Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)0.40%—Absolute Secure Access20/6/202417/6/2026
There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can impair the availability of certain elements of the Secure Access administrative UI by writing invalid data to the warehouse over the network.…
ModificadaMedia (5.4)0.22%—Absolute Secure Access20/6/202417/6/2026
There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to version 13.06. Attackers can pass a limited-length script to the administrative UI which is then stored where an administrator can access it. The scope is unchanged, there is no loss of…
ModificadaBaja (3.4)0.27%—Absolute Secure Access20/6/202417/6/2026
There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with another system administrator’s use of the policy management UI when the administrators are editing the same policy object. The…
ModificadaMedia (5.4)0.22%—Absolute Secure Access20/6/202417/6/2026
There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.06. Attackers with valid tunnel credentials can pass a limited-length script to the administrative console which is then temporarily stored where an administrator using a non-default…
AplazadaMedia (4.4)0.29%—Cusmin Absolutely Glamorous Custom AdminAI29/4/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Cusmin Absolutely Glamorous Custom Admin.This issue affects Absolutely Glamorous Custom Admin: from n/a through 7.2.2.
AnalizadaMedia (6.8)0.55%—Cusmin Absolutely Glamorous Custom Admin25/4/202417/6/2026
The AGCA WordPress plugin before 7.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaAlta (8.8)0.33%—Johnkolbert Absolute Privacy10/8/202317/6/2026
The Absolute Privacy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing nonce validation on the 'abpr_profileShortcode' function. This makes it possible for unauthenticated attackers to change user email and password via a forged request…
ModificadaMedia (4.3)0.56%—Codesupply Absolute Reviews12/7/202317/6/2026
The Absolute Reviews plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.8. This is due to missing or incorrect nonce validation on the metabox_review_save() function. This makes it possible for unauthenticated attackers to save meta tags via a forged request granted…
ModificadaCrítica (9.8)0.80%—Erikogluteknoloji Energy Monitoring2/6/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Erikoglu Technology ErMon allows Command Line Execution through SQL Injection, Authentication Bypass. This issue affects ErMon: before 230602.
ModificadaMedia (4.8)0.60%—Cusmin Absolutely Glamorous Custom Admin1/2/202217/6/2026
The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (8.2)0.74%—Cusmin Absolutely Glamorous Custom Admin23/9/202117/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolutely Glamorous Custom Admin (WordPress plugin): from n/a through 6.8.
ModificadaCrítica (9.8)1.5%—Lute-tab Project Lute-tab29/8/201917/6/2026
Lute-Tab before 2019-08-23 has a buffer overflow in pdf_print.cc.
ModificadaAlta (8.8)0.86%—Absolute Ctes Windows Agent8/9/201817/6/2026
An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479. The security permissions on the %ProgramData%\CTES folder and sub-folders may allow write access to low-privileged user accounts. This allows unauthorized replacement of service program executable (EXE) or dynamically loadable library…
ModificadaMedia (4.1)0.21%—Absolute Computrace Agent11/5/201816/6/2026
Absolute Computrace Agent, as distributed on certain Dell Inspiron systems through 2009, has a race condition with the Dell Client Configuration Utility (DCCU), which allows privileged local users to change Computrace Agent's activation/deactivation status to the factory default via a crafted TaskResult.xml file.
ModificadaMedia (6.7)0.49%—Absolute Computrace Agent11/5/201816/6/2026
The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for that code, which allows attackers to execute code on the BIOS. This allows a privileged local user to achieve persistent control of BIOS behavior, independent of later…
ModificadaMedia (6.7)0.54%—Absolute Computrace Agent11/5/201816/6/2026
Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's inter-partition space. This allows a privileged local user to…
ModificadaMedia (6.5)1.1%💥 ExploitAbsolutengine Absolut Engine2/1/201517/6/2026
Multiple SQL injection vulnerabilities in Absolut Engine 1.73 allow remote authenticated users to execute arbitrary SQL commands via the (1) sectionID parameter to admin/managersection.php, (2) userID parameter to admin/edituser.php, (3) username parameter to admin/admin.php, or (4) title parameter to…
ModificadaBaja (3.5)1.6%💥 ExploitAbsolutengine Absolut Engine2/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in admin/managerrelated.php in the administrative backend in Absolut Engine 1.73 allows remote authenticated users to inject arbitrary web script or HTML via the title parameter.
ModificadaMedia (5.4)0.27%—Mibizapps Absolute Lending Solutions11/10/201417/6/2026
The Absolute Lending Solutions (aka com.soln.S008F6C05EC0B63264B429F6D76286562) application 1.0073.b0073 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (9.3)29%💥 ExploitVandyke Absoluteftp15/9/201216/6/2026
Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response.
ModificadaAlta (9.3)3.1%—Investintech Absolute PDF Server1/11/201116/6/2026
Unspecified vulnerability in Investintech.com Absolute PDF Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
ModificadaMedia (6.5)0.88%💥 ExploitAbsoluteanime Prime Quick Style3/9/200916/6/2026
SQL injection vulnerability in root/includes/prime_quick_style.php in the Prime Quick Style addon before 1.2.3 for phpBB 3 allows remote authenticated users to execute arbitrary SQL commands via the prime_quick_style parameter to ucp.php.
ModificadaAlta (7.5)2.5%💥 ExploitXigla Absolute Live Support .net14/7/200916/6/2026
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
ModificadaAlta (7.5)2.5%💥 ExploitXigla Absolute Form Processor.net14/7/200916/6/2026
Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
ModificadaAlta (7.5)2.5%💥 ExploitXigla Absolute Content Rotator14/7/200916/6/2026
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
Orbitaley — Vulnerabilidades