Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.74% | — | Hexoeditor Project Hexoeditor | 21/3/2022 | 17/6/2026 | HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opened with the app, will execute several times. | |
| Analizada | Media (5.5) | 0.73% | — | Metadata-extractor Project Metadata-extractor | 24/2/2022 | 17/6/2026 | When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library. | |
| Analizada | Media (5.5) | 0.78% | — | Metadata-extractor Project Metadata-extractor | 24/2/2022 | 17/6/2026 | metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use metadata-extractor library. | |
| Modificada | Media (6.1) | 0.76% | — | H5p-css-editor Project H5p-css-editor | 14/12/2021 | 17/6/2026 | The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found in the ~/h5p-css-editor.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0. | |
| Modificada | Media (4.8) | 0.62% | — | Inspirational Quote Rotator Project Inspirational Quote Rotator | 13/12/2021 | 17/6/2026 | The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the "Quotes list" even when the unfiltered_html capability is disallowed | |
| Modificada | Media (5.4) | 0.62% | — | QR Redirector Project QR Redirector | 17/11/2021 | 17/6/2026 | The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could allow users with a role as low as Contributor perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (4.3) | 0.45% | — | QR Redirector Project QR Redirector | 17/11/2021 | 17/6/2026 | The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects | |
| Modificada | Alta (7.5) | 1.1% | — | Fort Validator Project Fort ValidatorDebian Linux | 9/11/2021 | 17/6/2026 | FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation. | |
| Modificada | Alta (7.5) | 1.8% | — | Validator Project Validator | 2/11/2021 | 17/6/2026 | validator.js is vulnerable to Inefficient Regular Expression Complexity | |
| Modificada | Media (6.1) | 0.73% | — | Detector Project Detector | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in _contactform.inc.php in Detector 0.8.5 and below version allows remote attackers to inject arbitrary web script or HTML via the cid parameter. | |
| Modificada | Alta (7.5) | 2.5% | — | Openvpn-monitor Project Openvpn-monitor | 27/9/2021 | 17/6/2026 | furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients. | |
| Modificada | Alta (7.5) | 3.3% | — | Openvpn-monitor Project Openvpn-monitor | 27/9/2021 | 17/6/2026 | furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM. | |
| Modificada | Media (6.5) | 0.68% | — | Openvpn-monitor Project Openvpn-monitor | 27/9/2021 | 17/6/2026 | furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client. | |
| Modificada | Media (5.4) | 0.62% | — | Custom Post View Generator Project Custom Post View Generator | 13/9/2021 | 17/6/2026 | The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leading to a Reflected Cross-Site issue | |
| Modificada | Media (5.4) | 0.62% | — | Business Hours Indicator Project Business Hours Indicator | 30/8/2021 | 17/6/2026 | The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue | |
| Modificada | Media (5.9) | 1.1% | — | Generator Project Generator | 8/8/2021 | 17/6/2026 | An issue was discovered in the generator crate before 0.7.0 for Rust. It does not ensure that a function (for yielding values) has Send bounds. | |
| Modificada | Media (5.9) | 0.98% | — | Disrustor Project Disrustor | 8/8/2021 | 17/6/2026 | An issue was discovered in the disrustor crate through 2020-12-17 for Rust. RingBuffer doe not properly limit the number of mutable references. | |
| Modificada | Media (6.1) | 0.67% | — | Cgm-remote-monitor Project Cgm-remote-monitor | 16/7/2021 | 17/6/2026 | Nightscout Web Monitor (aka cgm-remote-monitor) 14.2.2 allows XSS via a crafted X-Forwarded-For header. | |
| Modificada | Media (5.4) | 0.62% | — | WP Config File Editor Project WP Config File Editor | 21/6/2021 | 17/6/2026 | The WP Config File Editor WordPress plugin through 1.7.1 was affected by an Authenticated Stored Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Crítica (9.8) | 1.3% | — | Ps-visitor Project Ps-visitor | 18/4/2021 | 17/6/2026 | This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. | |
| Modificada | Media (5.4) | 0.69% | — | Testimonial Rotator Project Testimonial Rotator | 5/4/2021 | 17/6/2026 | Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privilege escalation | |
| Modificada | Alta (7.3) | 1.0% | — | Stackvector Project Stackvector | 1/4/2021 | 17/6/2026 | An issue was discovered in the stackvector crate through 2021-02-19 for Rust. There is an out-of-bounds write in StackVec::extend if size_hint provides certain anomalous data. | |
| Modificada | Alta (7.5) | 2.1% | — | Schema-inspector Project Schema-inspectorNetapp E-series Performance AnalyzerNetapp Oncommand Insight | 19/3/2021 | 17/6/2026 | Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example… | |
| Modificada | Alta (7.5) | 1.8% | — | Djvalidator Project Djvalidator | 26/11/2020 | 17/6/2026 | All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, --@------------------------------------------------------------------------------------------------------------------------!. | |
| Modificada | Media (5.4) | 0.72% | — | Testimonial Rotator Project Testimonial Rotator | 16/10/2020 | 17/6/2026 | Testimonial Rotator Wordpress Plugin 3.0.2 is affected by Cross Site Scripting (XSS) in /wp-admin/post.php. If a user intercepts a request and inserts a payload in "cite" parameter, the payload will be stored in the database. |