Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
1775 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.35% | — | Mattermost | 16/6/2023 | 17/6/2026 | Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands. | |
| Modificada | Media (6.5) | 0.32% | — | Mattermost | 16/6/2023 | 17/6/2026 | Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install requests to the Apps. | |
| Modificada | Media (4.3) | 0.44% | — | Mattermost | 16/6/2023 | 17/6/2026 | Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps. | |
| Modificada | Media (4.3) | 0.30% | — | Cimatti Contact Forms | 13/6/2023 | 17/6/2026 | The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms… | |
| Modificada | Media (4.3) | 0.50% | — | Nsqua Draw Attention | 9/6/2023 | 17/6/2026 | The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_set_featured_image function in versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the… | |
| Modificada | Crítica (9.8) | 0.74% | — | Automattic Vaultpress | 1/6/2023 | 17/6/2026 | A vulnerability was found in VaultPress Plugin up to 1.6.0 on WordPress. It has been declared as critical. Affected by this vulnerability is the function protect_aioseo_ajax of the file class.vaultpress-hotfixes.php of the component MailPoet Plugin. The manipulation leads to unrestricted upload. The attack can be… | |
| Modificada | Media (5.3) | 0.41% | — | Mattermost | 29/5/2023 | 17/6/2026 | Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link. | |
| Modificada | Alta (8.8) | 0.26% | — | Login AND Registration Attempts Limit Project Login AND Registration Attempts Limit | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in German Krutov LOGIN AND REGISTRATION ATTEMPTS LIMIT plugin <= 2.1 versions. | |
| Modificada | Media (4.3) | 0.28% | — | Infigosoftware Clock IN Portal- Staff & Attendance Management | 15/5/2023 | 17/6/2026 | The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admins delete arbitrary holidays via a CSRF attack | |
| Modificada | Media (4.3) | 0.28% | — | Infigosoftware Clock IN Portal- Staff & Attendance Management | 15/5/2023 | 17/6/2026 | The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in admins delete arbitrary designations via a CSRF attack | |
| Modificada | Media (4.3) | 0.28% | — | Infigosoftware Clock IN Portal- Staff & Attendance Management | 15/5/2023 | 17/6/2026 | The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack | |
| Modificada | Media (6.7) | 0.16% | — | Intel Battery Life Diagnostic ToolIntel Oneapi Base ToolkitIntel SOC Watch | 12/5/2023 | 17/6/2026 | Heap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.47% | — | Mattermost Server | 12/5/2023 | 17/6/2026 | Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin | |
| Modificada | Alta (7.5) | 0.55% | — | Mattermost | 12/5/2023 | 17/6/2026 | Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization. | |
| Modificada | Media (6.1) | 0.38% | — | Mauimarketing Update Image TAG ALT Attribute | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maui Marketing Update Image Tag Alt Attribute plugin <= 2.4.5 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Mattermost Desktop | 2/5/2023 | 17/6/2026 | Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website | |
| Modificada | Media (5.4) | 29% | — | Limit Login Attempts Project Limit Login Attempts | 2/5/2023 | 17/6/2026 | The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 1.1% | — | Textpattern | 28/4/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file. | |
| Modificada | Media (4.3) | 0.47% | — | Mattermost Server | 25/4/2023 | 17/6/2026 | When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team. | |
| Modificada | Crítica (9.1) | 0.59% | — | Mattermost | 20/4/2023 | 17/6/2026 | Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token. | |
| Modificada | Alta (7.5) | 0.42% | — | Mattermost Server | 17/4/2023 | 17/6/2026 | Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config). | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Automattic Woocommerce PaymentsAutomattic Woopayments | 12/4/2023 | 17/6/2026 | An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated. | |
| Modificada | Alta (7.2) | 2.0% | 💥 PoC | Textpattern | 12/4/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a crafted PHP file. | |
| Modificada | Media (6.1) | 0.38% | — | Cimatti Wordpress Contact Forms | 7/4/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Cimatti Wordpress Contact Forms | 7/4/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions. |