Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.38% | — | Cagewebdev Order Your Posts Manually | 24/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <= 2.2.5 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Cagewebdev Order Your Posts Manually | 23/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <= 2.2.5 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Pradeepsinghweb Dynamically Register Sidebars | 17/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= 1.0.1 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 17/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.6 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions. | |
| Modificada | Media (5.5) | 0.12% | — | Siemens Totally Integrated Automation Portal | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All… | |
| Modificada | Alta (8.8) | 0.26% | — | 984.ru FOR THE Visually Impaired | 26/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in 984.Ru For the visually impaired plugin <= 0.58 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Hasthemes Really Simple Google TAG Manager | 6/4/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6 versions. | |
| Modificada | Media (5.4) | 0.56% | — | Really-simple-plugins Complianz | 27/3/2023 | 17/6/2026 | The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site… | |
| Modificada | Alta (8.8) | 1.3% | — | Really-simple-plugins Complianz | 7/11/2022 | 17/6/2026 | The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco… | |
| Modificada | Alta (7.5) | 1.4% | — | Siemens Simatic PCS NEOSiemens SinetplanSiemens Totally Integrated Automation Portal | 12/4/2022 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15, V15.1, V16 and V17). The affected system cannot properly process specially crafted packets sent to port 8888/tcp. A remote attacker could exploit this vulnerability to… | |
| Modificada | Media (6.1) | 0.88% | — | Really-simple-plugins Complianz | 14/2/2022 | 17/6/2026 | The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 1.1% | — | Baxter Welch Allyn Connex CardioBaxter Welch Allyn Diagnostic Cardiology SuiteBaxter Welch Allyn Rscribe Resting ECG SystemBaxter Welch Allyn Vision Express Holter Analysis System+3 | 15/12/2021 | 17/6/2026 | The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the… | |
| Modificada | Alta (7.5) | 5.4% | 💥 Exploit | Accessally | 12/4/2021 | 17/6/2026 | In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping serialize($_SERVER), which contains all environment variables. The leakage occurs on all public facing pages containing the… | |
| Modificada | Alta (7.8) | 0.86% | — | Siemens Simatic Process Control System NEOSiemens Totally Integrated Automation Portal | 9/2/2021 | 17/6/2026 | A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain files in specific folders could allow a local attacker to execute code with SYSTEM privileges. The security vulnerability could be exploited by an attacker with a valid… | |
| Modificada | Alta (8.8) | 4.9% | 💥 PoC | Macally Wifisd2-2a82 Firmware | 14/12/2020 | 17/6/2026 | In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability which can be used to take over the administrator account and results in shell access. As the admin user may read the /etc/shadow file, the password hashes of each user… | |
| Modificada | Alta (7.8) | 0.43% | — | Siemens Totally Integrated Automation Portal | 16/1/2020 | 17/6/2026 | A vulnerability has been identified in TIA Portal V14 (All versions), TIA Portal V15 (All versions < V15.1 Update 7), TIA Portal V16 (All versions < V16 Update 6), TIA Portal V17 (All versions < V17 Update 4). Changing the contents of a configuration file could allow an attacker to execute arbitrary code with SYSTEM… | |
| Modificada | Media (5.3) | 0.58% | — | Really Jwt-scala | 12/10/2017 | 17/6/2026 | jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token. | |
| Modificada | Media (6.8) | 1.0% | — | WP Limit Posts Automatically Project WP Limit Posts Automatically | 31/12/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WP Limit Posts Automatically plugin 0.7 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the lpa_post_letters parameter in the… | |
| Modificada | Media (5.4) | 0.27% | — | ISS Rally Albania Live 2014 | 21/10/2014 | 17/6/2026 | The Rally Albania Live 2014 (aka com.wRallyAlbaniaLIVE2014) application 0.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.1% | — | Reallysimplechat Really Simple Chat | 29/6/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in chat/base/admin/login.php in A Really Simple Chat (ARSC) 3.3-rc2 allows remote attackers to inject arbitrary web script or HTML via the arsc_message parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Reallysimplechat Really Simple Chat | 29/6/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in A Really Simple Chat (ARSC) 3.3-rc2 allow remote attackers to execute arbitrary SQL commands via the (1) arsc_user parameter to base/admin/edit_user.php, (2) arsc_layout_id parameter in base/admin/edit_layout.php, or (3) arsc_room parameter to base/admin/edit_room.php. | |
| Modificada | Media (4.3) | 1.1% | — | Reallysimplechat Really Simple Chat | 29/6/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in dereferer.php in A Really Simple Chat (ARSC) 3.3-rc2 allows remote attackers to inject arbitrary web script or HTML via the arsc_link parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Joshua Oliver Really Simple CMS | 17/8/2009 | 16/6/2026 | Directory traversal vulnerability in plugings/pagecontent.php in Really Simple CMS (RSCMS) 0.3a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PT parameter. | |
| Modificada | Media (5) | 1.9% | — | Drupal Semantically Interconnected Online Communities | 18/2/2009 | 16/6/2026 | Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement menu and database APIs, which allows remote attackers to obtain usernames and read hashed emails and comments via unspecified vectors. |