Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 9.3% | 💥 Exploit | Modx Revolution | 26/2/2022 | 17/6/2026 | MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator. | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (6.1) | 0.80% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 14/2/2022 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Media (6.1) | 0.81% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 24/1/2022 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Crítica (9.1) | 2.4% | — | Modx Revolution | 31/10/2021 | 17/6/2026 | A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS). | |
| Modificada | Alta (8.8) | 1.7% | — | Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+39 | 11/10/2021 | 17/6/2026 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the… | |
| Modificada | Crítica (9.3) | 0.84% | — | Jscom Revoworks Browser | 17/9/2021 | 17/6/2026 | Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restriction and to exchange unauthorized files between the local environment and the isolated environment or settings of the web browser via unspecified vectors. | |
| Modificada | Crítica (9.6) | 1.3% | — | Jscom Revoworks Browser | 17/9/2021 | 17/6/2026 | Improper control of program execution vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to execute an arbitrary command or code via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.5% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Crítica (9.6) | 1.2% | — | Freebox Revolution FirmwareFreebox Mini FirmwareFreebox ONE FirmwareFreebox Delta Firmware+1 | 16/9/2020 | 17/6/2026 | A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3. | |
| Modificada | Crítica (9.6) | 1.00% | — | Freebox Revolution FirmwareFreebox Mini FirmwareFreebox ONE FirmwareFreebox Delta Firmware+1 | 16/9/2020 | 17/6/2026 | A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3. | |
| Modificada | Alta (8.8) | 0.53% | — | Freebox Revolution FirmwareFreebox Mini FirmwareFreebox ONE FirmwareFreebox Delta Firmware+1 | 16/9/2020 | 17/6/2026 | A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3. | |
| Modificada | Media (6.7) | 0.46% | — | HP Elite X2 1012 G1 FirmwareHP Elite X2 1012 G2 FirmwareHP Elitebook 1030 G1 FirmwareHP Elitebook 1040 G4 Firmware+10 | 12/8/2020 | 17/6/2026 | The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file. | |
| Modificada | Media (6.1) | 0.78% | — | F-revocrm | 27/1/2020 | 17/6/2026 | Cross-site scripting vulnerability in F-RevoCRM 6.0 to F-RevoCRM 6.5 patch6 (version 6 series) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Trustedsec Trevorc2 | 4/12/2019 | 17/6/2026 | TrevorC2 v1.1/v1.2 fails to prevent fingerprinting primarily via a discrepancy between response headers when responding to different HTTP methods, also via predictible responses when accessing and interacting with the "SITE_PATH_QUERY". | |
| Modificada | Alta (7.2) | 2.0% | — | HP 260 G1 DM FirmwareHP 280 PRO G1 FirmwareHP 285 G2 FirmwareHP 340 G3 Firmware+98 | 5/11/2019 | 17/6/2026 | A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management… | |
| Modificada | Alta (7.5) | 1.2% | — | Modx Revolution | 23/7/2019 | 17/6/2026 | MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and content. The component is: Filtering user parameters before passing them into phpthumb class. The attack vector is: web request via… | |
| Modificada | Media (5.4) | 0.61% | — | Modx Revolution | 6/2/2019 | 17/6/2026 | MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description. | |
| Modificada | Media (6.1) | 0.86% | — | Modx Revolution | 6/2/2019 | 17/6/2026 | MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name. | |
| Modificada | Media (6.1) | 0.86% | — | Modx Revolution | 6/2/2019 | 17/6/2026 | MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs. | |
| Modificada | Media (6.1) | 0.86% | — | Modx Revolution | 6/2/2019 | 17/6/2026 | MODX Revolution through v2.7.0-pl allows XSS via the User Photo field. | |
| Modificada | Media (5.4) | 0.59% | — | Modx Revolution | 26/9/2018 | 17/6/2026 | MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action. | |
| Modificada | Alta (7.5) | 1.9% | — | Modx Revolution | 13/7/2018 | 17/6/2026 | MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result in remove files. This attack appear to be exploitable via web request via security/login processor. This vulnerability appears to have been fixed in pull 13980. | |
| Modificada | Alta (7.2) | 64% | — | Modx Revolution | 13/7/2018 | 17/6/2026 | MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content. This attack appear to be exploitable via Web request. This vulnerability appears to have been fixed… |