Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
157 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.5) | 0.28% | — | Wow-company Float Menu | 2/5/2024 | 17/6/2026 | The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack. | |
| Aplazada | Alta (7.5) | 0.75% | — | TVS Motor Company Limited TVS ConnetAI | 30/4/2024 | 17/6/2026 | An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to obtain sensitive information via an insecure API endpoint. NOTE: this is disputed as discussed in the msn-official/CVE-Evidence repository. | |
| Aplazada | Crítica (9.1) | 0.65% | — | TVS Motor Company Limited TVS ConnetAIGoogle AndroidAIApple IOSAI | 30/4/2024 | 17/6/2026 | An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate privileges via the Emergency Contact Feature. NOTE: this is disputed as discussed in the msn-official/CVE-Evidence repository. | |
| Modificada | Media (5.4) | 0.34% | — | Wow-company Modal Window | 9/4/2024 | 17/6/2026 | The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 5.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.32% | — | Micro.company Form TO Chat APPAI | 7/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Micro.Company Form to Chat App allows Stored XSS.This issue affects Form to Chat App: from n/a through 1.1.6. | |
| Modificada | Media (4.8) | 0.32% | — | Wow-company WP Coder | 21/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder allows Stored XSS.This issue affects WP Coder: from n/a through 3.5. | |
| Analizada | Media (6.6) | 0.92% | — | Microsoft Intune Company Portal | 12/3/2024 | 17/6/2026 | Microsoft Intune Linux Agent Elevation of Privilege Vulnerability | |
| Modificada | Media (4.8) | 0.30% | — | Wow-company Sticky Buttons | 23/1/2024 | 17/6/2026 | The Sticky Buttons – floating buttons builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sticky URLs in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Modificada | Media (4.8) | 0.57% | — | Phpgurukul Company Visitor Management System | 18/1/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file search-visitor.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to… | |
| Modificada | Alta (7.2) | 0.63% | — | Phpgurukul Company Visitor Management System | 18/1/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file search-visitor.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.22% | — | Wow-company Floating Button | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button.This issue affects Floating Button: from n/a through 6.0. | |
| Modificada | Alta (8.2) | 0.60% | — | Geniecompany Aladdin Connect Garage Door Opener Firmware | 3/1/2024 | 17/6/2026 | Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) "Garage Door Control Module Setup" and modify the Garage door's SSID settings. | |
| Modificada | Alta (8.8) | 0.55% | — | Geniecompany Aladdin Connect Garage Door Opener Firmware | 3/1/2024 | 17/6/2026 | When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” page is vulnerable to XSS via a broadcast SSID name containing malicious code with client side Java Script and/or HTML. This allows the attacker to… | |
| Modificada | Media (6.8) | 0.42% | — | Geniecompany Aladdin Connect | 3/1/2024 | 17/6/2026 | Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices. This allows the attacker, with access to the android device, to potentially retrieve users' clear text authentication credentials. | |
| Modificada | Alta (8.8) | 0.29% | — | Wow-company Button Generator | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder.This issue affects Button Generator – easily Button Builder: from n/a through 2.3.8. | |
| Modificada | Alta (8.8) | 0.33% | — | Wow-company Side Menu Lite | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite – add sticky fixed buttons plugin <= 4.0 versions. | |
| Modificada | Alta (7.2) | 0.79% | — | Company Website CMS Project Company Website CMS | 2/11/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Company Website CMS 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /dashboard/createblog of the component Create Blog Page. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit… | |
| Modificada | Media (5.4) | 0.66% | — | Wow-company Modal Window | 27/9/2023 | 17/6/2026 | The Modal Window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above… | |
| Modificada | Crítica (9.8) | 0.67% | — | Acekaholding Company Management | 14/9/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aceka Company Management allows SQL Injection. This issue affects Company Management: before 3072 . | |
| Modificada | Media (4.3) | 0.25% | — | Wow-company Herd Effects | 11/9/2023 | 17/6/2026 | The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack | |
| Modificada | Media (4.8) | 0.47% | — | Wow-company Herd Effects | 11/9/2023 | 17/6/2026 | The Herd Effects WordPress plugin before 5.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.72% | — | Wow-company Bubble Menu | 7/8/2023 | 17/6/2026 | The Bubble Menu WordPress plugin before 3.0.5 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |
| Modificada | Media (6.5) | 0.22% | — | Wow-company Button Generator | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.5 versions. | |
| Modificada | Media (4.8) | 0.56% | — | Wow-company Float Menu | 10/7/2023 | 17/6/2026 | The Float menu WordPress plugin before 5.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.46% | — | Wow-company Bubble MenuWow-company Button GeneratorWow-company Calculator-builderWow-company Counter BOX+8 | 12/6/2023 | 17/6/2026 | The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before… |