Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
90 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.67% | — | Laravel DuskAIWintercms WN Dusk PluginAIWintercms Winter CMSAI | 12/4/2024 | 17/6/2026 | wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes as part of its testing framework to allow a browser environment (such as headless Chrome) to act as a user in the Backend or User plugin without having to go through… | |
| Analizada | Alta (7.2) | 1.8% | — | Wintercms Winter | 29/3/2024 | 17/6/2026 | Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugin components. NOTE: the vendor disputes this because the payload could only be entered by a trusted user, such as the owner of the server… | |
| Modificada | Media (5.3) | 0.47% | — | Themewinter Eventin | 9/2/2024 | 17/6/2026 | The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_data() function in all versions up to, and including, 3.3.50. This makes it possible for unauthenticated attackers to export… | |
| Modificada | Media (5.4) | 30% | 💥 Exploit | Wintercms Winter | 29/12/2023 | 17/6/2026 | Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included without further processing in the compilation of custom stylesheets via LESS. This had the potential to lead to a Local File Inclusion… | |
| Modificada | Media (5.4) | 0.31% | — | Wintercms Winter | 28/12/2023 | 17/6/2026 | Winter is a free, open-source content management system. Prior to 1.2.4, Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be rendered unescaped in the backend form, potentially allowing for a stored XSS attack. This issue has been patched in v1.2.4. | |
| Modificada | Media (4.8) | 0.31% | — | Wintercms Winter | 28/12/2023 | 17/6/2026 | Winter is a free, open-source content management system. Prior to 1.2.4, users with the `media.manage_media` permission can upload files to the Media Manager and rename them after uploading. Previously, media manager files were only sanitized on upload, not on renaming, which could have allowed a stored XSS attack.… | |
| Modificada | Media (6.1) | 0.44% | — | Myshopkit Winters | 20/10/2023 | 17/6/2026 | The Winters theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they… | |
| Modificada | Media (4.8) | 2.7% | 💥 Exploit | Wintercms Winter | 7/7/2023 | 17/6/2026 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Users with the `backend.manage_branding` permission can upload SVGs as the application logo. Prior to version 1.2.3, SVG uploads were not sanitized, which could have allowed a stored cross-site scripting (XSS) attack. To… | |
| Modificada | Media (5.4) | 0.36% | — | Winterchen My-site | 1/5/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in WinterChenS my-site before commit 3f0423da6d5200c7a46e200da145c1f54ee18548, allows attackers to inject arbitrary web script or HTML via editing blog articles. | |
| Modificada | Crítica (9.8) | 1.1% | — | Wintercms Winter | 26/10/2022 | 17/6/2026 | Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. The 1.0 branch of Winter is not affected, as it does not contain the… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Winterwebs Ezwebitor | 12/7/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL commands via the (1) txtUserId (Username) and (2) txtPassword (Password) parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 0.85% | — | Sebastian Winterhalder Mailform | 15/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Mailform (mailform) extension before 0.9.24 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Winterburns.co.uk Epersonnel | 31/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in protection.php in ePersonnel RC_2004_02 allows remote attackers to execute arbitrary PHP code via a URL in the logout_page parameter. | |
| Modificada | Media (5) | 7.2% | 💥 Exploit | Wyse Winterm | 16/8/2005 | 16/6/2026 | Wyse Winterm 1125SE running firmware 4.2.09f or 4.4.061f allows remote attackers to cause a denial of service (device crash) via a packet with a zero in the IP option length field. | |
| Modificada | Alta (10) | 10% | 💥 Exploit | Jack DE Winter Winsmtp | 14/11/2000 | 16/6/2026 | Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command. |