Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

129 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.60%—Webile Wifi PC File Transfer Project Webile Wifi PC File Transfer20/7/202317/6/2026
A vulnerability was found in Webile 1.0.1. It has been classified as problematic. Affected is an unknown function of the component HTTP POST Request Handler. The manipulation of the argument new_file_name/c leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to…
AnalizadaMedia (4.8)0.39%—Saleswonder Webinarignition7/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saleswonder.Biz Webinar ignition plugin <= 2.14.2 versions.
ModificadaCrítica (9.1)1.2%—Webidsupport Webid14/10/202217/6/2026
A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across directories.
ModificadaMedia (4.3)0.45%—Stylemixthemes Eroom - Zoom Meetings & Webinar11/4/202217/6/2026
Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.8 allows cache deletion.
ModificadaMedia (4.3)0.45%—Stylemixthemes Eroom - Zoom Meetings & Webinar11/4/202217/6/2026
Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.7 allows an attacker to Sync with Zoom Meetings.
ModificadaMedia (6.5)0.74%—Vivoh Webinar Manager30/3/202217/6/2026
Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configuration web portlet, a VIVOH_AUTH cookie is assigned so that they can be uniquely identified. Certain APIs can be successfully executed without proper authentication. This can let an attacker…
ModificadaCrítica (9.1)20%💥 ExploitSubtlewebinc Formcraft321/3/202217/6/2026
The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users
ModificadaMedia (5.4)0.52%—Openwebif Project Openwebif4/8/202117/6/2026
In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7, inserting JavaScript into the Add Bouquet feature of the Bouquet Editor (i.e., bouqueteditor/api/addbouquet?name=) leads to Stored XSS.
ModificadaCrítica (9.8)1.2%—Webidsupport Webid27/1/202117/6/2026
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness of two passwords. Two non-identical passwords can still bypass the check.
ModificadaCrítica (9.8)1.5%—Webimpacto Icommktconnector26/8/201917/6/2026
The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.
ModificadaMedia (6.5)7.9%💥 ExploitWebiness Inventory Project Webiness Inventory14/5/201917/6/2026
An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the creation of a new product. Consequently, an attacker can steal information from the site with the help of an installed executable file, or change the contents of pages.
ModificadaMedia (6.1)0.83%—Webidsupport Webid29/4/201917/6/2026
WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/excludeuser.php, or the offset parameter to admin/edituser.php.
ModificadaAlta (7.5)2.2%—Openwebif Project Openwebif21/12/201817/6/2026
An issue has been discovered in the OpenWebif plugin through 1.2.4 for Enigma2 based devices. Reading of arbitrary files is possible with /file?action=download&file= followed by a full pathname, and listing of arbitrary directories is possible with /file?action=download&dir= followed by a full pathname. This is…
ModificadaAlta (7.5)2.4%—Webidsupport Webid20/12/201817/6/2026
WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image File Read. This attack appear to be exploitable via HTTP GET Request. This vulnerability appears to have been fixed in after commit 256a5f9d3eafbc477dcf77c7682446cc4b449c7f.
ModificadaMedia (6.1)1.6%—Webidsupport Webid20/12/201817/6/2026
WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javascript execution in the user's browser, injection of malicious markup into the page. This attack appear to be exploitable via The victim user must click a malicous link.…
ModificadaAlta (8.8)1.5%—Webidsupport Webid20/12/201817/6/2026
WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Blind SQL Injection. This attack appear to be exploitable via HTTP Request. This vulnerability appears to have been fixed in after commit…
ModificadaCrítica (9.8)2.3%—Webiness Project Webiness Inventory29/10/201817/6/2026
Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo parameter.
ModificadaAlta (8.8)2.3%—Openwebif Project Openwebif18/9/201717/6/2026
OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the URL refers to an attacker-controlled web site with a Trojan horse package. This has security implications in cases where untrusted users can trigger CallOPKG calls, and…
ModificadaCrítica (9.8)4.9%—Openwebif Project Openwebif22/6/201717/6/2026
An issue was discovered in the OpenWebif plugin through 1.2.4 for E2 open devices. The saveConfig function of "plugin/controllers/models/config.py" performs an eval() call on the contents of the "key" HTTP GET parameter. This allows an unauthenticated remote attacker to execute arbitrary Python code or OS commands via…
ModificadaMedia (4)7.9%💥 ExploitHP Webinspect7/6/201517/6/2026
Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to bypass intended access restrictions via unknown vectors.
ModificadaMedia (5.4)0.27%—Webizz Apostilas Musicais11/10/201417/6/2026
The Apostilas musicais (aka com.apostilas) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Webizz Alma Corinthiana30/9/201417/6/2026
The Alma Corinthiana (aka com.alma.corinthiana) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)2.1%—Webidsupport Webid29/7/201417/6/2026
WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.
ModificadaMedia (4.3)2.5%💥 ExploitWebidsupport Webid25/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_nick, (3) TPL_email, (4) TPL_year, (5) TPL_address, (6) TPL_city, (7) TPL_prov, (8) TPL_zip, (9) TPL_phone, (10) TPL_pp_email, (11) TPL_authnet_id, (12)…
ModificadaMedia (5)5.7%💥 ExploitDream-multimedia-tv Enigma2 Webinterface8/2/201216/6/2026
Absolute path traversal vulnerability in file in Enigma2 Webinterface 1.6.0 through 1.6.8, 1.6rc3, and 1.7.0 allows remote attackers to read arbitrary files via a full pathname in the file parameter.
Orbitaley — Vulnerabilidades