Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.26% | — | Antonzaroutski AZ Content FinderAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in antonzaroutski AZ Content Finder az-content-finder allows Reflected XSS.This issue affects AZ Content Finder: from n/a through <= 0.1. | |
| Aplazada | Alta (7.1) | 0.20% | — | Kathleen Malone Find Your RepsAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kathleen Malone Find Your Reps find-your-reps allows Stored XSS.This issue affects Find Your Reps: from n/a through <= 1.2. | |
| Aplazada | Media (5.3) | 0.35% | — | Cyberlord92 Broken Link FinderAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Cyberlord92 Broken Link Checker | Finder broken-link-finder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broken Link Checker | Finder: from n/a through <= 2.4.2. | |
| Aplazada | Media (5.4) | 0.34% | — | Broken Link Checker FinderAI | 19/12/2024 | 17/6/2026 | The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the 'moblc_check_link' function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations… | |
| Aplazada | Alta (7.5) | 0.76% | — | JsfinderAI | 5/12/2024 | 17/6/2026 | JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function. | |
| Aplazada | Media (6.5) | 0.29% | — | Socialevolution WP Find Your NearestAI | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SocialEvolution WP Find Your Nearest wp-find-your-nearest allows Stored XSS.This issue affects WP Find Your Nearest: from n/a through <= 0.3.1. | |
| Aplazada | Alta (7.1) | 0.29% | — | DoofinderAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Doofinder Doofinder doofinder allows Reflected XSS.This issue affects Doofinder: from n/a through <= 0.5.4. | |
| Analizada | Media (6.1) | 0.27% | — | Std42 Elfinder | 31/10/2024 | 17/6/2026 | Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability. | |
| Analizada | Crítica (9.8) | 0.79% | — | Std42 Elfinder | 31/10/2024 | 17/6/2026 | Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension. | |
| Analizada | Media (6.1) | 0.44% | — | Phpgurukul Ifsc Code Finder | 29/10/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in PHPGurukul IFSC Code Finder Project v1.0, which allows remote attackers to execute arbitrary code via " searchifsccode" parameter. | |
| Analizada | Media (6.1) | 0.44% | — | Phpgurukul Ifsc Code Finder | 29/10/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/index.php in PHPGurukul IFSC Code Finder Project v1.0, which allows remote attackers to execute arbitrary code via the "searchifsccode" parameter. | |
| Analizada | Media (5.3) | 0.41% | — | Phpgurukul Ifsc Code Finder | 20/10/2024 | 17/6/2026 | A vulnerability has been found in PHPGurukul IFSC Code Finder Project 1.0 and classified as problematic. This vulnerability affects unknown code of the file search.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (5.3) | 0.68% | — | Find-my-wayAI | 18/9/2024 | 17/6/2026 | find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. A bad regular expression is generated any time one has two parameters within a single segment, when adding a `-` at the end, like `/:a-:b-`. This… | |
| Modificada | Media (6.1) | 0.27% | — | Superstorefinder Super Store Finder | 18/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in highwarden Super Store Finder superstorefinder-wp.This issue affects Super Store Finder: from n/a through <= 6.9.7. | |
| Modificada | Crítica (9.8) | 0.46% | — | Superstorefinder Super Store Finder | 17/9/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder superstorefinder-wp.This issue affects Super Store Finder: from n/a through < 6.9.8. | |
| Modificada | Crítica (9.8) | 0.46% | — | Superstorefinder Super Store Finder | 17/9/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder superstorefinder-wp.This issue affects Super Store Finder: from n/a through <= 6.9.7. | |
| Analizada | Media (5.4) | 0.42% | — | Pagefind | 3/9/2024 | 17/6/2026 | Pagefind, a fully static search library, initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script the user loads. This information is gathered by looking up the value of `document.currentScript.src`. Prior to Pagefind version 1.1.1, it is possible to "clobber" this lookup… | |
| Aplazada | Alta (8.3) | 0.40% | — | Codesolz Better Find AND ReplaceAI | 1/8/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1. | |
| Modificada | Crítica (9.8) | 0.48% | — | Std42 Elfinder | 30/7/2024 | 9/7/2026 | Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc. | |
| Modificada | Media (5.3) | 0.64% | — | Openfind Mail2000 | 15/7/2024 | 17/6/2026 | Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled. | |
| Modificada | Media (6.1) | 0.50% | — | Openfind Mail2000 | 15/7/2024 | 17/6/2026 | Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attachment and perform Stored Cross-site scripting attacks. | |
| Modificada | Media (6.1) | 0.45% | — | Openfind MailauditOpenfind Mailgates | 15/7/2024 | 17/6/2026 | The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS. | |
| Aplazada | Crítica (9.8) | 0.68% | — | Openfind MailgatesAIOpenfind MailauditAI | 17/6/2024 | 17/6/2026 | Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticated remote attacker can exploit this vulnerability to inject system commands and execute them on the remote server. | |
| Analizada | Alta (8.8) | 0.58% | — | Openfind Mail2000 | 27/5/2024 | 17/6/2026 | Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on the remote server. | |
| Analizada | Alta (7.2) | 0.56% | — | Openfind Mail2000 | 27/5/2024 | 17/6/2026 | Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the remote server. |