Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 12 respecto a la semana anterior
Críticas / altas1272▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
2098 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.75% | — | Campcodes Advanced Online Voting System | 14/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in Campcodes Advanced Online Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ballot_down.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed… | |
| Analizada | Alta (8.8) | 0.75% | — | Campcodes Advanced Online Voting System | 14/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Campcodes Advanced Online Voting System 1.0. Affected is an unknown function of the file /admin/positions_row.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.8) | 0.79% | — | Campcodes Advanced Online Voting System | 14/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/positions_add.php. The manipulation of the argument description leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 0.74% | — | Campcodes Advanced Online Voting System | 14/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/ballot_up.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.8) | 0.74% | — | Campcodes Advanced Online Voting System | 14/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/voters_row.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.8) | 0.74% | — | Campcodes Advanced Online Voting System | 14/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Advanced Online Voting System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument voter leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (7.5) | 0.95% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Alta (7.5) | 0.72% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Alta (7.5) | 0.95% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Alta (7.8) | 0.22% | — | Jtekt Screen Creator Advance 2 | 11/4/2023 | 17/6/2026 | Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the bounds of a memory buffer (CWE-119) due to improper check of its data size when processing a project file. If a user of Screen Creator Advance 2 opens a specially crafted project file, information… | |
| Modificada | Alta (7.8) | 0.89% | — | Jtekt Screen Creator Advance 2 | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of KOYO Screen Creator 0.1.1.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SCA2 files.… | |
| Modificada | Media (4.8) | 0.39% | — | Advancedformintegration Advanced Form Integration | 23/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nasirahmed Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration plugin <= 1.62.0 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Wpbean WPB Advanced FAQ | 20/3/2023 | 17/6/2026 | The WPB Advanced FAQ WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (4.8) | 0.39% | — | Nsthemes Advanced Social Pixel | 20/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NsThemes Advanced Social Pixel plugin <= 2.1.1 versions. | |
| Analizada | Crítica (9.8) | 0.86% | — | Microfocus Netiq Advanced Authentication | 15/3/2023 | 17/6/2026 | Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2 | |
| Modificada | Alta (8.8) | 0.90% | — | Prestashop Advanced Reviews | 14/3/2023 | 17/6/2026 | PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection. | |
| Modificada | Media (6.7) | 0.37% | — | Mcafee Advanced Threat DefenseTrellix Intelligent Sandbox | 13/3/2023 | 17/6/2026 | A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The… | |
| Modificada | Alta (8.8) | 1.1% | — | Okta Advanced Server Access | 6/3/2023 | 17/6/2026 | Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An outdated library, webbrowser, used by the ASA client was found to be vulnerable to command injection. To exploit this issue, an attacker would need to phish the user to… | |
| Modificada | Media (5.4) | 0.47% | — | Advanced Recent Posts Project Advanced Recent Posts | 6/3/2023 | 17/6/2026 | The Advanced Recent Posts WordPress plugin through 0.6.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Crítica (9.8) | 1.1% | — | Wago 751-9301 FirmwareWago 752-8303/8000-002 FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 27/2/2023 | 17/6/2026 | The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise. | |
| Modificada | Media (5.3) | 0.25% | — | Wago 751-9301 FirmwareWago 752-8303/8000-002 FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 27/2/2023 | 17/6/2026 | A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the… | |
| Modificada | Crítica (9.8) | 0.74% | — | Wago 751-9301 FirmwareWago 752-8303/8000-002 FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 27/2/2023 | 17/6/2026 | The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device. | |
| Modificada | Media (6.1) | 0.38% | — | Wago 751-9301 FirmwareWago 752-8303/8000-002 FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 27/2/2023 | 17/6/2026 | The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no impact of availability. | |
| Modificada | Media (6.1) | 0.50% | — | Vsourz Advanced CF7 DB | 13/2/2023 | 17/6/2026 | Las versiones 1.7.2 y 1.9.1 de Vsourz Digital Advanced Contact form 7 DB son vulnerables a Cross Site Scripting (XSS). | |
| Modificada | Alta (7.8) | 0.29% | — | Jtekt Screen Creator Advance 2 | 13/2/2023 | 17/6/2026 | Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process even when an error was detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution. |