Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

157 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)5.1%💥 ExploitCompanymaps Project Companymaps12/5/202317/6/2026
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary code via the auditlog tab in the admin panel.
ModificadaCrítica (9.8)11%💥 ExploitCompanymaps Project Companymaps12/5/202317/6/2026
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a crafted script in the request.
ModificadaMedia (6.1)1.4%💥 PoCCompanymaps Project Companymaps12/5/202317/6/2026
Cross Site Scripting (XSS) vulnerability in vogtmh cmaps (companymaps) 8.0 allows attackers to execute arbitrary code.
ModificadaAlta (7.5)0.42%—Vk.company Mymail7/5/202317/6/2026
The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.
ModificadaMedia (5.4)0.23%—Wow-company Bubble Menu1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu plugin <= 3.0.1 leading to form deletion.
ModificadaMedia (4.9)0.80%—Wow-company WP Coder17/2/202317/6/2026
The WP Coder – add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
ModificadaMedia (6.5)0.42%—Wow-company WP Coder22/8/202217/6/2026
The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack
ModificadaMedia (5.4)0.60%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Company Website CMS. This issue affects some unknown processing of the file /dashboard/contact. The manipulation of the argument phone leads to cross site scripting. The attack may be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)1.2%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/settings. The manipulation leads to improper authentication. The attack can be launched remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/add-portfolio.php. The manipulation of the argument ufile leads to unrestricted upload. The attack may be launched remotely. The identifier of this…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS. Affected is an unknown function of the file /dashboard/add-service.php of the component Add Service Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-206022 is the…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability affects unknown code of the file /dashboard/add-blog.php of the component Add Blog. The manipulation of the argument ufile leads to unrestricted upload. The attack can be initiated remotely. VDB-205882…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unknown part of the file /dashboard/updatelogo.php of the component Background Upload Logo Icon. The manipulation of the argument xfile/ufile leads to unrestricted upload. It is possible to initiate the…
ModificadaMedia (6.1)0.46%—Company Website CMS Project Company Website CMS9/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add-blog.php. The manipulation leads to cross site scripting. The attack may be launched remotely. VDB-205838 is the identifier assigned to this…
ModificadaMedia (6.5)0.63%—Company Website/cms Project Company Website/cms8/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file site-settings.php of the component Cookie Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been…
ModificadaAlta (8.8)0.85%—Company Website CMS Project Company Website CMS6/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205817 was…
ModificadaAlta (8.8)0.54%—Wow-company Counter BOX1/8/202217/6/2026
The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
ModificadaMedia (4.8)0.59%—Linkedin Company Updates Project Linkedin Company Updates17/7/202217/6/2026
The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (7.2)1.0%—Wow-company Hover Effects20/5/202217/6/2026
Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effects plugin <= 2.1 at WordPress.
ModificadaAlta (7.2)1.0%—Wow-company Counter BOX19/5/202217/6/2026
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugin <= 1.1.1 at WordPress.
ModificadaAlta (7.2)1.3%—Wow-company WOW Countdowns28/3/202217/6/2026
The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.
ModificadaMedia (5.5)0.72%—Microsoft Intune Company Portal9/3/202217/6/2026
Microsoft Intune Portal for iOS Security Feature Bypass Vulnerability
ModificadaAlta (8.8)1.3%—Wow-company Wpcalc10/1/202217/6/2026
The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.
ModificadaAlta (8.8)0.67%—Wow-company WP Coder10/1/202217/6/2026
The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
ModificadaAlta (8.8)3.0%💥 ExploitWow-company Button Generator10/1/202217/6/2026
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
Orbitaley — Vulnerabilidades