Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
–

3429 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.22%—Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions.
ModificadaMedia (6.1)0.59%—Oomphinc View ALL Post's Pages10/7/202317/6/2026
A vulnerability, which was classified as problematic, has been found in View All Posts Page Plugin up to 0.9.0 on WordPress. This issue affects the function action_admin_notices_activation of the file view-all-posts-pages.php. The manipulation leads to cross site scripting. The attack may be initiated remotely.…
ModificadaMedia (6.1)0.59%—Sophos Iview5/7/202317/6/2026
Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed.
ModificadaMedia (4.8)0.37%—Wpmet WP Ultimate Review23/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.
ModificadaMedia (4.8)0.37%—Grade Review Stream22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Grade Us, Inc. Review Stream plugin <= 1.6.5 versions.
ModificadaMedia (5.4)0.41%—Geminilabs Site Reviews22/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions.
ModificadaMedia (5.4)0.40%—Geminilabs Site Reviews22/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions.
ModificadaMedia (6.1)0.39%—Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview20/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions.
ModificadaMedia (4.8)0.39%—Gvectors Wpview19/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Display Custom Fields – wpView plugin <= 1.3.0 versions.
ModificadaAlta (7.7)0.46%—Bosch Video Management SystemBosch Video Management System ViewerBosch Divar IP 3000 FirmwareBosch Divar IP 6000 Firmware+515/6/202317/6/2026
Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted internal network via a port forwarding request.
ModificadaMedia (5.5)0.25%—Teamviewer Remote14/6/202317/6/2026
Una comprobación de autorización incorrecta de la configuración del dispositivo local en TeamViewer Remote entre las versiones 15.41 y 15.42.7 para Windows y macOS permite a un usuario sin privilegios cambiar la configuración básica del dispositivo local aunque las opciones estuvieran bloqueadas. Esto puede dar lugar…
ModificadaAlta (8.8)1.3%—Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+127/6/202317/6/2026
Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or…
ModificadaCrítica (9.8)1.6%—Etoilewebdesign Ultimate Reviews7/6/202317/6/2026
The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin.
ModificadaAlta (8.8)17%💥 PoCWpdeveloper Reviewx6/6/202317/6/2026
The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by…
ModificadaCrítica (9.8)4.2%—Uniview Camera Firmware31/5/202317/6/2026
Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an internal buffer and achieve code execution. By using this buffer…
ModificadaAlta (8.8)0.44%—Inline Google Spreadsheet Viewer Project Inline Google Spreadsheet Viewer31/5/202317/6/2026
A vulnerability was found in meitar Inline Google Spreadsheet Viewer Plugin up to 0.9.6 on WordPress and classified as problematic. Affected by this issue is the function displayShortcode of the file inline-gdocs-viewer.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely.…
ModificadaMedia (6.1)0.92%—Uthscsa Papaya Viewer26/5/202317/6/2026
An issue was discovered in Papaya Viewer 1.0.1449. User-supplied input in form of DICOM or NIFTI images can be loaded into the Papaya web application without any kind of sanitization. This allows injection of arbitrary JavaScript code into image metadata, which is executed when that metadata is displayed in the Papaya…
ModificadaCrítica (9.1)60%💥 ExploitContec Solarview Compact Firmware23/5/202317/6/2026
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.
ModificadaAlta (8.8)0.26%—Ljapps WP Airbnb Review Slider20/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in LJ Apps WP Airbnb Review Slider plugin <= 3.2 versions.
ModificadaMedia (6.1)4.0%💥 ExploitCMS Tree Page View Project CMS Tree Page View18/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions.
ModificadaMedia (4.8)0.37%—Skeepers Verified Reviews (avis Verifies)16/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NetReviews SAS Verified Reviews (Avis Vérifiés) plugin <= 2.3.13 versions.
ModificadaMedia (5.3)0.75%—Spring-boot-actuator-logview Project Spring-boot-actuator-logview11/5/202317/6/2026
spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view.
AnalizadaCrítica (9.8)0.83%—Janobe Online Reviewer System9/5/202317/6/2026
A vulnerability was found in SourceCodester Online Reviewer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /reviewer/system/system/admins/manage/users/user-update.php of the component GET Parameter Handler. The manipulation of the argument user_id leads to sql…
ModificadaAlta (7.8)0.98%💥 ExploitCyberark Viewfinity3/5/202317/6/2026
In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add printer" option.
ModificadaMedia (6.1)0.85%💥 ExploitPlainviewplugins Mycryptocheckout2/5/202317/6/2026
The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting