Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
179 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 4.8% | 💥 Exploit | Transposh Wordpress Translation | 6/9/2022 | 17/6/2026 | The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for… | |
| Modificada | Alta (7.2) | 1.7% | — | Transposh Wordpress Translation | 22/8/2022 | 17/6/2026 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allow allowing high privilege users such as admin to perform RCE | |
| Modificada | Alta (7.2) | 1.4% | — | Transposh Wordpress Translation | 22/8/2022 | 17/6/2026 | The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby parameters before using them in a SQL statement, leading to a SQL injection | |
| Modificada | Media (6.5) | 1.0% | — | Transposh Wordpress Translation | 22/8/2022 | 17/6/2026 | The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_reset” under the Utilities tab (/wp-admin/admin.php?page=tp_utils), which can be used/executed as the lowest-privileged user. Basically all Utilities functionalities are vulnerable this way, which… | |
| Modificada | Media (5.4) | 0.34% | — | Transposh Wordpress Translation | 22/8/2022 | 17/6/2026 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. Given the lack of sanitisation in the tk0 parameter, this could lead to a Stored Cross-Site Scripting issue which will be… | |
| Modificada | Media (5.4) | 0.67% | — | Transposh Wordpress Translation | 22/8/2022 | 17/6/2026 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The minimum role needed to perform such attack depends on the plugin… | |
| Modificada | Media (6.1) | 1.6% | 💥 Exploit | Transposh Wordpress Translation | 22/8/2022 | 17/6/2026 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.81% | — | Oracle Transportation Management | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: User Interface). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Transportation Management.… | |
| Modificada | Media (6.5) | 1.2% | — | WireWire-ios-transport | 11/3/2022 | 17/6/2026 | Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions prior to 3.95 malformed resource identifiers may render the iOS Wire Client completely unusable by causing it to repeatedly crash on launch. These malformed resource identifiers can be generated and sent between Wire… | |
| Modificada | Crítica (9.8) | 2.4% | — | Broadcom Xcom Data Transport | 14/2/2022 | 17/6/2026 | XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validation that could potentially allow remote attackers to execute arbitrary commands with elevated privileges. | |
| Modificada | Alta (7.5) | 0.61% | — | Digi Transport Wr11 FirmwareDigi Transport Wr11 XT FirmwareDigi Transport Wr21 FirmwareDigi Transport Wr31 Firmware+2 | 10/12/2021 | 17/6/2026 | An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session. | |
| Modificada | Alta (8.8) | 0.48% | — | Digi Transport Dr64 FirmwareDigi Transport Vc74 FirmwareDigi Transport Wr11 FirmwareDigi Transport Wr11 XT Firmware+4 | 10/12/2021 | 17/6/2026 | An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firmware (because the bootloader does not verify that it is authentic), changing the behavior of the gateway. | |
| Modificada | Media (6.5) | 0.70% | — | Digi Transport Dr64 FirmwareDigi Transport Vc74 FirmwareDigi Transport Wr11 FirmwareDigi Transport Wr11 XT Firmware+4 | 10/12/2021 | 17/6/2026 | An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file (with reversible passwords) from the device, which allows decoding of other users' passwords. | |
| Modificada | Crítica (9.8) | 3.7% | — | Digi Transport Dr64 FirmwareDigi Transport Sr44 FirmwareDigi Transport Vc74 FirmwareDigi Transport Wr11 Firmware+5 | 10/12/2021 | 17/6/2026 | An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with knowledge of the protocol) to execute arbitrary code on the controller including overwriting firmware, adding/removing users, disabling the… | |
| Modificada | Media (5.4) | 28% | 💥 PoC | Oracle Transportation Management | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). The supported version that is affected is 6.4.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful… | |
| Modificada | Media (5.3) | 1.2% | — | Oracle Transportation Management | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The supported version that is affected is 6.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Transportation Management. Successful… | |
| Modificada | Crítica (9.8) | 0.69% | — | Digi RealportDigi Connectport TS 8/16 FirmwareDigi Connectport LTS 8/16/32 FirmwareDigi Passport Integrated Console Server Firmware+15 | 8/10/2021 | 17/6/2026 | In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed version of the server's access password. The… | |
| Modificada | Alta (8.1) | 0.89% | — | Digi RealportDigi Connectport TS 8/16 FirmwareDigi Connectport LTS 8/16/32 FirmwareDigi Passport Integrated Console Server Firmware+14 | 8/10/2021 | 17/6/2026 | An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform authentication. | |
| Modificada | Crítica (9.8) | 1.6% | — | Digi RealportDigi Connectport TS 8/16 FirmwareDigi Connectport LTS 8/16/32 FirmwareDigi Passport Integrated Console Server Firmware+14 | 8/10/2021 | 17/6/2026 | An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP discovery response messages. This could result in arbitrary code execution. | |
| Modificada | Alta (7.5) | 1.0% | — | Transpile Project Transpile | 24/8/2021 | 17/6/2026 | All versions of package transpile are vulnerable to Denial of Service (DoS) due to a lack of input sanitization or whitelisting, coupled with improper exception handling in the .to() function. | |
| Modificada | Alta (8.1) | 1.2% | — | Oracle Transportation Execution | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Install and Upgrade). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution.… | |
| Modificada | Crítica (9.8) | 1.5% | — | Nakivo Backup & Replication Transporter | 24/9/2020 | 17/6/2026 | Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup repositories and the Nakivo Controller configuration via a network accessible transporter service. It is also possible to create or delete backup repositories. | |
| Modificada | Alta (8.2) | 0.89% | — | IBM Control DeskIBM Maximo Asset Configuration ManagerIBM Maximo Asset Health InsightsIBM Maximo Asset Management+16 | 16/9/2020 | 17/6/2026 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to redirect a user to a malicious Web site that would appear to be trusted.… | |
| Modificada | Media (4.3) | 0.87% | — | Oracle Transportation Management | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Data, Domain & Function Security). The supported version that is affected is 6.4.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation… | |
| Modificada | Alta (7) | 56% | 💥 Exploit | Apache TomcatDebian LinuxOpensuse LeapFedoraproject Fedora+22 | 20/5/2020 | 25/8/2026 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is… |