Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

307 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)2.1%—Kirisun Fujian KelixunAI23/5/202517/6/2026
A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the file /app/fax/fax_view.php of the component Filename Handler. The manipulation of the argument fax_file leads to os command injection. It is possible to initiate the attack remotely. The exploit has…
AplazadaAlta (7.1)0.15%—Felixtz Modern-pollsAI24/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in felixtz Modern Polls modern-polls allows Stored XSS.This issue affects Modern Polls: from n/a through <= 1.0.10.
AplazadaMedia (6.3)0.46%—Perforce Helix ALMAI15/4/202517/6/2026
Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists.
AnalizadaMedia (6.3)0.16%—Felixker Wordpress/plugin Upgrade Time OUT Plugin9/4/202517/6/2026
The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
AplazadaMedia (6.9)0.46%—Mingyuefusu TushuguanlixitongAI24/3/202517/6/2026
A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. Affected by this vulnerability is the function doFilter of the file /admin/ of the component Backend. The manipulation of the argument Request leads to improper access…
AnalizadaMedia (5.6)0.57%—Apache Felix Http Webconsole Plugin12/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issue affects Apache Felix HTTP Webconsole Plugin: from Version 1.X through 1.2.0. Users are recommended to upgrade to version 1.2.2, which fixes the issue.
AnalizadaMedia (6.1)0.69%—Apache Felix Webconsole10/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8. Users are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the issue.
AplazadaMedia (5.4)0.37%—Trellix Epolicy OrchestratorAI20/12/202417/6/2026
Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a remote authenticated attacker to craft requests causing arbitrary content to be injected into the response when accessing the epolicy Orchestrator.
AplazadaMedia (6.5)0.41%—Devfelixmoira Poll BuilderAI13/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devfelixmoira Poll Builder poll-builder allows Stored XSS.This issue affects Poll Builder: from n/a through <= 1.3.5.
AplazadaAlta (8.2)0.59%—Heolixfy Flexible Woocommerce Checkout Field EditorAI9/12/202417/6/2026
Missing Authorization vulnerability in heoLixfy Flexible Woocommerce Checkout Field Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flexible Woocommerce Checkout Field Editor: from n/a through 2.0.1.
AplazadaMedia (5.4)0.34%—Felixwelberg Extended Post StatusAI9/12/202417/6/2026
Missing Authorization vulnerability in Felix Welberg Extended Post Status allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extended Post Status: from n/a through 1.0.19.
AplazadaMedia (6.1)0.37%—FlixitaAI6/12/202417/6/2026
The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.82 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if…
AnalizadaCrítica (9.8)2.5%—Trellix Enterprise Security Manager29/11/202417/6/2026
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.
AnalizadaAlta (8.2)0.44%—Trellix Enterprise Security Manager29/11/202417/6/2026
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and lack of authentication for accessing internal API endpoints.
AplazadaAlta (8.7)0.49%—Perforce Helix CoreAI11/11/202417/6/2026
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek.
AplazadaAlta (8.7)0.49%—Perforce Helix CoreAI11/11/202417/6/2026
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was identified. Reported by Karol Więsek.
AplazadaAlta (8.7)0.49%—Perforce Helix CoreAI11/11/202417/6/2026
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation function was identified. Reported by Karol Więsek.
AplazadaCrítica (9.8)0.42%—Fujian Kelixin Communication Command AND Dispatch PlatformAI8/10/202417/6/2026
Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php.
AnalizadaAlta (8.7)0.69%—Netflix E2nest27/9/202417/6/2026
A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a
AplazadaMedia (5.8)0.20%—Perforce Helix CoreAI25/9/202417/6/2026
In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument injection was identified.
AnalizadaMedia (5.3)0.22%—Devfelixmoira Limit Login Attempts Plus19/9/202417/6/2026
The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header…
AnalizadaAlta (7.5)0.38%—Trellix Intrusion Prevention System Manager5/9/202417/6/2026
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
AnalizadaMedia (5.3)0.39%—Trellix Intrusion Prevention System Manager5/9/202417/6/2026
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly
AnalizadaAlta (7.5)0.73%—Apache Helix20/8/202417/6/2026
** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies. This issue affects Apache Helix Front (UI): all versions. As this project is retired, we do not plan to release a version that fixes this…
AplazadaCrítica (9.8)0.77%—Kirisun Fujian KelixunAI9/7/202417/6/2026
Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php.
Orbitaley — Vulnerabilidades