Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
173 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.37% | — | Lemeconsultoria Galera | 7/5/2025 | 17/6/2026 | SQL Injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the Data export, filters functions. | |
| Analizada | Alta (7.6) | 0.43% | — | Lemeconsultoria Galera | 7/5/2025 | 17/6/2026 | Cross-Site Scripting vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via multiple components, including Strategic Planning Perspective Registration, Training Request, Perspective Editing, Education Registration, Hierarchical Level Registration, Decision Level… | |
| Aplazada | Alta (7.1) | 0.31% | — | Cynob IT Consultancy THE Logo SliderAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cynob IT Consultancy The Logo Slider the-logo-slider allows Reflected XSS.This issue affects The Logo Slider: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.14% | — | Cynob IT Consultancy WP Custom Post RSS FeedAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cynob IT Consultancy WP Custom Post RSS Feed wp-custom-post-rss-feed allows Stored XSS.This issue affects WP Custom Post RSS Feed: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.1) | 0.18% | — | WebcamconsultAI | 18/1/2025 | 17/6/2026 | The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged… | |
| Aplazada | Media (6.5) | 0.37% | — | Willowsconsulting Gdpr Personal Data ReportsAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willowsconsulting GDPR Personal Data Reports gdpr-personal-data-reports allows Stored XSS.This issue affects GDPR Personal Data Reports: from n/a through <= 1.0.5. | |
| Modificada | Media (6.1) | 0.42% | — | Hashicorp Consul | 30/10/2024 | 17/6/2026 | A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS. | |
| Modificada | Media (5.8) | 0.47% | — | Hashicorp Consul | 30/10/2024 | 17/6/2026 | A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules. | |
| Modificada | Media (5.8) | 0.77% | — | Hashicorp Consul | 30/10/2024 | 17/6/2026 | A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules. | |
| Modificada | Alta (8.8) | 0.53% | — | Stylemixthemes Consulting Elementor WidgetsStylemixthemes Masterstudy Elementor Widgets | 9/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Masterstudy Elementor Widgets, StylemixThemes Consulting Elementor Widgets.This issue affects Masterstudy Elementor Widgets: from n/a through 1.2.2; Consulting Elementor Widgets: from n/a through 1.3.0. | |
| Aplazada | Media (6.1) | 0.24% | — | Magarsus Consultancy SSOAI | 26/6/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields. This issue affects SSO (Single Sign On): from 1.0 before 1.1. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Magarsus Consultancy SSOAI | 26/6/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive Information to an Unauthorized Actor, CWE - 522 - Insufficiently Protected Credentials vulnerability in Magarsus Consultancy SSO (Single Sign On) allows SQL Injection. This issue affects SSO (Single… | |
| Modificada | Alta (8.8) | 0.53% | — | Stylemixthemes Consulting Elementor Widgets | 24/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PHP Local File Inclusion.This issue affects Consulting Elementor Widgets: from n/a through 1.3.0. | |
| Modificada | Alta (8.8) | 1.2% | — | Stylemixthemes Consulting Elementor Widgets | 24/6/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, StylemixThemes Masterstudy Elementor Widgets allows OS Command Injection.This issue affects Consulting Elementor Widgets: from n/a through 1.3.0; Masterstudy Elementor… | |
| Modificada | Crítica (9.8) | 0.61% | — | Stylemixthemes Consulting Elementor Widgets | 24/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PHP Local File Inclusion.This issue affects Consulting Elementor Widgets: from n/a through 1.3.0. | |
| Aplazada | Alta (7.3) | 0.50% | — | Stylemixthemes ConsultingAI | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through 6.5.6. | |
| Analizada | Media (4.3) | 0.33% | — | Bdtask G-prescription Gynaecology & OBS Consultation | 8/3/2024 | 17/6/2026 | A vulnerability was found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /Setting/change_password_save of the component Password Reset Handler. The manipulation leads to cross-site request forgery. The… | |
| Analizada | Media (6.1) | 0.49% | — | Bdtask G-prescription Gynaecology & OBS Consultation | 8/3/2024 | 17/6/2026 | A vulnerability has been found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /Venue_controller/edit_venue/ of the component Edit Venue Page. The manipulation of the argument Venue map leads to… | |
| Analizada | Media (6.1) | 0.45% | — | Bdtask G-prescription Gynaecology & OBS Consultation | 8/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0. Affected is an unknown function of the component OBS Patient/Gynee Prescription. The manipulation of the argument Patient Title/Full Name/Address/Cheif Complain/LMP/Menstrual Edd/OBS… | |
| Analizada | Media (6.1) | 0.49% | — | Bdtask G-prescription Gynaecology & OBS Consultation | 8/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0. This issue affects some unknown processing of the file /Home/Index of the component Prescription Dashboard. The manipulation of the argument Title leads to cross site scripting.… | |
| Analizada | Alta (8.8) | 0.28% | — | Mandsconsulting Email Before Download | 29/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before Download: from n/a through 6.9.7. | |
| Modificada | Alta (7.5) | 0.56% | — | Dallmann-consulting Open Charge Point Protocol | 7/12/2023 | 17/6/2026 | An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. The server processes mishandle StartTransaction messages containing additional, arbitrary properties, or duplicate properties. The last occurrence of a duplicate property is accepted. This could be… | |
| Modificada | Alta (7.5) | 0.53% | — | Dallmann-consulting Open Charge Point Protocol | 7/12/2023 | 17/6/2026 | An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. It permits multiple transactions with the same connectorId and idTag, contrary to the expected ConcurrentTx status. This could result in critical transaction management and billing errors. NOTE: the… | |
| Modificada | Alta (7.5) | 0.71% | — | Dallmann-consulting Open Charge Point Protocol | 7/12/2023 | 17/6/2026 | An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. A StopTransaction message with any random transactionId terminates active transactions. | |
| Modificada | Alta (7.5) | 0.71% | — | Dallmann-consulting Open Charge Point Protocol | 7/12/2023 | 17/6/2026 | An issue was discovered in Dalmann OCPP.Core before 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. It does not validate the length of the chargePointVendor field in a BootNotification message, potentially leading to server instability and a denial of service when processing excessively large… |