Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.85%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A reflected cross-site scripting (XSS) vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to inject arbitrary web script or HTML into various locations.
ModificadaAlta (7.2)1.2%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10 and A11 and earlier enables attackers in possession of cryptographic material to access the device as root.
ModificadaMedia (6.1)0.66%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to redirect users to malicious websites.
ModificadaAlta (8.1)1.3%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sessions and escalate privileges.
ModificadaAlta (8.8)1.5%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker can execute arbitrary commands.
ModificadaMedia (6.7)0.25%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A vulnerability in the configuration import mechanism of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with command line access to the underlying Linux system to escalate privileges to the root user.
ModificadaMedia (6.1)7.4%—Updraftplus4/4/202217/6/2026
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.
ModificadaMedia (6.5)2.1%—Updraftplus17/2/202217/6/2026
The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.
ModificadaMedia (6.1)0.80%—Updraftplus1/2/202217/6/2026
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (4.8)0.61%—Updraftplus24/1/202217/6/2026
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue
ModificadaMedia (6.1)1.1%—Updraftplus3/1/202217/6/2026
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues
ModificadaAlta (7.5)1.6%—Convertplug Convertplus3/9/201917/6/2026
The ConvertPlus plugin before 3.4.5 for WordPress has an unintended account creation (with the none role) via a request for variants.
ModificadaMedia (6.1)0.92%—Updraftplus28/8/201917/6/2026
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.
ModificadaMedia (6.1)0.95%—Updraftplus28/8/201917/6/2026
The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().
ModificadaMedia (6.1)0.91%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
ModificadaCrítica (9.8)2.0%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
ModificadaMedia (6.1)0.91%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
ModificadaCrítica (9.1)2.5%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
ModificadaCrítica (9.8)2.2%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
ModificadaMedia (5.3)1.3%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
ModificadaCrítica (9.8)1.8%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
ModificadaMedia (6.1)1.7%—Wpsupportplus WP Support Plus Responsive Ticket System21/3/201917/6/2026
A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in…
ModificadaCrítica (9.8)2.1%—Wpsupportplus WP Support Plus Responsive Ticket System14/3/201817/6/2026
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This…
ModificadaAlta (8.1)1.6%—Updraftplus17/11/201717/6/2026
The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race condition before deleting a file associated with the name parameter. NOTE: the vendor reports that this does not cross a privilege boundary
ModificadaAlta (8.1)0.96%—Updraftplus17/11/201717/6/2026
The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the vendor reports that this does not cross a privilege boundary