Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

132 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.52%—Jenkins Synopsys Coverity15/2/202317/6/2026
Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaBaja (3.5)0.36%—Jenkins Synopsys Coverity15/2/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaCrítica (9.8)77%💥 ExploitApsystems Ecu-r Firmware10/2/202317/6/2026
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.
ModificadaMedia (6.1)1.3%—Synopsys Coverity6/2/202317/6/2026
Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability. Any web service hosted on the same sub domain can set a cookie for the whole subdomain which can be used to bypass other mitigations in place for malicious purposes.…
ModificadaAlta (8.8)0.65%—Apsystems Ecu-c Firmware29/11/202217/6/2026
An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allows attackers to access sensitive data and execute specific commands and functions with full admin rights without authenticating allows him to perform multiple attacks, such as…
AnalizadaMedia (6.1)46%⚠ Explotación activa💥 PoCHelpsystems Cobalt Strike22/9/202217/6/2026
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new…
ModificadaMedia (4.8)0.60%—Digital Publications BY Supsystic15/8/202217/6/2026
The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (6.5)1.0%—Helpsystems Goanywhere Managed File Transfer27/7/202217/6/2026
A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain access to files at a higher directory level…
ModificadaAlta (8.8)0.98%—Supsystic Social Share Buttons22/7/202217/6/2026
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.
ModificadaAlta (8.8)0.92%—Supsystic Social Share Buttons22/7/202217/6/2026
Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.
ModificadaMedia (4.8)0.59%—Supsystic Data Tables Generator17/7/202217/6/2026
The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaCrítica (9.3)1.2%—Internshipsystem Project Internshipsystem11/7/202217/6/2026
The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaMedia (4.3)0.43%—Supsystic Social Share Buttons27/6/202217/6/2026
The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin settings, as well as create, delete and rename projects and networks.
ModificadaMedia (4.3)0.71%—Supsystic Popup20/6/202217/6/2026
A vulnerability was found in Supsystic Popup Plugin 1.7.6 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
ModificadaMedia (4.3)0.38%—Supsystic Photo Gallery15/6/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows changing the plugin settings.
ModificadaMedia (5.7)0.23%—BD Synapsys2/6/202217/6/2026
BD Synapsys™, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable…
ModificadaMedia (4.3)0.42%—Supsystic Social Share Buttons2/6/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.2 at WordPress.
ModificadaMedia (6.1)0.83%—Synopsys Black Duck HUB10/5/202217/6/2026
A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a cross-site scripting attack. The vulnerability is due to improper validation of user-supplied input to MadCap Flare's framework embedded within Black Duck Hub's Help Documentation…
ModificadaMedia (5.3)2.9%💥 ExploitSupsystic Popup9/5/202217/6/2026
The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users
ModificadaMedia (6.1)0.80%—Supsystic Price Table25/4/202217/6/2026
The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)0.80%—Supsystic Easy Google Maps25/4/202217/6/2026
The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
ModificadaMedia (5.5)0.29%—Helpsystems Titus Data Classification21/4/202217/6/2026
The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification label by using Excel's safe mode.
ModificadaAlta (7.5)1.1%—Helpsystems Cobalt Strike15/2/202217/6/2026
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL.
ModificadaMedia (4.8)0.97%—Supsystic Easy Google Maps1/11/202117/6/2026
The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attackers with administrative user access to inject arbitrary web…
ModificadaAlta (7.5)4.3%💥 PoCHelpsystems Cobalt Strike9/8/202117/6/2026
A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.
Orbitaley — Vulnerabilidades