alta (7.2) | 0.54% | — | Miniorange Malware Scanner | 28/2/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects Malware Scanner: from n/a through 4.7.2. | |
| Modificada | Alta (8.2) | 0.60% | — | Dronetag Drone Scanner | 6/2/2024 | 17/6/2026 | An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones via transmission of crafted data packets. | |
| Modificada | Crítica (9.8) | 0.63% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 24/1/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner and Inventory manager.This issue affects Barcode Scanner and Inventory manager: from n/a through 1.5.1. | |
| Modificada | Crítica (9.8) | 0.55% | — | Ukrsolution Barcode Scanner AND Inventory Manager | 8/1/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce.This issue affects Simple Inventory Management – just scan barcode to manage products and orders. For… | |
| Modificada | Alta (7.2) | 1.1% | — | Quttera WEB Malware Scanner | 18/12/2023 | 17/6/2026 | IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks | |
| Modificada | Media (5.3) | 19% | 💥 Exploit | Quttera WEB Malware Scanner | 18/12/2023 | 17/6/2026 | The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code | |
| Modificada | Media (4.3) | 0.48% | — | Jenkins Neuvector Vulnerability Scanner | 29/11/2023 | 17/6/2026 | A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password. | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Neuvector Vulnerability ScannerJenkins JiraJenkins Google Compute EngineJenkins Matlab | 29/11/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password. | |
| Modificada | Alta (8.8) | 0.23% | — | Peterbutler Timthumb Vulnerability Scanner | 9/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Peter Butler Timthumb Vulnerability Scanner plugin <= 1.54 versions. | |
| Modificada | Media (4.3) | 0.39% | — | Websitescanner Remove Schema | 1/7/2023 | 17/6/2026 | The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the validate() function. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted… |