Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

216 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.53%—Smarts-srl Smart Agent27/12/202417/6/2026
SmartAgent v1.1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/interface.php.
AnalizadaMedia (5.4)0.23%—IBM Carbon Charts10/12/202417/6/2026
IBM Carbon Design System (Carbon Charts 0.4.0 through 1.13.16) is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaMedia (6.1)0.76%—Benhuson Page Parts21/11/202417/6/2026
The Page Parts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they…
AplazadaMedia (6.5)0.32%—Baptiste Wicht Google-visualization-chartsAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Baptiste Wicht Google Visualization Charts google-visualization-charts allows Stored XSS.This issue affects Google Visualization Charts: from n/a through <= 0.1.
ModificadaMedia (5.4)0.25%—Chartscss Coub29/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coub Coub coub allows DOM-Based XSS.This issue affects Coub: from n/a through <= 1.4.
AnalizadaMedia (6.1)0.38%—Amcharts\12/9/202417/6/2026
The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, 1.4.4 due to the ability to supply arbitrary JavaScript a lack of nonce validation on the preview functionality. This makes it possible for…
AnalizadaAlta (7.5)0.86%—Apollographql Apollo-routerApollographql Apollo Helms-charts RouterApollographql Apollo Router27/8/202417/6/2026
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service vulnerability if _all_ of the following are true: 1. The Apollo…
AnalizadaAlta (7.5)0.99%—Apollographql Apollo-routerApollographql Apollo GatewayApollographql Apollo Helms-charts RouterApollographql Apollo Query-planner+127/8/202417/6/2026
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and <2.8.5 are impacted by a denial-of-service vulnerability.…
AplazadaCrítica (9.8)0.65%—SmartspsAI9/7/202417/6/2026
An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.
AnalizadaMedia (6.3)0.83%—Ag-gridAg-grid AG Charts1/7/202417/6/2026
ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
ModificadaMedia (4.8)0.39%—Goldbroker Live Gold Price & Silver Price Charts Widgets14/11/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GoldBroker.Com Live Gold Price & Silver Price Charts Widgets plugin <= 2.4 versions.
ModificadaAlta (7.5)0.73%—Apollographql Apollo RouterApollographql Apollo Helms-charts Router18/10/202317/6/2026
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send…
ModificadaMedia (5.4)0.51%—Wpartisan Wordpress Charts20/9/202317/6/2026
The WordPress Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wp_charts' shortcode in versions up to, and including, 0.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and…
ModificadaCrítica (9.8)0.81%—Carts.guru Cartsguru15/9/202317/6/2026
Carts Guru cartsguru up to v2.4.2 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::display().
ModificadaAlta (7.5)0.94%—Smartsoft Smartbpm.net10/7/202317/6/2026
SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.
ModificadaCrítica (9.1)0.94%—Smartsoft Smartbpm.net10/7/202317/6/2026
SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privilege to read application data, and execute submission and approval processes.
ModificadaCrítica (9.8)1.0%—Smartsoft Smartbpm.net10/7/202317/6/2026
SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.
ModificadaMedia (4.8)0.37%—Stock Market Charts From Finviz3/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Moris Dov Stock market charts from finviz plugin <= 1.0.1 versions.
ModificadaAlta (7.8)0.43%—Serenity SereneSerenity Startsharp27/4/202317/6/2026
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This token remains valid even after the password reset and can be used a second time to change the password of the corresponding user. The token…
ModificadaMedia (5.3)1.0%—Serenity SereneSerenity Startsharp27/4/202317/6/2026
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to reset a password of a non-existent user, an error message indicates that this user does not exist.
ModificadaMedia (6.1)0.78%—Serenity SereneSerenity Startsharp27/4/202317/6/2026
An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some specific file endings are not allowed, but it is possible to upload .html or .htm files containing an XSS payload. The resulting link can be sent to an administrator user.
ModificadaAlta (8.8)1.1%—Save Your Carts AND BUY Later OR Send IT Project Save Your Carts AND BUY Later OR Send IT10/4/202317/6/2026
SQL injection vulnerability found in PrestaShop Igbudget v.1.0.3 and before allow a remote attacker to gain privileges via the LgBudgetBudgetModuleFrontController::displayAjaxGenerateBudget component.
ModificadaMedia (5.4)0.55%—Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System13/3/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add User Account. The manipulation of the argument username leads to cross site scripting. It is possible to launch the attack remotely. The…
ModificadaCrítica (9.8)0.81%—Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System11/3/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Computer Parts Sales and Inventory System 1.0. This affects an unknown part of the file cust_transac.php. The manipulation of the argument phonenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaMedia (5.4)0.59%—Computer Parts Sales AND Inventory System Project Computer Parts Sales AND Inventory System5/3/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add Supplier Handler. The manipulation of the argument company_name/province/city/phone_number leads to cross site scripting. It is possible…
Orbitaley — Vulnerabilidades