Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

108 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.38%—Cagewebdev Order Your Posts Manually24/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <= 2.2.5 versions.
ModificadaMedia (6.1)0.38%—Cagewebdev Order Your Posts Manually23/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <= 2.2.5 versions.
ModificadaMedia (4.8)0.37%—Pradeepsinghweb Dynamically Register Sidebars17/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= 1.0.1 versions.
ModificadaMedia (6.1)0.38%—Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes17/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.6 versions.
ModificadaAlta (8.8)0.26%—Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions.
ModificadaMedia (5.5)0.12%—Siemens Totally Integrated Automation Portal13/6/202317/6/2026
A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All…
ModificadaAlta (8.8)0.26%—984.ru FOR THE Visually Impaired26/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in 984.Ru For the visually impaired plugin <= 0.58 versions.
ModificadaAlta (8.8)0.26%—Hasthemes Really Simple Google TAG Manager6/4/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6 versions.
ModificadaMedia (5.4)0.56%—Really-simple-plugins Complianz27/3/202317/6/2026
The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site…
ModificadaAlta (8.8)1.3%—Really-simple-plugins Complianz7/11/202217/6/2026
The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco…
ModificadaAlta (7.5)1.4%—Siemens Simatic PCS NEOSiemens SinetplanSiemens Totally Integrated Automation Portal12/4/202217/6/2026
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15, V15.1, V16 and V17). The affected system cannot properly process specially crafted packets sent to port 8888/tcp. A remote attacker could exploit this vulnerability to…
ModificadaMedia (6.1)0.88%—Really-simple-plugins Complianz14/2/202217/6/2026
The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaCrítica (9.8)1.1%—Baxter Welch Allyn Connex CardioBaxter Welch Allyn Diagnostic Cardiology SuiteBaxter Welch Allyn Rscribe Resting ECG SystemBaxter Welch Allyn Vision Express Holter Analysis System+315/12/202117/6/2026
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the…
ModificadaAlta (7.5)5.4%💥 ExploitAccessally12/4/202117/6/2026
In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping serialize($_SERVER), which contains all environment variables. The leakage occurs on all public facing pages containing the…
ModificadaAlta (7.8)0.86%—Siemens Simatic Process Control System NEOSiemens Totally Integrated Automation Portal9/2/202117/6/2026
A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain files in specific folders could allow a local attacker to execute code with SYSTEM privileges. The security vulnerability could be exploited by an attacker with a valid…
ModificadaAlta (8.8)4.9%💥 PoCMacally Wifisd2-2a82 Firmware14/12/202017/6/2026
In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability which can be used to take over the administrator account and results in shell access. As the admin user may read the /etc/shadow file, the password hashes of each user…
ModificadaAlta (7.8)0.43%—Siemens Totally Integrated Automation Portal16/1/202017/6/2026
A vulnerability has been identified in TIA Portal V14 (All versions), TIA Portal V15 (All versions < V15.1 Update 7), TIA Portal V16 (All versions < V16 Update 6), TIA Portal V17 (All versions < V17 Update 4). Changing the contents of a configuration file could allow an attacker to execute arbitrary code with SYSTEM…
ModificadaMedia (5.3)0.58%—Really Jwt-scala12/10/201717/6/2026
jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.
ModificadaMedia (6.8)1.0%—WP Limit Posts Automatically Project WP Limit Posts Automatically31/12/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in the WP Limit Posts Automatically plugin 0.7 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the lpa_post_letters parameter in the…
ModificadaMedia (5.4)0.27%—ISS Rally Albania Live 201421/10/201417/6/2026
The Rally Albania Live 2014 (aka com.wRallyAlbaniaLIVE2014) application 0.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.1%—Reallysimplechat Really Simple Chat29/6/201116/6/2026
Cross-site scripting (XSS) vulnerability in chat/base/admin/login.php in A Really Simple Chat (ARSC) 3.3-rc2 allows remote attackers to inject arbitrary web script or HTML via the arsc_message parameter.
ModificadaAlta (7.5)1.1%—Reallysimplechat Really Simple Chat29/6/201116/6/2026
Multiple SQL injection vulnerabilities in A Really Simple Chat (ARSC) 3.3-rc2 allow remote attackers to execute arbitrary SQL commands via the (1) arsc_user parameter to base/admin/edit_user.php, (2) arsc_layout_id parameter in base/admin/edit_layout.php, or (3) arsc_room parameter to base/admin/edit_room.php.
ModificadaMedia (4.3)1.1%—Reallysimplechat Really Simple Chat29/6/201116/6/2026
Cross-site scripting (XSS) vulnerability in dereferer.php in A Really Simple Chat (ARSC) 3.3-rc2 allows remote attackers to inject arbitrary web script or HTML via the arsc_link parameter.
ModificadaAlta (7.5)2.3%💥 ExploitJoshua Oliver Really Simple CMS17/8/200916/6/2026
Directory traversal vulnerability in plugings/pagecontent.php in Really Simple CMS (RSCMS) 0.3a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PT parameter.
ModificadaMedia (5)1.9%—Drupal Semantically Interconnected Online Communities18/2/200916/6/2026
Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement menu and database APIs, which allows remote attackers to obtain usernames and read hashed emails and comments via unspecified vectors.
Orbitaley — Vulnerabilidades