Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.96% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 12/8/2019 | 17/6/2026 | The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS. | |
| Modificada | Media (5.4) | 0.68% | — | Typesettercms Typesetter | 13/5/2019 | 17/6/2026 | Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation. | |
| Modificada | Media (4.8) | 0.67% | — | Typesettercms Typesetter | 13/5/2019 | 17/6/2026 | index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name. | |
| Modificada | Media (4.8) | 0.67% | — | Typesettercms Typesetter | 13/5/2019 | 17/6/2026 | index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. | |
| Modificada | Media (4.8) | 0.73% | — | Typesettercms Typesetter | 9/5/2019 | 17/6/2026 | include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS. | |
| Modificada | Alta (8.8) | 6.7% | 💥 Exploit | Typesettercms Typesetter | 12/2/2018 | 17/6/2026 | An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction. | |
| Modificada | Alta (8) | 1.9% | 💥 Exploit | Typesettercms Typesetter | 12/2/2018 | 17/6/2026 | An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token. | |
| Modificada | Media (4.3) | 2.0% | — | WP Easy Post Types Project WP Easy Post Types | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in classes/custom-image/media.php in the WP Easy Post Types plugin before 1.4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ref parameter. | |
| Modificada | Media (5) | 1.5% | — | Typespeed | 4/12/2007 | 16/6/2026 | typespeed before 0.6.4 allows remote attackers to cause a denial of service (application crash) via unspecified network behavior that triggers a divide-by-zero error. | |
| Modificada | Alta (7.5) | 3.6% | — | Typespeed | 31/5/2006 | 16/6/2026 | Buffer overflow in the addnewword function in typespeed 0.4.4 and earlier might allow remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Media (4.6) | 0.71% | 💥 Exploit | Typespeed | 16/2/2005 | 16/6/2026 | Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges. | |
| Modificada | Alta (7.5) | 2.7% | — | Typespeed | 24/7/2003 | 16/6/2026 | Buffer overflow in net_swapscore for typespeed 0.4.1 and earlier allows remote attackers to execute arbitrary code. | |
| Modificada | Media (4.6) | 0.38% | — | Typespeed | 2/1/2003 | 16/6/2026 | Buffer overflow in typespeed 0.4.2 and earlier allows local users to gain privileges via long input. |