Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.7%—Bitdefender Gravityzone16/12/202117/6/2026
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Bitdefender GravityZone versions prior to 3.3.8.272
ModificadaCrítica (10)2.1%—Bitdefender Endpoint Security ToolsBitdefender Gravityzone24/11/202117/6/2026
Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.6.27.390;…
ModificadaAlta (7.5)1.3%—Bitdefender Endpoint Security ToolsBitdefender Gravityzone24/11/202117/6/2026
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows an attacker to use the Endpoint Protection relay as a proxy for any remote host. This issue affects: Bitdefender Endpoint Security Tools versions prior to 6.6.27.390; versions prior to 7.1.2.33.…
ModificadaAlta (7.5)1.3%—Bitdefender Endpoint Security ToolsBitdefender Gravityzone24/11/202117/6/2026
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Endpoint Security Tools versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender GravityZone…
ModificadaMedia (6.1)0.35%—Bitdefender Gravityzone9/11/202117/6/2026
Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows allows a local attacker to cause a denial of service. This issue affects: Bitdefender GravityZone version 7.1.2.33 and prior versions.
ModificadaCrítica (9.8)1.1%—Bitdefender Gravityzone28/10/202117/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects: Bitdefender GravityZone versions prior to 3.3.8.249.
ModificadaMedia (5.5)0.64%—Creolabs Gravity20/9/202117/6/2026
An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function list_iterator_next() located in gravity_core.c. It allows an attacker to cause Denial of Service.
ModificadaAlta (7.8)0.76%—Creolabs Gravity20/9/202117/6/2026
An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function ircode_register_pop_context_protect() located in gravity_ircode.c. It allows an attacker to cause Denial of Service.
ModificadaMedia (5.5)0.64%—Creolabs Gravity20/9/202117/6/2026
An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function gravity_string_to_value() located in gravity_value.c. It allows an attacker to cause Denial of Service.
ModificadaMedia (5.5)0.64%—Creolabs Gravity20/9/202117/6/2026
An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function ircode_add_check() located in gravity_ircode.c. It allows an attacker to cause Denial of Service.
ModificadaAlta (7.8)1.1%—Creolabs Gravity20/9/202117/6/2026
An issue was discovered in gravity through 0.8.1. A heap-buffer-overflow exists in the function gnode_function_add_upvalue located in gravity_ast.c. It allows an attacker to cause code Execution.
ModificadaAlta (7.8)0.21%—Bitdefender Gravityzone Business Security18/5/202117/6/2026
Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to load a third party DLL to elevate privileges. This issue affects Bitdefender GravityZone Business Security versions prior to 6.6.23.329.
ModificadaMedia (5.4)0.78%—Rocketgenius Gravityforms20/1/202117/6/2026
A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via a textarea field. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
ModificadaMedia (5.4)0.78%—Rocketgenius Gravityforms20/1/202117/6/2026
Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
ModificadaMedia (4.8)0.80%—Rocketgenius Gravityforms20/1/202117/6/2026
A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via the import of a GF form. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
ModificadaAlta (7.5)1.8%—Rocketgenius Gravityforms2/6/202017/6/2026
common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.
ModificadaMedia (6.1)3.9%—Katz Infusionsoft Gravity Forms27/12/201917/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2) contactId, or (3) campaignId parameter.
ModificadaMedia (6.1)0.92%—Mediaburst Gravity Forms13/8/201917/6/2026
The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS.
ModificadaCrítica (9.8)1.5%—Bitdefender Gravityzone30/10/201817/6/2026
Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via unspecified vectors.
ModificadaCrítica (9.8)4.3%—Bitdefender Gravityzone24/10/201817/6/2026
The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitrary code by changing the filename while leaving the file's digital signature unchanged.
ModificadaAlta (7.5)1.5%—Creolabs Gravity9/7/201817/6/2026
Gravity before 0.5.1 does not support a maximum recursion depth.
ModificadaCrítica (9.8)4.7%—Ajax Upload FOR Gravity Forms Project Ajax Upload FOR Gravity Forms8/1/201817/6/2026
Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under wp-content/uploads/gravity_forms.
ModificadaCrítica (9.8)3.8%—Creolabs Gravity2/1/201817/6/2026
Creolabs Gravity 1.0 contains a stack based buffer overflow in the operator_string_add function, resulting in remote code execution.
ModificadaMedia (6.1)0.95%—Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+420/12/201717/6/2026
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,…
ModificadaCrítica (9.8)2.5%—Creolabs Gravity17/11/201717/6/2026
Creolabs Gravity Version: 1.0 Heap Overflow Potential Code Execution. By creating a large loop whiling pushing data to a buffer, we can break out of the bounds checking of that buffer. When list.join is called on the data it will read past a buffer resulting in a Heap-Buffer-Overflow.