Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.11% | — | Argus Surveillance DVRAI | 10/5/2026 | 25/7/2026 | Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the… | |
| Aplazada | Alta (8.8) | 0.28% | — | Survey AND PollAI | 10/5/2026 | 25/7/2026 | WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap cookie parameter. Attackers can craft SQL payloads in the cookie to extract sensitive database information including… | |
| Aplazada | Media (5.3) | 0.67% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 17/4/2026 | 17/6/2026 | The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pass through sanitize_text_field() and… | |
| Analizada | Media (6.1) | 0.28% | — | Limesurvey | 9/4/2026 | 17/6/2026 | Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the Box[title] and box[url] parameters. | |
| Analizada | Media (6.1) | 0.23% | — | Limesurvey | 9/4/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validation of gid parameter in getInstance() function in application/models/QuestionCreate.php. This allows an attacker to craft a malicious URL and compromise the logged in user. | |
| Aplazada | Alta (8.7) | 0.44% | — | Console-surveyAI | 30/3/2026 | 17/6/2026 | A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIMESTAMP}/' endpoint. Exploiting this vulnerability would allow an unauthenticated attacker to enumerate event IDs and obtain the complete Q&A history. This publicly exposed data may include IDs,… | |
| Aplazada | Media (6.5) | 0.32% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 23/3/2026 | 17/6/2026 | The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter in all versions up to, and including, 10.3.5. This is due to insufficient sanitization of user-supplied input before being used in a SQL query. The sanitize_text_field() function applied to the… | |
| Aplazada | Alta (7.2) | 0.28% | — | SurveyjsAI | 21/3/2026 | 17/6/2026 | The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.3 via survey result submissions. This is due to insufficient input sanitization and output escaping. The public survey page exposes the nonce required for submission, allowing unauthenticated… | |
| Aplazada | Media (4.4) | 0.24% | — | SurveyAI | 21/3/2026 | 17/6/2026 | The Survey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary… | |
| Modificada | Crítica (9.8) | 0.85% | — | Limesurvey | 10/3/2026 | 5/7/2026 | A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server. | |
| Modificada | Alta (7.5) | 0.47% | — | Limesurvey | 10/3/2026 | 5/7/2026 | SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database. | |
| Analizada | Baja (2.1) | 0.50% | — | Tiandy Video Surveillance System Firmware | 9/3/2026 | 17/6/2026 | A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile of the file /src/com/tiandy/easy7/core/rest/CLS_REST_File.java. The manipulation of the argument fileName leads to unrestricted upload. The attack may be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 0.36% | — | Tiandy Video Surveillance SystemAI | 23/2/2026 | 17/6/2026 | A security flaw has been discovered in Tiandy Video Surveillance System 视频监控平台 7.17.0. This impacts the function downloadImage of the file /com/tiandy/easy7/core/bo/CLSBODownLoad.java. Performing a manipulation of the argument urlPath results in server-side request forgery. The attack is possible to be carried out… | |
| Aplazada | Alta (8.5) | 0.27% | — | Expresstechsystems Quiz AND Survey MasterAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows SQL Injection.This issue affects Quiz And Survey Master: from n/a through <= 10.3.1. | |
| Aplazada | Media (5.1) | 0.27% | — | Ays-pro Survey MakerAI | 20/2/2026 | 17/6/2026 | WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. | |
| Aplazada | Media (4.3) | 0.19% | — | Expresstechsystems Quiz AND Survey MasterAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4. | |
| Aplazada | Media (5.3) | 0.33% | — | Expresstechsystems Quiz AND Survey MasterAI | 19/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4. | |
| Aplazada | Media (5.1) | 0.28% | — | Zendesk Sweethawk SurveyAI | 3/2/2026 | 17/6/2026 | Zendesk SweetHawk Survey 1.6 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through support ticket submissions. Attackers can insert XSS payloads like script tags into ticket text that automatically execute when survey pages are loaded by other users. | |
| Modificada | Media (5.1) | 0.29% | — | Limesurvey | 28/1/2026 | 17/6/2026 | LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can inject malicious SVG scripts through the Surveymenu[title] and Surveymenu[parent_id] parameters to execute arbitrary JavaScript in administrative contexts. | |
| Aplazada | Media (4.3) | 0.14% | — | Surveyjs Drag Drop Wordpress Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the `SurveyJS_CloneSurvey` AJAX action. This… | |
| Aplazada | Media (4.3) | 0.15% | — | Surveyjs Drag Drop Wordpress Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce verification on the 'SurveyJS_RenameSurvey' AJAX action. This makes it… | |
| Aplazada | Media (4.3) | 0.15% | — | Surveyjs Drag AND Drop Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce validation on the SurveyJS_AddSurvey AJAX action. This makes it possible for unauthenticated attackers to create surveys via a… | |
| Aplazada | Media (4.3) | 0.18% | — | Expresstechsystems Quiz AND Survey MasterAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.3. | |
| Aplazada | Media (5.1) | 0.47% | — | Opinionstage Poll Survey AND Quiz MakerAI | 16/1/2026 | 17/6/2026 | Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes… | |
| Analizada | Alta (7.5) | 0.31% | — | Rustcrypto SM2 Elliptic Curve | 10/1/2026 | 17/6/2026 | RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a denial-of-service vulnerability exists in the SM2… |