Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.38% | — | Church Admin Project Church Admin | 23/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.29 versions. | |
| Modificada | Crítica (9.8) | 0.87% | — | Funadmin | 22/6/2023 | 17/6/2026 | funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install. | |
| Modificada | Media (6.1) | 0.54% | — | Thinkadmin | 15/6/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arbitrary code via a crafted file. | |
| Modificada | Media (6.1) | 0.38% | — | Zestard Admin Side Data Storage FOR Contact Form 7 | 15/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <= 1.1.1 versions. | |
| Modificada | Alta (8.8) | 1.2% | — | Wpruby Controlled Admin Access | 7/6/2023 | 17/6/2026 | The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted access. | |
| Modificada | Media (5.4) | 0.40% | — | Dcatadmin Dcat Admin | 31/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Dcat-Admin v2.1.3-beta allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter. | |
| Modificada | Alta (8.8) | 0.26% | — | Admin Block Country Project Admin Block Country | 26/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in TheOnlineHero - Tom Skroza Admin Block Country plugin <= 7.1.4 versions. | |
| Modificada | Alta (7.1) | 0.30% | — | Opentext Archive Center Administration | 24/5/2023 | 17/6/2026 | The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft… | |
| Modificada | Media (6.1) | 0.55% | — | Rediker Adminplus | 3/5/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Rediker Software AdminPlus 6.1.91.00 allows remote attackers to run arbitrary code via the onload function within the application DOM. | |
| Modificada | Media (6.1) | 0.55% | — | Funadmin | 2/5/2023 | 17/6/2026 | A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (5.4) | 0.40% | — | Pearadmin Pear Admin Boot | 25/4/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Pear-Admin-Boot up to v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title of a private message. | |
| Modificada | Media (5.3) | 2.5% | — | Fedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityPython | 19/4/2023 | 17/6/2026 | The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after… | |
| Modificada | Media (4.9) | 0.64% | — | Tpadmin Project Tpadmin | 10/4/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in yuan1994 tpAdmin 1.3.12. Affected is the function remote of the file application\admin\controller\Upload.php. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack… | |
| Modificada | Alta (7.2) | 1.0% | — | Tpadmin Project Tpadmin | 10/4/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in yuan1994 tpAdmin 1.3.12. This issue affects the function Upload of the file application\admin\controller\Upload.php. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated… | |
| Modificada | Media (4.8) | 0.39% | — | Auto Hide Admin BAR Project Auto Hide Admin BAR | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcel Bootsman Auto Hide Admin Bar plugin <= 1.6.1 versions. | |
| Modificada | Media (6.1) | 0.49% | — | Phpminiadmin Project Phpminiadmin | 6/4/2023 | 17/6/2026 | A vulnerability classified as problematic was found in phpMiniAdmin up to 1.8.120510. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.9.140405 is able to address this issue. It is recommended to… | |
| Modificada | Media (5.4) | 0.60% | — | SAS WEB Administration Interface | 3/4/2023 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the user creation and editing form fields. The product name is SAS Web Administration interface (SASAdmin). For the product… | |
| Modificada | Media (6.5) | 8.8% | — | Pgadmin 4 | 27/3/2023 | 17/6/2026 | pgAdmin 4 versions prior to v6.19 contains a directory traversal vulnerability. A user of the product may change another user's settings or alter the database. | |
| Modificada | Alta (8.8) | 0.27% | — | Admin LOG Project Admin LOG | 20/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in David Gwyer Admin Log plugin <= 1.50 versions. | |
| Modificada | Media (5.4) | 0.33% | — | Onekeyadmin | 16/3/2023 | 17/6/2026 | onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Member List module. | |
| Modificada | Crítica (9.8) | 0.88% | — | Funadmin | 10/3/2023 | 17/6/2026 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php. | |
| Modificada | Crítica (9.1) | 0.61% | — | Onekeyadmin | 9/3/2023 | 17/6/2026 | onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins. | |
| Modificada | Alta (7.5) | 0.60% | — | Onekeyadmin | 9/3/2023 | 17/6/2026 | onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download. | |
| Modificada | Crítica (9.8) | 0.74% | — | Funadmin | 8/3/2023 | 17/6/2026 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list. | |
| Modificada | Crítica (9.8) | 0.74% | — | Funadmin | 8/3/2023 | 17/6/2026 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit. |