Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.20% | — | Stephanieleary Convert Post TypesAI | 11/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stephanie Leary Convert Post Types.This issue affects Convert Post Types: from n/a through 1.4. | |
| Modificada | Alta (7.5) | 0.52% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 10/4/2024 | 12/8/2026 | Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5. | |
| Aplazada | Alta (7.1) | 0.35% | — | Stephanieleary Convert Post TypesAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stephanie Leary Convert Post Types allows Reflected XSS.This issue affects Convert Post Types: from n/a through 1.4. | |
| Aplazada | Media (6.5) | 0.33% | — | Currencyratetoday Crypto Converter WidgetAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Crypto Converter Widget allows Stored XSS.This issue affects Crypto Converter Widget: from n/a through 1.8.4. | |
| Analizada | Media (6.5) | 1.1% | 💥 PoC | Xnview Nconvert | 28/2/2024 | 17/6/2026 | Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file. | |
| Modificada | Media (5.5) | 0.38% | — | Poikosoft EZ CD Audio Converter | 25/1/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Poikosoft EZ CD Audio Converter 8.0.7. Affected by this vulnerability is an unknown functionality of the component Activation Handler. The manipulation of the argument Key leads to denial of service. Local access is required to approach this attack. The exploit… | |
| Modificada | Alta (8.8) | 0.54% | — | Briandgoad Ptypeconverter | 8/1/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brian D. Goad pTypeConverter.This issue affects pTypeConverter: from n/a through 0.2.8.1. | |
| Modificada | Media (5.4) | 0.30% | — | Currencywiki Currency Converter Widget - Exchange Rates | 21/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Currency.Wiki Currency Converter Widget – Exchange Rates allows Stored XSS.This issue affects Currency Converter Widget – Exchange Rates: from n/a through 3.0.2. | |
| Modificada | Media (5.4) | 0.39% | — | Currencyratetoday Crypto Converter Widget | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Crypto Converter Widget allows Stored XSS.This issue affects Crypto Converter Widget: from n/a through 1.8.1. | |
| Modificada | Media (5.4) | 0.39% | — | Currencyratetoday Currency Converter Calculator | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Currency Converter Calculator allows Stored XSS.This issue affects Currency Converter Calculator: from n/a through 1.3.1. | |
| Modificada | Media (5.4) | 0.38% | — | Spreadsheetconverter Import Spreadsheets | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Stored XSS.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.3. | |
| Modificada | Alta (8.8) | 0.30% | — | Codeboxr CBX Currency Converter | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in codeboxr CBX Currency Converter plugin <= 3.0.3 versions. | |
| Modificada | Alta (7.8) | 0.54% | — | Xnview Nconvert | 19/10/2023 | 17/6/2026 | XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution. | |
| Modificada | Alta (7.8) | 0.52% | — | Xnview Nconvert | 19/10/2023 | 17/6/2026 | XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file. | |
| Modificada | Alta (7.8) | 0.62% | — | Xnview Nconvert | 18/10/2023 | 17/6/2026 | XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution. | |
| Modificada | Crítica (9.8) | 1.3% | — | Ezsoftmagic MP3 Audio Converter | 10/8/2023 | 17/6/2026 | EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow. | |
| Modificada | Media (5.5) | 0.22% | — | Fortinet ForticlientFortinet Forticonverter | 13/6/2023 | 17/6/2026 | An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper with files in the installation folder, if… | |
| Modificada | Media (6.1) | 0.70% | — | Woocommerce Sidebar Manager TO Woosidebars Converter | 5/6/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in WooSidebars Sidebar Manager Converter Plugin up to 1.1.1 on WordPress. This affects the function process_request of the file classes/class-woosidebars-sbm-converter.php. The manipulation leads to open redirect. It is possible to initiate the attack… | |
| Modificada | Media (6.1) | 0.46% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 5/6/2023 | 17/6/2026 | The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.4) | 0.36% | — | Convertbox Auto Embed | 9/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ConvertBox ConvertBox Auto Embed WordPress plugin <= 1.0.19 versions. | |
| Modificada | Alta (7.8) | 0.43% | — | Wondershare Uniconverter | 4/4/2023 | 17/6/2026 | An issue found in Wondershare Technology Co., Ltd UniConverter v.14.0.0 allows a remote attacker to execute arbitrary commands via the uniconverter14_64bit_setup_full14204.exe file. | |
| Modificada | Crítica (9.8) | 0.78% | — | Jenkins Convert TO Pipeline | 2/4/2023 | 17/6/2026 | Jenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build Environment, Build Steps, and Post-build Actions to the equivalent Pipeline step invocations, allowing attackers able to configure Freestyle projects to prepare a crafted configuration that injects… | |
| Modificada | Alta (8.8) | 0.64% | — | Jenkins Convert TO Pipeline | 2/4/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers to create a Pipeline based on a Freestyle project, potentially leading to remote code execution (RCE). | |
| Modificada | Media (5.4) | 0.53% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 16/1/2023 | 17/6/2026 | The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as… | |
| Modificada | Crítica (9.8) | 1.2% | — | Avs4you AVS Audio Converter | 28/11/2022 | 17/6/2026 | AVS Audio Converter 10.3 is vulnerable to Buffer Overflow. |