Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

88 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.96%—Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV12/8/201917/6/2026
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
ModificadaMedia (5.4)0.68%—Typesettercms Typesetter13/5/201917/6/2026
Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.
ModificadaMedia (4.8)0.67%—Typesettercms Typesetter13/5/201917/6/2026
index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.
ModificadaMedia (4.8)0.67%—Typesettercms Typesetter13/5/201917/6/2026
index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
ModificadaMedia (4.8)0.73%—Typesettercms Typesetter9/5/201917/6/2026
include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.
ModificadaAlta (8.8)6.7%💥 ExploitTypesettercms Typesetter12/2/201817/6/2026
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.
ModificadaAlta (8)1.9%💥 ExploitTypesettercms Typesetter12/2/201817/6/2026
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token.
ModificadaMedia (4.3)2.0%—WP Easy Post Types Project WP Easy Post Types2/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in classes/custom-image/media.php in the WP Easy Post Types plugin before 1.4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ref parameter.
ModificadaMedia (5)1.5%—Typespeed4/12/200716/6/2026
typespeed before 0.6.4 allows remote attackers to cause a denial of service (application crash) via unspecified network behavior that triggers a divide-by-zero error.
ModificadaAlta (7.5)3.6%—Typespeed31/5/200616/6/2026
Buffer overflow in the addnewword function in typespeed 0.4.4 and earlier might allow remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (4.6)0.71%💥 ExploitTypespeed16/2/200516/6/2026
Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.
ModificadaAlta (7.5)2.7%—Typespeed24/7/200316/6/2026
Buffer overflow in net_swapscore for typespeed 0.4.1 and earlier allows remote attackers to execute arbitrary code.
ModificadaMedia (4.6)0.38%—Typespeed2/1/200316/6/2026
Buffer overflow in typespeed 0.4.2 and earlier allows local users to gain privileges via long input.
Orbitaley — Vulnerabilidades