Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 6.4% | — | Answer | 8/2/2023 | 17/6/2026 | Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4. | |
| Modificada | Crítica (9) | 0.74% | — | Answer | 8/2/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4. | |
| Modificada | Crítica (9) | 0.87% | — | Answer | 8/2/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4. | |
| Modificada | Crítica (9) | 0.87% | — | Answer | 8/2/2023 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4. | |
| Modificada | Crítica (9) | 0.71% | — | Answer | 8/2/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4. | |
| Modificada | Media (6.8) | 0.69% | — | Answer | 8/2/2023 | 17/6/2026 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitHub repository answerdev/answer prior to 1.0.4. | |
| Modificada | Media (4.3) | 0.43% | — | Designwall DW Question & Answer | 25/4/2022 | 17/6/2026 | The DW Question & Answer Pro WordPress plugin through 1.3.4 does not properly check for CSRF in some of its functions, allowing attackers to make logged in users perform unwanted actions, such as update a comment or a question status. | |
| Modificada | Media (4.3) | 0.65% | — | Designwall DW Question & Answer | 25/4/2022 | 17/6/2026 | The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comments. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Alta (7.5) | 1.4% | — | Devada Dzone Answerhub | 28/10/2019 | 17/6/2026 | An XML External Entity Injection vulnerability exists in Dzone AnswerHub. | |
| Modificada | Crítica (9.8) | 2.7% | — | Jextn Question AND Answer | 27/12/2017 | 17/6/2026 | The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Question2answer | 29/8/2017 | 17/6/2026 | qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts. | |
| Modificada | Media (5) | 1.5% | — | George Karpouzas YET Another Question & Answer System | 13/8/2012 | 16/6/2026 | Yaqas (Yet Another Question & Answer System) 1.0 Alpha 1 allows remote attackers to obtain sensitive information via an invalid character in the PHPSESSID, which reveals the installation path in an error message. | |
| Modificada | Media (4.3) | 1.3% | — | Hitronsoft Answer ME | 11/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0 allows remote attackers to inject arbitrary web script or HTML via the q_id parameter to the answers script (aka answers.php). NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.3% | — | Turnkeyforms Yahoo-answers-clone | 11/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML via the questionid parameter. | |
| Modificada | Alta (7.5) | 0.93% | — | Questions Answered | 18/3/2010 | 16/6/2026 | SQL injection vulnerability in the administrative interface in Questions Answered 1.3 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.4) | 2.3% | — | Easy-scripts Answer AND Question Script | 18/5/2009 | 16/6/2026 | myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter without specifying any additional fields. | |
| Modificada | Alta (7.5) | 2.0% | — | Easy-scripts Answer AND Question Script | 18/5/2009 | 16/6/2026 | myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via modified userid, txtpassword, and txtRpassword parameters. | |
| Modificada | Media (6.8) | 2.9% | — | Easy-scripts Answer AND Question Script | 18/5/2009 | 16/6/2026 | Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads/[username] directory. | |
| Modificada | Media (6.5) | 1.7% | — | Easy-scripts Answer AND Question Script | 16/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitrary SQL commands via the (1) user name (userid parameter) and (2) password. | |
| Modificada | Media (4.3) | 1.5% | — | Easy-scripts Answer AND Question Script | 16/5/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy Scripts Answer and Question Script allows remote attackers to inject arbitrary web script or HTML via the questionid parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Ticklespace Answers Module | 6/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Answers module 5.x-1.x-dev and possibly other 5.x versions, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a Simple Answer to a question. | |
| Modificada | Alta (7.5) | 1.2% | — | Phpstore Yahoo Answers | 12/12/2008 | 16/6/2026 | SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (9.3) | 38% | — | Intuit BookkeepingIntuit ProseriesIntuit QuickbooksIntuit Quicken+4 | 15/12/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping, ProSeries, QuickBooks, Quicken, QuickTax, and TurboTax, allow remote attackers to execute arbitrary code via long arguments to the (1)… | |
| Modificada | Media (4.3) | 1.7% | — | SUN Solaris Answerbook2 | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the "View Log Files" function. |