Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

82 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.4%—Windriver VxworksSiemens Ruggedcom WIN Subscriber Station FirmwareSiemens Scalance X200-4 P IRT FirmwareSiemens Scalance X201-3p IRT Firmware+3213/4/202117/6/2026
An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client.
ModificadaMedia (5.9)7.1%💥 PoCOpensslDebian LinuxFedoraproject FedoraOracle API Gateway+408/12/202017/6/2026
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both…
ModificadaMedia (5.3)1.6%—Icegram Email Subscribers & Newsletters10/9/202017/6/2026
Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.
ModificadaMedia (4.9)2.0%—Icegram Email Subscribers & Newsletters17/7/202017/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields.
ModificadaMedia (6.5)0.92%—Icegram Email Subscribers & Newsletters17/7/202017/6/2026
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.
ModificadaAlta (7.4)5.2%—LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+1415/7/202017/6/2026
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
ModificadaCrítica (9.8)85%💥 ExploitIcegram Email Subscribers & Newsletters8/1/202017/6/2026
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
ModificadaMedia (5.3)71%💥 ExploitIcegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
ModificadaMedia (6.3)0.97%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
ModificadaMedia (5.3)1.2%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.
ModificadaMedia (5.4)0.56%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
ModificadaMedia (4.3)1.0%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to…
ModificadaMedia (6.1)1.7%💥 ExploitBestwebsoft Subscriber12/8/201917/6/2026
The subscriber plugin before 1.3.5 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)1.3%—Icegram Email Subscribers & Newsletters28/7/201917/6/2026
An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter.
ModificadaCrítica (9.8)3.7%—Icegram Email Subscribers & Newsletters19/7/201917/6/2026
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
ModificadaMedia (6.1)1.2%—Email Subscribers & Newsletters Project Email Subscribers & Newsletters26/6/201817/6/2026
Cross-site scripting vulnerability in Email Subscribers & Newsletters versions prior to 3.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)3.2%—Icegram Email Subscribers & Newsletters26/1/201817/6/2026
An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscriber data.
ModificadaMedia (6.1)0.89%—Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+4722/5/201717/6/2026
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,…
ModificadaAlta (9.3)5.0%—Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance12/5/201016/6/2026
The default configuration of pluginlicense.ini for the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance, when downloaded from a server operated by Telefonica or possibly other companies, contains an incorrect DNS whitelist that includes the DNS hostnames of…
ModificadaAlta (9.3)5.2%—Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance12/5/201016/6/2026
The SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to bypass intended restrictions on ActiveX execution via "instantiation/free attacks."
ModificadaAlta (9.3)3.2%—Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance12/5/201016/6/2026
The site-locking implementation in the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance relies on a list of server domain names to restrict execution of ActiveX controls, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a…
ModificadaMedia (5.1)2.5%—Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance12/5/201016/6/2026
The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields.
ModificadaAlta (7.6)5.7%—Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance12/5/201016/6/2026
Buffer overflow in the RunCmd method in the SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to execute arbitrary code via vectors involving "CreateProcess params." NOTE: some of these details are obtained from third party…
ModificadaAlta (9.3)2.3%—Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance12/5/201016/6/2026
The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance does not properly restrict access to the HTTPDownloadFile, HTTPGetFile, Install, and RunCmd methods, which allows remote attackers to execute arbitrary programs via a URL in the url argument to (1)…
ModificadaMedia (4.3)1.5%—Consona Dynamic AgentConsona Live AssistanceConsona Subscriber Assistance12/5/201016/6/2026
The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to discover the username of the client user, and consequently determine a pathname to a certain user directory, via a call to the GetUserName method.