Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

2620 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Mayurik Free Hospital Management System FOR Small Practices6/8/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this issue is some unknown functionality of the file /vm/admin/delete-doctor.php?id=2 of the component Redirect Handler. The manipulation leads to enforcement of…
ModificadaCrítica (9.8)0.94%—Mayurik Free Hospital Management System FOR Small Practices6/8/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this vulnerability is an unknown functionality of the file /vm/login.php. The manipulation of the argument useremail/userpassword leads to sql injection. The attack can be launched…
ModificadaCrítica (9.8)0.83%—Mayurik Free Hospital Management System FOR Small Practices6/8/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected is an unknown function of the file /vm/doctor/doctors.php?action=view. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The…
ModificadaAlta (8.8)0.23%—Freebsd1/8/202317/6/2026
El controlador fwctl implementa una máquina de estados que se ejecuta cuando un huésped bhyve accede a ciertos puertos de E/S x86. La interfaz permite al huésped copiar una cadena en un búfer residente en la memoria del proceso bhyve. Un error en la implementación de la máquina de estado puede provocar el…
ModificadaAlta (7.5)0.65%—FreebsdNetapp Clustered Data Ontap1/8/202317/6/2026
Un conjunto de paquetes ipv6 cuidadosamente diseñados puede desencadenar un desbordamiento de enteros en el cálculo del campo de longitud de la carga útil de un paquete reensamblado por fragmentos. Esto permite a un atacante desencadenar un kernel panic, resultando en una denegación de servicio.
ModificadaMedia (5.5)0.90%—Freedesktop Poppler31/7/202317/6/2026
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
ModificadaMedia (6.5)0.32%—Addify Abandoned Cart RecoveryAddify Advanced Free GiftsAddify Checkout Fields ManagerAddify Custom Fields FOR Woocommerce+631/7/202317/6/2026
The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through 1.0.1, Custom Registration Forms Builder WordPress plugin before 1.0.2, Advanced Free Gifts…
ModificadaAlta (8.8)0.25%—Piwebsolution Advanced-free-flat-shipping-woocommerce11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in PI Websolution Conditional shipping & Advanced Flat rate shipping rates / Flexible shipping for WooCommerce shipping plugin <= 1.6.4.4 versions.
ModificadaCrítica (9.8)1.1%—Freebsd22/6/202317/6/2026
pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key Distribution Center) over the network, as a way to verify the password. However, if a keytab is not provisioned on the system, pam_krb5 has no way to validate the response…
ModificadaMedia (6.5)1.4%—Freedesktop DbusFedoraproject FedoraDebian Linux8/6/202317/6/2026
D-Bus en versiones anteriores a v1.15.6 a veces permite a usuarios sin privilegios bloquear el "dbus-daemon". Si un usuario privilegiado con control sobre "dbus-daemon" está usando la interfaz "org.freedesktop.DBus.Monitoring" para monitorizar el tráfico del bus de mensajes, entonces un usuario sin privilegios con la…
ModificadaMedia (6.1)0.61%—Webaware GF Windcave Free6/6/202317/6/2026
A vulnerability, which was classified as problematic, was found in Gravity Forms DPS PxPay Plugin up to 1.4.2 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.4.3 is able to address this issue. The name…
ModificadaAlta (8.8)0.81%—Salephpscripts WEB Directory Free2/6/202317/6/2026
Web Directory Free para WordPress es vulnerable a la inyección SQL a través del parámetro "post_id" en las versiones hasta la 1.6.7 inclusive, debido a un escape insuficiente del parámetro suministrado por el usuario y a la falta de preparación suficiente de la consulta SQL existente. Esto hace posible que atacantes…
ModificadaAlta (8.8)0.27%—Pingonline Dyslexiefont Free20/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in PingOnline Dyslexiefont Free plugin <= 1.0.0 versions.
ModificadaCrítica (9.8)0.94%—Perfreeblog18/5/202317/6/2026
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file.
ModificadaCrítica (9.8)2.1%—Freeguppy Guppy17/5/202317/6/2026
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.
ModificadaAlta (7.8)0.47%—Soft-o Free Password Manager12/5/202317/6/2026
A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.
ModificadaMedia (5.4)0.46%—Perfreeblog1/5/202317/6/2026
Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function.
ModificadaAlta (8.1)0.65%—Sangoma Freepbx Linux 726/4/202317/6/2026
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a…
ModificadaAlta (7.5)0.52%—Freesoul Deactivate Plugins - Plugin Manager AND Cleanup Project Freesoul Deactivate Plugins - Plugin Manager AND Cleanup16/4/202317/6/2026
Insecure Storage of Sensitive Information vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager and cleanup plugin <= 1.9.4.0 versions.
ModificadaAlta (7.5)1.2%—Bestools Trusted Tools Free Music14/4/202317/6/2026
SQL injection vulnerability found in Trusted Tools Free Music v.2.1.0.47, v.2.0.0.46, v.1.9.1.45, v.1.8.2.43 allows a remote attacker to cause a denial of service via the search history table
ModificadaMedia (4.3)0.25%—Hasthemes Free Woocommerce Theme 99fy Extension27/3/202317/6/2026
The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
ModificadaCrítica (9.8)0.94%—Perfreeblog15/3/202317/6/2026
An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file.
ModificadaMedia (5.5)0.28%—Freeimage Project Freeimage22/2/202317/6/2026
Buffer Overflow vulnerability in Freeimage v3.18.0 allows attacker to cause a denial of service via a crafted JXR file.
ModificadaMedia (6.5)0.64%—Freebsd8/2/202317/6/2026
When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once resulting in the second and subsequent devices silently using a NULL key as the user key file. If a user only uses a key file without a user passphrase, the master key is encrypted with an empty key…
ModificadaMedia (6.5)1.1%—Freeradius17/1/202317/6/2026
Se encontró un defecto en freeradius. Un cliente RADIUS o un servidor doméstico malicioso puede enviar un atributo binario con formato incorrecto que puede provocar que el servidor falle.