Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
–

1775 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.79%—Limit Login Attempts Project Limit Login Attempts6/4/202317/6/2026
The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
ModificadaMedia (5.3)0.54%—Mattermost Server31/3/202317/6/2026
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
ModificadaMedia (5.4)0.45%—Mattermost Server31/3/202317/6/2026
Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.
ModificadaMedia (6.5)0.55%—Mattermost Server31/3/202317/6/2026
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.
ModificadaMedia (5.4)0.32%—Mattermost Server31/3/202317/6/2026
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.
ModificadaMedia (4.3)0.46%—Mattermost22/3/202317/6/2026
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
ModificadaMedia (6.1)0.41%—Mattermost Server15/3/202317/6/2026
A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.
ModificadaAlta (7.2)0.60%—Bbraun Battery-pack SP With Wifi Firmware13/3/202317/6/2026
An improper neutralization of directives in dynamically evaluated code vulnerability in the WiFi Battery embedded web server in versions L90/U70 and L92/U92 can be used to gain administrative access to the WiFi communication module. An authenticated user, having access to both the medical device WiFi network (such as…
ModificadaMedia (5.4)0.48%—Dfactory Download Attachments6/3/202317/6/2026
The Download Attachments WordPress plugin before 1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaBaja (2.7)0.53%—Mattermost Server27/2/202317/6/2026
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
ModificadaBaja (2.7)0.53%—Mattermost Server27/2/202317/6/2026
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
ModificadaMedia (6.5)0.50%—Mattermost27/2/202317/6/2026
A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.
ModificadaMedia (6.5)0.50%—Mattermost27/2/202317/6/2026
A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.
ModificadaAlta (7.8)0.17%—Intel Battery Life Diagnostic Tool16/2/202317/6/2026
Uncontrolled search path in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.19%—Intel Battery Life Diagnostic Tool16/2/202317/6/2026
Insufficient control flow management in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.20%—Intel Battery Life Diagnostic Tool16/2/202317/6/2026
Improper initialization in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)0.83%—Snapav Wattbox Wb-300-ip-3 Firmware30/1/202317/6/2026
Snap One Wattbox WB-300-IP-3 versiones WB10.9a17 y anteriores son vulnerables a un desbordamiento de búfer de almacenamiento dinámico, lo que podría permitir a un atacante ejecutar código arbitrario o bloquear el dispositivo de forma remota.
ModificadaMedia (6.5)0.48%—Snapav Wattbox Wb-300-ip-3 Firmware30/1/202317/6/2026
Snap One Wattbox WB-300-IP-3 versiones WB10.9a17 y anteriores almacenan contraseñas en un archivo de texto plano cuando la configuración del dispositivo se exporta a través de Save/Restore–>Backup Settings, que cualquier usuario que acceda al archivo podría leer.
ModificadaCrítica (9.8)0.65%—Snapav Wattbox Wb-300-ip-3 Firmware30/1/202317/6/2026
Snap One Wattbox WB-300-IP-3 versiones WB10.9a17 y anteriores podrían evitar la protección de fuerza bruta, permitiendo múltiples intentos de forzar un inicio de sesión.
ModificadaAlta (7.8)0.11%—Snapav Wattbox Wb-300-ip-3 Firmware30/1/202317/6/2026
Snap One Wattbox WB-300-IP-3 versiones WB10.9a17 y anteriores utilizan un protocolo de red de área local (LAN) propietario que no verifica las actualizaciones del dispositivo. Un atacante podría cargar un archivo de actualización con formato incorrecto en el dispositivo y ejecutar código arbitrario.
ModificadaAlta (7.5)0.70%—Ciphercoin WP Limit Login Attempts23/1/202317/6/2026
El complemento WP Limit Login Attempts de WordPress hasta la versión 2.6.4 prioriza la obtención de la IP de un visitante de ciertos encabezados HTTP sobre REMOTE_ADDR de PHP, lo que permite evitar las restricciones basadas en IP en los formularios de inicio de sesión.
ModificadaMedia (4.8)0.47%—Marcomilesi WP Attachments16/1/202317/6/2026
Las versiones del complemento WP Attachments de WordPress anteriores a la 5.0.6 no sanitizan ni escapan algunas de sus configuraciones, lo que podría permitir a usuarios con privilegios elevados, como el administrador, realizar ataques de cross site scripting almacenado incluso cuando la capacidad unfiltered_html no…
ModificadaCrítica (9.8)0.66%—Aibattle Project Aibattle13/1/202317/6/2026
** NO SOPORTADO CUANDO SE ASIGNÓ ** Se ha encontrado una vulnerabilidad en Dovgalyuk AIBattle clasificada como crítica. La función RegisterUser del archivo site/procedures.php es afectada por esta vulnerabilidad. La manipulación del argumento postLogin conduce a la inyección SQL. El identificador del parche es…
ModificadaCrítica (9.8)0.74%—Aibattle Project Aibattle13/1/202317/6/2026
** NO SOPORTADO CUANDO SE ASIGNÓ ** Se encontró una vulnerabilidad clasificada como crítica en Dovgalyuk AIBattle. La función sendComments del fichero site/procedures.php es afectada por la vulnerabilidad. La manipulación del texto del argumento conduce a la inyección SQL. El nombre del parche es…
ModificadaMedia (5.4)0.53%—Automattic Jetpack CRM9/1/202317/6/2026
El complemento Jetpack CRM para WordPress anterior a 5.5 no valida ni escapa algunos de sus atributos de código corto antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar ataques de cross-site scripting almacenado que podrían usarse contra alto nivel…
Orbitaley — Vulnerabilidades