Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
3429 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.22% | — | Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions. | |
| Modificada | Media (6.1) | 0.59% | — | Oomphinc View ALL Post's Pages | 10/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in View All Posts Page Plugin up to 0.9.0 on WordPress. This issue affects the function action_admin_notices_activation of the file view-all-posts-pages.php. The manipulation leads to cross site scripting. The attack may be initiated remotely.… | |
| Modificada | Media (6.1) | 0.59% | — | Sophos Iview | 5/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed. | |
| Modificada | Media (4.8) | 0.37% | — | Wpmet WP Ultimate Review | 23/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Grade Review Stream | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Grade Us, Inc. Review Stream plugin <= 1.6.5 versions. | |
| Modificada | Media (5.4) | 0.41% | — | Geminilabs Site Reviews | 22/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions. | |
| Modificada | Media (5.4) | 0.40% | — | Geminilabs Site Reviews | 22/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions. | |
| Modificada | Media (6.1) | 0.39% | — | Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview | 20/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Gvectors Wpview | 19/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Display Custom Fields – wpView plugin <= 1.3.0 versions. | |
| Modificada | Alta (7.7) | 0.46% | — | Bosch Video Management SystemBosch Video Management System ViewerBosch Divar IP 3000 FirmwareBosch Divar IP 6000 Firmware+5 | 15/6/2023 | 17/6/2026 | Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted internal network via a port forwarding request. | |
| Modificada | Media (5.5) | 0.25% | — | Teamviewer Remote | 14/6/2023 | 17/6/2026 | Una comprobación de autorización incorrecta de la configuración del dispositivo local en TeamViewer Remote entre las versiones 15.41 y 15.42.7 para Windows y macOS permite a un usuario sin privilegios cambiar la configuración básica del dispositivo local aunque las opciones estuvieran bloqueadas. Esto puede dar lugar… | |
| Modificada | Alta (8.8) | 1.3% | — | Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+12 | 7/6/2023 | 17/6/2026 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or… | |
| Modificada | Crítica (9.8) | 1.6% | — | Etoilewebdesign Ultimate Reviews | 7/6/2023 | 17/6/2026 | The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. | |
| Modificada | Alta (8.8) | 17% | 💥 PoC | Wpdeveloper Reviewx | 6/6/2023 | 17/6/2026 | The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by… | |
| Modificada | Crítica (9.8) | 4.2% | — | Uniview Camera Firmware | 31/5/2023 | 17/6/2026 | Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an internal buffer and achieve code execution. By using this buffer… | |
| Modificada | Alta (8.8) | 0.44% | — | Inline Google Spreadsheet Viewer Project Inline Google Spreadsheet Viewer | 31/5/2023 | 17/6/2026 | A vulnerability was found in meitar Inline Google Spreadsheet Viewer Plugin up to 0.9.6 on WordPress and classified as problematic. Affected by this issue is the function displayShortcode of the file inline-gdocs-viewer.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely.… | |
| Modificada | Media (6.1) | 0.92% | — | Uthscsa Papaya Viewer | 26/5/2023 | 17/6/2026 | An issue was discovered in Papaya Viewer 1.0.1449. User-supplied input in form of DICOM or NIFTI images can be loaded into the Papaya web application without any kind of sanitization. This allows injection of arbitrary JavaScript code into image metadata, which is executed when that metadata is displayed in the Papaya… | |
| Modificada | Crítica (9.1) | 60% | 💥 Exploit | Contec Solarview Compact Firmware | 23/5/2023 | 17/6/2026 | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted. | |
| Modificada | Alta (8.8) | 0.26% | — | Ljapps WP Airbnb Review Slider | 20/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LJ Apps WP Airbnb Review Slider plugin <= 3.2 versions. | |
| Modificada | Media (6.1) | 4.0% | 💥 Exploit | CMS Tree Page View Project CMS Tree Page View | 18/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Skeepers Verified Reviews (avis Verifies) | 16/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NetReviews SAS Verified Reviews (Avis Vérifiés) plugin <= 2.3.13 versions. | |
| Modificada | Media (5.3) | 0.75% | — | Spring-boot-actuator-logview Project Spring-boot-actuator-logview | 11/5/2023 | 17/6/2026 | spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view. | |
| Analizada | Crítica (9.8) | 0.83% | — | Janobe Online Reviewer System | 9/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Reviewer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /reviewer/system/system/admins/manage/users/user-update.php of the component GET Parameter Handler. The manipulation of the argument user_id leads to sql… | |
| Modificada | Alta (7.8) | 0.98% | 💥 Exploit | Cyberark Viewfinity | 3/5/2023 | 17/6/2026 | In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add printer" option. | |
| Modificada | Media (6.1) | 0.85% | 💥 Exploit | Plainviewplugins Mycryptocheckout | 2/5/2023 | 17/6/2026 | The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting |