Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.44%—Squareup OkhttpRedhat A-mq Streams27/9/202323/6/2026
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions.
ModificadaMedia (5.9)0.72%—Squareup Okhttp-brotli19/7/202317/6/2026
DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response
ModificadaAlta (7.5)1.3%💥 PoCSquareup Okio12/7/202317/6/2026
GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
ModificadaAlta (7.5)0.64%—Virtualsquare Picotcp19/6/202317/6/2026
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not properly check whether header sizes would result in accessing data outside of a packet.
ModificadaAlta (7.5)0.70%—Virtualsquare Picotcp19/6/202317/6/2026
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 lacks certain size calculations before attempting to set a value of an mss structure member.
ModificadaAlta (7.5)0.70%—Virtualsquare Picotcp19/6/202317/6/2026
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not have an MSS lower bound (e.g., it could be zero).
ModificadaAlta (7.5)0.70%—Virtualsquare Picotcp19/6/202317/6/2026
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not check the transport layer length in a frame before performing port filtering.
ModificadaMedia (6.5)0.42%—Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe3/6/202317/6/2026
The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function. This makes it possible…
ModificadaMedia (5.4)0.76%—Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe3/6/202317/6/2026
The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 1.3.1 due to insufficient input sanitization…
ModificadaMedia (6.1)2.2%💥 ExploitSquarepiginteractive Fusioninvoice25/5/202317/6/2026
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details.
ModificadaMedia (4.8)0.37%—GMO Typesquare Webfonts FOR Conoha4/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GMO Internet Group, Inc. TypeSquare Webfonts for ConoHa plugin <= 2.0.3 versions.
ModificadaMedia (4.8)0.39%—Catchsquare WP Smart Preloader30/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catchsquare WP Smart Preloader plugin <= 1.15 versions.
ModificadaMedia (6.1)0.40%—Squaredup Dashboard Server23/2/202317/6/2026
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2).
ModificadaMedia (6.1)0.37%—Squaredup Dashboard Server23/2/202317/6/2026
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.)
ModificadaMedia (5.4)0.39%—Squaredup Dashboard Server23/2/202317/6/2026
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 2 of 2).
ModificadaMedia (5.4)0.53%—Catchsquare WP Social Widget30/1/202317/6/2026
The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaCrítica (9.8)2.1%💥 PoCAidreform Project AidreformChimpgroup BolsterChimpgroup SpikesChimpgroup Westand+623/1/202317/6/2026
The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill…
AnalizadaCrítica (9.8)0.69%—Squareup Squalor7/1/202317/6/2026
A vulnerability, which was classified as critical, was found in square squalor. This affects an unknown part. The manipulation leads to sql injection. Upgrading to version v0.0.0 is able to address this issue. The patch is named f6f0a47cc344711042eb0970cb423e6950ba3f93. It is recommended to upgrade the affected…
ModificadaCrítica (9.1)36%💥 ExploitTelesquare Tlr-2005ksh Firmware27/4/202217/6/2026
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.
ModificadaMedia (5.3)1.6%—Telesquare Tlr-2005ksh Firmware27/4/202217/6/2026
Telesquare TLR-2005KSH 1.0.0 is affected by an unauthenticated file download vulnerability that allows a remote attacker to download a full configuration file.
ModificadaCrítica (9.8)94%💥 ExploitTelesquare Sdt-cs3b1 Firmware27/4/202217/6/2026
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.
ModificadaCrítica (9.1)71%💥 ExploitTelesquare Tlr-2855ks6 Firmware7/4/202217/6/2026
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.
ModificadaAlta (7.5)24%💥 ExploitTelesquare Tlr-2855ks6 Firmware7/4/202217/6/2026
An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
ModificadaCrítica (9.8)57%💥 ExploitTelesquare Tlr-2005ksh Firmware3/1/202217/6/2026
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.
ModificadaMedia (5.4)0.80%—Squaredup7/12/202117/6/2026
A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modification of the authorisationUrl in some integration configurations.