Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

106 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)6.4%—Answer8/2/202317/6/2026
Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.
ModificadaCrítica (9)0.74%—Answer8/2/202317/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.
ModificadaCrítica (9)0.87%—Answer8/2/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
ModificadaCrítica (9)0.87%—Answer8/2/202317/6/2026
Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.
ModificadaCrítica (9)0.71%—Answer8/2/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
ModificadaMedia (6.8)0.69%—Answer8/2/202317/6/2026
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitHub repository answerdev/answer prior to 1.0.4.
ModificadaMedia (4.3)0.43%—Designwall DW Question & Answer25/4/202217/6/2026
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not properly check for CSRF in some of its functions, allowing attackers to make logged in users perform unwanted actions, such as update a comment or a question status.
ModificadaMedia (4.3)0.65%—Designwall DW Question & Answer25/4/202217/6/2026
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments.
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaAlta (7.5)1.4%—Devada Dzone Answerhub28/10/201917/6/2026
An XML External Entity Injection vulnerability exists in Dzone AnswerHub.
ModificadaCrítica (9.8)2.7%—Jextn Question AND Answer27/12/201717/6/2026
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
ModificadaAlta (7.5)1.6%—Question2answer29/8/201717/6/2026
qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts.
ModificadaMedia (5)1.5%—George Karpouzas YET Another Question & Answer System13/8/201216/6/2026
Yaqas (Yet Another Question & Answer System) 1.0 Alpha 1 allows remote attackers to obtain sensitive information via an invalid character in the PHPSESSID, which reveals the installation path in an error message.
ModificadaMedia (4.3)1.3%—Hitronsoft Answer ME11/5/201016/6/2026
Cross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0 allows remote attackers to inject arbitrary web script or HTML via the q_id parameter to the answers script (aka answers.php). NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.3%—Turnkeyforms Yahoo-answers-clone11/5/201016/6/2026
Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.
ModificadaAlta (7.5)0.93%—Questions Answered18/3/201016/6/2026
SQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.4)2.3%—Easy-scripts Answer AND Question Script18/5/200916/6/2026
myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter without specifying any additional fields.
ModificadaAlta (7.5)2.0%—Easy-scripts Answer AND Question Script18/5/200916/6/2026
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via modified userid, txtpassword, and txtRpassword parameters.
ModificadaMedia (6.8)2.9%—Easy-scripts Answer AND Question Script18/5/200916/6/2026
Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads/[username] directory.
ModificadaMedia (6.5)1.7%—Easy-scripts Answer AND Question Script16/5/200916/6/2026
Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitrary SQL commands via the (1) user name (userid parameter) and (2) password.
ModificadaMedia (4.3)1.5%—Easy-scripts Answer AND Question Script16/5/200916/6/2026
Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy Scripts Answer and Question Script allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.
ModificadaMedia (4.3)1.1%—Ticklespace Answers Module6/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Answers module 5.x-1.x-dev and possibly other 5.x versions, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a Simple Answer to a question.
ModificadaAlta (7.5)1.2%—Phpstore Yahoo Answers12/12/200816/6/2026
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (9.3)38%—Intuit BookkeepingIntuit ProseriesIntuit QuickbooksIntuit Quicken+415/12/200716/6/2026
Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping, ProSeries, QuickBooks, Quicken, QuickTax, and TurboTax, allow remote attackers to execute arbitrary code via long arguments to the (1)…
ModificadaMedia (4.3)1.7%—SUN Solaris Answerbook22/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the "View Log Files" function.