Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

127 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.43%—Verbb Comments5/6/202017/6/2026
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.
ModificadaMedia (6.1)1.8%💥 ExploitLivefyre Livecomments27/12/201917/6/2026
Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded picture.
ModificadaMedia (6.1)1.2%—Videowhisper Video Comments Webcam Recorder27/12/201917/6/2026
Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder plugin 1.55, as downloaded before 20140116 for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter.
ModificadaMedia (6.5)1.1%—Jenkins Violation Comments TO Gitlab25/9/201917/6/2026
Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
ModificadaMedia (6.5)1.1%—Jenkins Violation Comments TO Gitlab25/9/201917/6/2026
Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
ModificadaMedia (6.1)0.98%—Spot.im Comments10/9/201917/6/2026
The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues.
ModificadaMedia (4.3)0.50%—Pippinsplugins Featured Comments22/8/201917/6/2026
The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.
ModificadaMedia (6.1)0.91%—Embed Images IN Comments Project Embed Images IN Comments21/8/201917/6/2026
The embed-comment-images plugin before 0.6 for WordPress has XSS.
ModificadaAlta (7.8)5.1%💥 ExploitWebtoffee Wordpress Comments Import AND Export19/6/201817/6/2026
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
ModificadaAlta (8.8)1.6%—Disable Comments Project19/3/201817/6/2026
Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that enable comments via a request to the disable_comments_settings page to wp-admin/options-general.php.
ModificadaAlta (8.8)0.91%—Subscribe TO Comments Reloaded Project Subscribe TO Comments Reloaded19/3/201817/6/2026
Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the…
ModificadaCrítica (9.1)8.6%—Contussupport Contus-video-comments6/10/201617/6/2026
Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin
ModificadaMedia (4.3)1.6%—Verification Code FOR Comments Project Verification Code FOR Comments2/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in the Verification Code for Comments plugin 2.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) vp, (2) vs, (3) l, (4) vu, or (5) vm parameter.
ModificadaMedia (6.8)2.6%💥 ExploitFeatured Comments Plugin Project Featured Comments16/6/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that change the (1) buried or (2) featured status of a comment via a request to wp-admin/admin-ajax.php.
ModificadaMedia (4.3)2.1%—Mg12 Wp-recentcomments14/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.
ModificadaAlta (7.5)2.0%—Mg12 Wp-recentcomments14/2/201216/6/2026
SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.7%💥 ExploitJoomlatune COM Jcomments23/11/201116/6/2026
Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inject arbitrary web script or HTML via the name parameter to index.php.
ModificadaAlta (7.5)1.0%—Raphael Zschorsch Commentsbe7/10/201116/6/2026
SQL injection vulnerability in the Commenting system Backend Module (commentsbe) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.0%—Jxtended Comments9/12/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the JXtended Comments component before 1.3.1 for Joomla allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.7%💥 ExploitRsjoomla COM Rscomments25/6/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website and (2) name parameters to index.php.
ModificadaMedia (4.3)1.1%—Alkacon Oamp Comments26/3/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in OpenCMS OAMP Comments Module 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the name field in a comment, and other unspecified vectors.
ModificadaBaja (3.5)1.00%—Fourkitchens Recent Comments25/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in the Recent Comments module 5.x through 5.x-1.2 and 6.x through 6.x-1.0 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a "custom block title interface."
ModificadaAlta (7.5)1.1%—Typo3 Eluna Page Comments Extension31/12/200816/6/2026
SQL injection vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.0%—Typo3 Eluna Page Comments Extension31/12/200816/6/2026
Cross-site scripting (XSS) vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaCrítica (9.8)2.9%💥 ExploitOocomments25/3/200816/6/2026
Multiple PHP remote file inclusion vulnerabilities in ooComments 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the PathToComment parameter for (1) classes/class_admin.php and (2) classes/class_comments.php. NOTE: the provenance of this information is unknown; the details are obtained solely…
Orbitaley — Vulnerabilidades