Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.85% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to inject arbitrary web script or HTML into various locations. | |
| Modificada | Alta (7.2) | 1.2% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10 and A11 and earlier enables attackers in possession of cryptographic material to access the device as root. | |
| Modificada | Media (6.1) | 0.66% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to redirect users to malicious websites. | |
| Modificada | Alta (8.1) | 1.3% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sessions and escalate privileges. | |
| Modificada | Alta (8.8) | 1.5% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker can execute arbitrary commands. | |
| Modificada | Media (6.7) | 0.25% | — | Bbraun Datamodule CompactplusBbraun Spacecom | 14/4/2022 | 17/6/2026 | A vulnerability in the configuration import mechanism of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with command line access to the underlying Linux system to escalate privileges to the root user. | |
| Modificada | Media (6.1) | 7.4% | — | Updraftplus | 4/4/2022 | 17/6/2026 | The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Media (6.5) | 2.1% | — | Updraftplus | 17/2/2022 | 17/6/2026 | The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup. | |
| Modificada | Media (6.1) | 0.80% | — | Updraftplus | 1/2/2022 | 17/6/2026 | The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (4.8) | 0.61% | — | Updraftplus | 24/1/2022 | 17/6/2026 | The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 1.1% | — | Updraftplus | 3/1/2022 | 17/6/2026 | The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Alta (7.5) | 1.6% | — | Convertplug Convertplus | 3/9/2019 | 17/6/2026 | The ConvertPlus plugin before 3.4.5 for WordPress has an unintended account creation (with the none role) via a request for variants. | |
| Modificada | Media (6.1) | 0.92% | — | Updraftplus | 28/8/2019 | 17/6/2026 | The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file. | |
| Modificada | Media (6.1) | 0.95% | — | Updraftplus | 28/8/2019 | 17/6/2026 | The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |
| Modificada | Media (6.1) | 0.91% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection. | |
| Modificada | Crítica (9.8) | 2.0% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number. | |
| Modificada | Media (6.1) | 0.91% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection. | |
| Modificada | Crítica (9.1) | 2.5% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal. | |
| Modificada | Crítica (9.8) | 2.2% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication. | |
| Modificada | Media (5.3) | 1.3% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure. | |
| Modificada | Crítica (9.8) | 1.8% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 22/8/2019 | 17/6/2026 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection. | |
| Modificada | Media (6.1) | 1.7% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 21/3/2019 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in… | |
| Modificada | Crítica (9.8) | 2.1% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 14/3/2018 | 17/6/2026 | Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This… | |
| Modificada | Alta (8.1) | 1.6% | — | Updraftplus | 17/11/2017 | 17/6/2026 | The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race condition before deleting a file associated with the name parameter. NOTE: the vendor reports that this does not cross a privilege boundary | |
| Modificada | Alta (8.1) | 0.96% | — | Updraftplus | 17/11/2017 | 17/6/2026 | The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the vendor reports that this does not cross a privilege boundary |