Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.40% | — | Absolute Secure Access | 20/6/2024 | 17/6/2026 | There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can impair the availability of certain elements of the Secure Access administrative UI by writing invalid data to the warehouse over the network.… | |
| Modificada | Media (5.4) | 0.22% | — | Absolute Secure Access | 20/6/2024 | 17/6/2026 | There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to version 13.06. Attackers can pass a limited-length script to the administrative UI which is then stored where an administrator can access it. The scope is unchanged, there is no loss of… | |
| Modificada | Baja (3.4) | 0.27% | — | Absolute Secure Access | 20/6/2024 | 17/6/2026 | There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with another system administrator’s use of the policy management UI when the administrators are editing the same policy object. The… | |
| Modificada | Media (5.4) | 0.22% | — | Absolute Secure Access | 20/6/2024 | 17/6/2026 | There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.06. Attackers with valid tunnel credentials can pass a limited-length script to the administrative console which is then temporarily stored where an administrator using a non-default… | |
| Aplazada | Media (4.4) | 0.29% | — | Cusmin Absolutely Glamorous Custom AdminAI | 29/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Cusmin Absolutely Glamorous Custom Admin.This issue affects Absolutely Glamorous Custom Admin: from n/a through 7.2.2. | |
| Analizada | Media (6.8) | 0.55% | — | Cusmin Absolutely Glamorous Custom Admin | 25/4/2024 | 17/6/2026 | The AGCA WordPress plugin before 7.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Alta (8.8) | 0.33% | — | Johnkolbert Absolute Privacy | 10/8/2023 | 17/6/2026 | The Absolute Privacy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing nonce validation on the 'abpr_profileShortcode' function. This makes it possible for unauthenticated attackers to change user email and password via a forged request… | |
| Modificada | Media (4.3) | 0.56% | — | Codesupply Absolute Reviews | 12/7/2023 | 17/6/2026 | The Absolute Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.8. This is due to missing or incorrect nonce validation on the metabox_review_save() function. This makes it possible for unauthenticated attackers to save meta tags via a forged request granted… | |
| Modificada | Crítica (9.8) | 0.80% | — | Erikogluteknoloji Energy Monitoring | 2/6/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Erikoglu Technology ErMon allows Command Line Execution through SQL Injection, Authentication Bypass. This issue affects ErMon: before 230602. | |
| Modificada | Media (4.8) | 0.60% | — | Cusmin Absolutely Glamorous Custom Admin | 1/2/2022 | 17/6/2026 | The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8.2) | 0.74% | — | Cusmin Absolutely Glamorous Custom Admin | 23/9/2021 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPress plugin): from n/a through 6.8. | |
| Modificada | Crítica (9.8) | 1.5% | — | Lute-tab Project Lute-tab | 29/8/2019 | 17/6/2026 | Lute-Tab before 2019-08-23 has a buffer overflow in pdf_print.cc. | |
| Modificada | Alta (8.8) | 0.86% | — | Absolute Ctes Windows Agent | 8/9/2018 | 17/6/2026 | An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479. The security permissions on the %ProgramData%\CTES folder and sub-folders may allow write access to low-privileged user accounts. This allows unauthorized replacement of service program executable (EXE) or dynamically loadable library… | |
| Modificada | Media (4.1) | 0.21% | — | Absolute Computrace Agent | 11/5/2018 | 16/6/2026 | Absolute Computrace Agent, as distributed on certain Dell Inspiron systems through 2009, has a race condition with the Dell Client Configuration Utility (DCCU), which allows privileged local users to change Computrace Agent's activation/deactivation status to the factory default via a crafted TaskResult.xml file. | |
| Modificada | Media (6.7) | 0.49% | — | Absolute Computrace Agent | 11/5/2018 | 16/6/2026 | The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for that code, which allows attackers to execute code on the BIOS. This allows a privileged local user to achieve persistent control of BIOS behavior, independent of later… | |
| Modificada | Media (6.7) | 0.54% | — | Absolute Computrace Agent | 11/5/2018 | 16/6/2026 | Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's inter-partition space. This allows a privileged local user to… | |
| Modificada | Media (6.5) | 1.1% | 💥 Exploit | Absolutengine Absolut Engine | 2/1/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in Absolut Engine 1.73 allow remote authenticated users to execute arbitrary SQL commands via the (1) sectionID parameter to admin/managersection.php, (2) userID parameter to admin/edituser.php, (3) username parameter to admin/admin.php, or (4) title parameter to… | |
| Modificada | Baja (3.5) | 1.6% | 💥 Exploit | Absolutengine Absolut Engine | 2/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in admin/managerrelated.php in the administrative backend in Absolut Engine 1.73 allows remote authenticated users to inject arbitrary web script or HTML via the title parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Mibizapps Absolute Lending Solutions | 11/10/2014 | 17/6/2026 | The Absolute Lending Solutions (aka com.soln.S008F6C05EC0B63264B429F6D76286562) application 1.0073.b0073 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 29% | 💥 Exploit | Vandyke Absoluteftp | 15/9/2012 | 16/6/2026 | Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response. | |
| Modificada | Alta (9.3) | 3.1% | — | Investintech Absolute PDF Server | 1/11/2011 | 16/6/2026 | Unspecified vulnerability in Investintech.com Absolute PDF Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |
| Modificada | Media (6.5) | 0.88% | 💥 Exploit | Absoluteanime Prime Quick Style | 3/9/2009 | 16/6/2026 | SQL injection vulnerability in root/includes/prime_quick_style.php in the Prime Quick Style addon before 1.2.3 for phpBB 3 allows remote authenticated users to execute arbitrary SQL commands via the prime_quick_style parameter to ucp.php. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Xigla Absolute Live Support .net | 14/7/2009 | 16/6/2026 | Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Xigla Absolute Form Processor.net | 14/7/2009 | 16/6/2026 | Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Xigla Absolute Content Rotator | 14/7/2009 | 16/6/2026 | Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. |