Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

178 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)9.3%💥 ExploitModx Revolution26/2/202217/6/2026
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaMedia (6.1)0.80%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe14/2/202217/6/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
ModificadaMedia (6.1)0.81%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe24/1/202217/6/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
ModificadaCrítica (9.1)2.4%—Modx Revolution31/10/202117/6/2026
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
ModificadaAlta (8.8)1.7%—Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+3911/10/202117/6/2026
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the…
ModificadaCrítica (9.3)0.84%—Jscom Revoworks Browser17/9/202117/6/2026
Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restriction and to exchange unauthorized files between the local environment and the isolated environment or settings of the web browser via unspecified vectors.
ModificadaCrítica (9.6)1.3%—Jscom Revoworks Browser17/9/202117/6/2026
Improper control of program execution vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to execute an arbitrary command or code via unspecified vectors.
ModificadaCrítica (9.8)1.5%—Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+10814/12/202017/6/2026
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
ModificadaCrítica (9.8)1.1%—Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+10814/12/202017/6/2026
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
ModificadaCrítica (9.6)1.2%—Freebox Revolution FirmwareFreebox Mini FirmwareFreebox ONE FirmwareFreebox Delta Firmware+116/9/202017/6/2026
A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.
ModificadaCrítica (9.6)1.00%—Freebox Revolution FirmwareFreebox Mini FirmwareFreebox ONE FirmwareFreebox Delta Firmware+116/9/202017/6/2026
A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3.
ModificadaAlta (8.8)0.53%—Freebox Revolution FirmwareFreebox Mini FirmwareFreebox ONE FirmwareFreebox Delta Firmware+116/9/202017/6/2026
A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
ModificadaMedia (6.7)0.46%—HP Elite X2 1012 G1 FirmwareHP Elite X2 1012 G2 FirmwareHP Elitebook 1030 G1 FirmwareHP Elitebook 1040 G4 Firmware+1012/8/202017/6/2026
The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.
ModificadaMedia (6.1)0.78%—F-revocrm27/1/202017/6/2026
Cross-site scripting vulnerability in F-RevoCRM 6.0 to F-RevoCRM 6.5 patch6 (version 6 series) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.2%—Trustedsec Trevorc24/12/201917/6/2026
TrevorC2 v1.1/v1.2 fails to prevent fingerprinting primarily via a discrepancy between response headers when responding to different HTTP methods, also via predictible responses when accessing and interacting with the "SITE_PATH_QUERY".
ModificadaAlta (7.2)2.0%—HP 260 G1 DM FirmwareHP 280 PRO G1 FirmwareHP 285 G2 FirmwareHP 340 G3 Firmware+985/11/201917/6/2026
A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management…
ModificadaAlta (7.5)1.2%—Modx Revolution23/7/201917/6/2026
MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and content. The component is: Filtering user parameters before passing them into phpthumb class. The attack vector is: web request via…
ModificadaMedia (5.4)0.61%—Modx Revolution6/2/201917/6/2026
MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.
ModificadaMedia (6.1)0.86%—Modx Revolution6/2/201917/6/2026
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.
ModificadaMedia (6.1)0.86%—Modx Revolution6/2/201917/6/2026
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
ModificadaMedia (6.1)0.86%—Modx Revolution6/2/201917/6/2026
MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.
ModificadaMedia (5.4)0.59%—Modx Revolution26/9/201817/6/2026
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
ModificadaAlta (7.5)1.9%—Modx Revolution13/7/201817/6/2026
MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result in remove files. This attack appear to be exploitable via web request via security/login processor. This vulnerability appears to have been fixed in pull 13980.
ModificadaAlta (7.2)64%—Modx Revolution13/7/201817/6/2026
MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content. This attack appear to be exploitable via Web request. This vulnerability appears to have been fixed…