Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▲ 5 respecto a la semana anterior
Críticas / altas1275▼ 253 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
3429 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.90% | — | Prestashop Advanced Reviews | 14/3/2023 | 17/6/2026 | PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection. | |
| Modificada | Media (5.4) | 0.38% | 💥 PoC | Qlikview | 6/3/2023 | 9/7/2026 | QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality. | |
| Modificada | Media (5.3) | 0.44% | — | Discourse Yearly Review | 6/3/2023 | 17/6/2026 | discourse-yearly-review is a discourse plugin which publishes an automated Year in Review topic. In affected versions a user present in a yearly review topic that is then anonymised will still have some data linked to its original account. This issue has been patched in commit `b3ab33bbf7` which is included in the… | |
| Modificada | Media (5.5) | 0.20% | — | HP Oneview FOR Vmware Vcenter | 1/3/2023 | 17/6/2026 | HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password. | |
| Modificada | Alta (7.2) | 0.73% | — | Online Reviewer Management System Project Online Reviewer Management System | 28/2/2023 | 17/6/2026 | An issue was discovered in Online Reviewer Management System v1.0. There is a SQL injection that can directly issue instructions to the background database system via reviewer_0/admins/assessments/course/course-update.php. | |
| Modificada | Media (4.8) | 0.46% | — | Online Reviewer Management System Project Online Reviewer Management System | 28/2/2023 | 17/6/2026 | An issue was discovered in Online Reviewer Management System v1.0. There is a XSS vulnerability via reviewer_0/admins/assessments/course/course-update.php. | |
| Modificada | Alta (7.1) | 0.15% | — | Hitachi Automation DirectorHitachi Infrastructure Analytics AdvisorHitachi OPS Center AnalyzerHitachi OPS Center Automator+1 | 28/2/2023 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infrastructure Analytics Advisor, Analytics probe server components), Hitachi Ops Center Automator on Linux, Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer,… | |
| Modificada | Crítica (9.8) | 0.81% | — | Online Reviewer Management System Project Online Reviewer Management System | 26/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Reviewer Management System 1.0. Affected is an unknown function of the file /reviewer_0/admins/assessments/pretest/questions-view.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely.… | |
| Modificada | Alta (8.8) | 0.87% | — | Wpdeveloper Reviewx | 23/2/2023 | 17/6/2026 | The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters. | |
| Modificada | Media (5.4) | 0.63% | — | Post Views Count Project Post Views Count | 21/2/2023 | 17/6/2026 | The Post Views Count WordPress plugin through 3.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.92% | — | Ljapps WP Yelp Review Slider | 13/2/2023 | 17/6/2026 | El complemento WP Yelp Review Slider de WordPress anterior a 7.1 no desinfecta ni escapa adecuadamente un parámetro antes de usarlo en una declaración SQL, lo que lleva a una inyección SQL explotable por usuarios con un rol tan bajo como el de suscriptor. | |
| Modificada | Alta (8.8) | 0.92% | — | Ljapps WP Airbnb Review Slider | 13/2/2023 | 17/6/2026 | El complemento WP Airbnb Review Slider de WordPress anterior a 3.3 no desinfecta ni escapa adecuadamente un parámetro antes de usarlo en una declaración SQL, lo que lleva a una inyección de SQL explotable por usuarios con un rol tan bajo como el de suscriptor. | |
| Modificada | Alta (8.8) | 4.4% | 💥 Exploit | Ljapps WP Tripadvisor Review Slider | 13/2/2023 | 17/6/2026 | El complemento WP TripAdvisor Review Slider de WordPress anterior a 10.8 no desinfecta ni escapa adecuadamente un parámetro antes de usarlo en una declaración SQL, lo que lleva a una inyección SQL explotable por usuarios con un rol tan bajo como el de suscriptor. | |
| Modificada | Alta (8.8) | 0.92% | — | Ljapps WP Review Slider | 13/2/2023 | 17/6/2026 | El complemento WP Review Slide de WordPress anterior a 12.2 no desinfecta ni escapa adecuadamente un parámetro antes de usarlo en una declaración SQL, lo que lleva a una inyección SQL explotable por usuarios con un rol tan bajo como el de suscriptor. | |
| Modificada | Alta (8.8) | 0.92% | — | Ljapps WP Google Review Slider | 13/2/2023 | 17/6/2026 | El complemento WP Google Review Slider de WordPress anterior a 11.8 no desinfecta ni escapa adecuadamente un parámetro antes de usarlo en una declaración SQL, lo que lleva a una inyección de SQL explotable por usuarios con un rol tan bajo como el de suscriptor. | |
| Modificada | Alta (8.8) | 1.1% | — | Cusrev Customer Reviews FOR Woocommerce | 13/2/2023 | 17/6/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also… | |
| Modificada | Media (5.4) | 0.64% | — | Judge Product Reviews FOR Woocommerce | 13/2/2023 | 17/6/2026 | The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Crítica (9.8) | 99% | 💥 Exploit | Contec Solarview Compact Firmware | 6/2/2023 | 17/6/2026 | Existe una vulnerabilidad de inyección de comandos en SolarView Compact hasta la versión 6.00, los atacantes pueden ejecutar comandos eludiendo las restricciones internas a través de downloader.php. | |
| Modificada | Media (5.4) | 0.57% | — | A3rev Page View Count | 6/2/2023 | 17/6/2026 | The Page View Count WordPress plugin before 2.6.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.56% | — | Pdf.js Viewer Project Pdf.js Viewer | 6/2/2023 | 17/6/2026 | The PDF.js Viewer WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Keking Kkfileview | 1/2/2023 | 17/6/2026 | kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java. | |
| Modificada | Alta (7.8) | 0.17% | — | Hpsfviewer | 1/2/2023 | 17/6/2026 | HPSFViewer might allow Escalation of Privilege. This potential vulnerability was remediated on July 29th, 2022. Customers who opted for automatic updates should have already received the remediation. | |
| Modificada | Media (5.4) | 0.47% | — | PDF Viewer Project PDF Viewer | 30/1/2023 | 17/6/2026 | El complemento PDF Viewer de WordPress anterior a 1.0.0 no valida ni escapa uno de sus atributos de código corto, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar un ataque de cross-site scripting almacenado. | |
| Modificada | Media (5.4) | 0.51% | — | Trustindex Widgets FOR Google Reviews | 30/1/2023 | 17/6/2026 | El complemento Widgets for Google Reviews de WordPress anterior a 9.8 no valida ni escapa algunos de sus atributos de código corto antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar ataques de cross-site scripting almacenado que podrían usarse contra… | |
| Modificada | Media (6.5) | 0.60% | — | Jenkins View-cloner | 26/1/2023 | 17/6/2026 | El complemento view-cloner de Jenkins en su versión 1.1 y anteriores almacena contraseñas sin cifrar en archivos job config.xml en el controlador Jenkins, donde los usuarios con permiso de lectura extendida pueden verlas o acceder al sistema de archivos del controlador Jenkins. |