Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.42% | — | Phpgurukul Teacher Subject Allocation Management System | 14/11/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) en profile.php en phpgurukul Teacher Subject Allocation Management System 1.0 permite a atacantes ejecutar código arbitrario a través de los parámetros 'adminname' y 'email'. | |
| Modificada | Media (4.9) | 0.65% | — | Phpgurukul Teacher Subject Allocation Management System | 14/11/2023 | 17/6/2026 | Vulnerabilidad de inyección SQL en teacher-info.php en phpgurukul Teacher Subject Allocation Management System 1.0 permite a atacantes obtener información confidencial a través del parámetro 'editid'. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Phpgurukul Teacher Subject Allocation Management System | 14/11/2023 | 17/6/2026 | Vulnerabilidad de inyección SQL en index.php en phpgurukul Teacher Subject Allocation Management System 1.0 permite a atacantes ejecutar comandos SQL arbitrarios y obtener información confidencial a través del parámetro 'searchdata'. | |
| Modificada | Alta (8.8) | 0.26% | — | Themelocation Remove ADD TO Cart Woocommerce | 13/11/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Request Forgery (CSRF) en la ubicación del tema en el complemento Remove Add to Cart WooCommerce en versiones <= 1.4.4. | |
| Modificada | Media (5.4) | 0.31% | — | User Location AND IP Project User Location AND IP | 18/10/2023 | 17/6/2026 | Vulnerabilidad de Coss-Site Scripting (XSS) autenticada (con permisos de colaboradores o superiores) almacenada en el complemento MyTechTalky User Location and IP en versiones <= 1.6. | |
| Modificada | Media (5.4) | 0.39% | — | Goldplugins Locations | 2/10/2023 | 17/6/2026 | Vulnerabilidad de Coss-Site Scripting (XSS) autenticada (con permisos de colaboradores o superiores) almacenada en el complemento Gold Plugins Locations en versiones <= 4.0. | |
| Modificada | Media (4.8) | 0.44% | — | Auto Location FOR WP JOB Manager VIA Google Project Auto Location FOR WP JOB Manager VIA Google | 24/7/2023 | 17/6/2026 | The Auto Location for WP Job Manager via Google WordPress plugin before 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.8) | 0.21% | — | Keysight Geolocation Server | 19/7/2023 | 17/6/2026 | In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges. | |
| Modificada | Alta (7.8) | 0.24% | — | Keysight Geolocation Server | 19/7/2023 | 17/6/2026 | In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service condition. | |
| Modificada | Media (6.1) | 0.35% | — | Phpgurukul Teacher Subject Allocation System | 13/7/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Teacher Subject Allocation System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search text box. | |
| Modificada | Media (4.3) | 0.46% | — | Goldplugins Locations | 1/7/2023 | 17/6/2026 | The Locations plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to update custom field meta data via a forged request… | |
| Modificada | Media (5.4) | 0.36% | — | Theguidex User IP AND Location | 18/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TheGuideX User IP and Location plugin <= 2.2 versions. | |
| Analizada | Alta (7.5) | 64% | ⚠ Explotación activa | Netapp Smi-s ProviderSuse Manager ServerSuse Linux Enterprise ServerVmware Esxi+1 | 25/4/2023 | 17/6/2026 | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor. | |
| Modificada | Crítica (9.8) | 0.61% | — | Simple Task Allocation System Project Simple Task Allocation System | 2/4/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Simple Task Allocation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.64% | — | Simple Task Allocation System Project Simple Task Allocation System | 1/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Task Allocation System 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Modificada | Media (6.1) | 0.36% | — | Task Allocation System Project Task Allocation System | 29/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Simple Task Allocation System 1.0. Affected is an unknown function of the file LoginRegistration.php?a=register_user. The manipulation of the argument Fullname leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Modificada | Media (5.4) | 0.47% | — | Themelocation Widgets FOR Woocommerce Products ON Elementor | 13/3/2023 | 17/6/2026 | The Widgets for WooCommerce Products on Elementor WordPress plugin before 1.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting… | |
| Modificada | Media (5.4) | 0.54% | — | Shapedplugin Location Weather | 13/2/2023 | 17/6/2026 | El complemento Location Weather de WordPress anterior a 1.3.4 no valida ni escapa algunas de sus opciones de bloqueo antes de devolverlas a una página/publicación donde está incrustado el bloque, lo que podría permitir a los usuarios con el rol de colaborador y superior realizar un cross-site scripting almacenado. | |
| Modificada | Media (6.5) | 0.68% | — | Sewio Real-time Location System Studio | 18/1/2023 | 17/6/2026 | El sistema de ubicación en tiempo real (RTLS) Studio de Sewio, versión 2.0.0 hasta la versión 2.6.2 inclusive, es vulnerable a una validación de entrada incorrecta de la entrada del usuario en varios módulos y servicios del software. Esto podría permitir a un atacante eliminar archivos arbitrarios y provocar una… | |
| Modificada | Alta (7.2) | 1.2% | — | Sewio Real-time Location System Studio | 18/1/2023 | 17/6/2026 | El sistema de ubicación en tiempo real (RTLS) Studio de Sewio, versión 2.0.0 hasta la versión 2.6.2 inclusive, no valida correctamente el nombre del módulo de entrada para los servicios de respaldo del software. Esto podría permitir que un atacante remoto acceda a funciones confidenciales de la aplicación y ejecute… | |
| Modificada | Alta (8.1) | 0.33% | — | Sewio Real-time Location System Studio | 18/1/2023 | 17/6/2026 | El sistema de ubicación en tiempo real (RTLS) Studio de Sewio, versión 2.0.0 hasta la versión 2.6.2 incluida, es vulnerable a la Cross Site Request Forgery en sus servicios de monitorización. Un atacante podría aprovechar esta vulnerabilidad para ejecutar operaciones de mantenimiento arbitrarias y provocar una… | |
| Modificada | Crítica (9.6) | 0.57% | — | Sewio Real-time Location System Studio | 18/1/2023 | 17/6/2026 | El sistema de ubicación en tiempo real (RTLS) Studio de Sewio, versión 2.0.0 hasta la versión 2.6.2 incluida, es vulnerable a cross site scripting en sus servicios de respaldo. Un atacante podría aprovechar esta vulnerabilidad para ejecutar comandos arbitrarios. | |
| Modificada | Crítica (9.8) | 0.94% | — | Sewio Real-time Location System Studio | 18/1/2023 | 17/6/2026 | El sistema de ubicación en tiempo real (RTLS) de Sewio, versión 2.0.0 hasta la versión 2.6.2 incluida, contiene contraseñas codificadas para usuarios seleccionados en la base de datos de la aplicación. Esto podría permitir que un atacante remoto inicie sesión en la base de datos con acceso sin restricciones. | |
| Modificada | Alta (8.1) | 0.33% | — | Sewio Real-time Location System Studio | 18/1/2023 | 17/6/2026 | Real-Time Location System (RTLS) Studio de Sewio, versión 2.0.0 hasta la versión 2.6.2 incluida, es vulnerable a la Cross Site Request Forgery en sus servicios de respaldo. Un atacante podría aprovechar esta vulnerabilidad para ejecutar operaciones de copia de seguridad arbitrarias y provocar una condición de… | |
| Modificada | Alta (7.2) | 1.2% | — | Sewio Real-time Location System Studio | 18/1/2023 | 17/6/2026 | Real-Time Location System (RTLS) Studio de Sewio, versión 2.0.0 hasta la versión 2.6.2 incluida, no valida correctamente el nombre del módulo de entrada para los servicios de monitorización del software. Esto podría permitir que un atacante remoto acceda a funciones confidenciales de la aplicación y ejecute comandos… |