Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.49% | — | Microweber | 8/12/2023 | 17/6/2026 | Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0. | |
| Modificada | Media (6.5) | 0.49% | — | Microweber | 7/12/2023 | 17/6/2026 | Business Logic Errors in GitHub repository microweber/microweber prior to 2.0. | |
| Modificada | Alta (8.8) | 2.4% | 💥 PoC | Microweber | 30/11/2023 | 17/6/2026 | File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component. | |
| Modificada | Alta (8.8) | 1.2% | — | Atlassian Crowd | 21/11/2023 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.6 of Crowd Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.0, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to… | |
| Modificada | Media (6.1) | 0.37% | — | Themeum WP Crowdfunding | 14/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themeum WP Crowdfunding plugin <= 2.1.6 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Thecrowned Post PAY Counter | 14/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Stefano Ottolenghi Post Pay Counter plugin <= 2.784 versions. | |
| Modificada | Media (5.4) | 0.51% | — | Microweber | 8/11/2023 | 17/6/2026 | Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality. | |
| Modificada | Media (4.3) | 0.39% | — | Microweber | 7/11/2023 | 17/6/2026 | Improper Access Control in GitHub repository microweber/microweber prior to 2.0. | |
| Modificada | Media (4.8) | 0.44% | — | Microweber | 31/10/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0. | |
| Modificada | Alta (7.5) | 0.65% | — | Microweber | 30/9/2023 | 17/6/2026 | Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0. | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Microweber | 28/9/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0. | |
| Modificada | Media (4.8) | 0.40% | — | Pdfcrowd Save AS PDF | 27/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd plugin <= 2.16.0 versions. | |
| Modificada | Media (4.8) | 0.40% | — | Pdfcrowd Save AS Image | 27/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pdfcrowd Save as Image plugin by Pdfcrowd plugin <= 2.16.0 versions. | |
| Modificada | Media (6.1) | 0.52% | — | Crowcpp Crow | 12/9/2023 | 17/6/2026 | All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values. Header values are not properly sanitized against CRLF Injection in the set_header and add_header functions. An attacker can add the \r\n (carriage return line feeds) characters to end… | |
| Modificada | Media (5.4) | 0.35% | — | Microweber | 7/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 2.0. | |
| Modificada | Media (5.3) | 0.59% | — | Trianglemicroworks Scada Data Gateway | 7/6/2023 | 17/6/2026 | On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker… | |
| Modificada | Crítica (9.8) | 0.71% | — | Trianglemicroworks Scada Data Gateway | 7/6/2023 | 17/6/2026 | On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to the SCADA Data Gateway to perform unrestricted memory reads.An unauthenticated user can use this format string vulnerability to repeatedly… | |
| Modificada | Media (6.5) | 0.50% | — | Microweber | 22/4/2023 | 17/6/2026 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4. | |
| Modificada | Alta (8.8) | 0.71% | — | Microweber | 22/4/2023 | 17/6/2026 | Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4. | |
| Modificada | Media (4.8) | 0.48% | — | Microweber | 13/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository microweber/microweber prior to 1.3.3. | |
| Modificada | Media (5.4) | 0.49% | — | Microweber | 5/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3. | |
| Modificada | Crítica (9.8) | 1.8% | — | Microweber | 5/4/2023 | 17/6/2026 | Command Injection in GitHub repository microweber/microweber prior to 1.3.3. | |
| Modificada | Media (4.8) | 0.43% | — | Microweber | 28/2/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3. | |
| Modificada | Media (6.1) | 0.63% | — | Microweber | 21/2/2023 | 17/6/2026 | Microweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. A fix was attempted in versions 1.2.9 and… | |
| Modificada | Media (5.4) | 0.52% | — | Microweber | 1/2/2023 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository microweber/microweber prior to 1.3.2. |