Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
132 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 16% | 💥 Exploit | Supsystic Contact Form | 5/5/2021 | 17/6/2026 | The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 18% | 💥 Exploit | Supsystic Popup | 5/5/2021 | 17/6/2026 | The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 18% | 💥 Exploit | Supsystic Ultimate Maps | 5/5/2021 | 17/6/2026 | The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue | |
| Modificada | Alta (7.5) | 1.1% | — | Synopsys Hub-rest-api-python | 6/11/2020 | 17/6/2026 | Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases. | |
| Modificada | Alta (8.8) | 0.69% | — | Supsystic Data Tables Generator | 23/4/2020 | 17/6/2026 | The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS. | |
| Modificada | Alta (8.8) | 1.0% | — | Supsystic Data Tables Generator | 23/4/2020 | 17/6/2026 | The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions. | |
| Modificada | Alta (7.3) | 1.7% | — | Pricing Table BY Supsystic | 23/3/2020 | 17/6/2026 | An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table. | |
| Modificada | Alta (8.8) | 0.68% | — | Pricing Table BY Supsystic | 25/2/2020 | 17/6/2026 | An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF. | |
| Modificada | Media (6.1) | 0.92% | — | Pricing Table BY Supsystic | 25/2/2020 | 17/6/2026 | An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS. | |
| Modificada | Alta (8.8) | 0.69% | — | Supsystic Photo Gallery | 22/8/2019 | 17/6/2026 | The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF. | |
| Modificada | Alta (8.8) | 0.68% | — | Supsystic Popup | 20/8/2019 | 17/6/2026 | The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF. | |
| Modificada | Alta (8.8) | 0.65% | — | Newsletter BY Supsystic | 14/8/2019 | 17/6/2026 | The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF. | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Alta (8.8) | 1.9% | — | Inteno Iopsys | 11/4/2019 | 17/6/2026 | An issue was discovered in the firewall3 component in Inteno IOPSYS 1.0 through 3.16. The attacker must make a JSON-RPC method call to add a firewall rule as an "include" and point the "path" argument to a malicious script or binary. This gets executed as root when the firewall changes are committed. | |
| Modificada | Crítica (9.8) | 1.2% | — | Helpsystems Boks | 8/2/2019 | 17/6/2026 | A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation. | |
| Modificada | Alta (7.8) | 1.5% | 💥 Exploit | Intenogroup Iopsys Firmware | 31/7/2018 | 17/6/2026 | read_tmp and write_tmp in Inteno IOPSYS allow attackers to gain privileges after writing to /tmp/etc/smb.conf because /var is a symlink to /tmp. | |
| Modificada | Media (6.5) | 0.99% | — | Jenkins Synopsys Detect | 5/6/2018 | 17/6/2026 | A exposure of sensitive information vulnerability exists in Jenkins Black Duck Detect Plugin 1.4.0 and older in DetectPostBuildStepDescriptor.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing… | |
| Modificada | Alta (8.8) | 10% | 💥 Exploit | Intenogroup Iopsys Firmware | 16/5/2018 | 17/6/2026 | p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via requests on TCP port 9100. | |
| Modificada | Alta (8.8) | 11% | 💥 Exploit | Intenogroup Iopsys | 4/1/2018 | 17/6/2026 | Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located on an SMB share. This issue existed because the /etc/uci-defaults directory was… | |
| Modificada | Media (6.8) | 1.3% | — | Saskia Bruckner Saskias Shopsystem | 10/3/2010 | 16/6/2026 | Directory traversal vulnerability in content.php in Saskia's Shopsystem beta1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter. | |
| Modificada | Media (6.8) | 4.4% | 💥 Exploit | Shopsystem-forum K&S Shopsoftware | 29/4/2009 | 16/6/2026 | Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/upload/. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Powie Psys | 28/11/2008 | 16/6/2026 | SQL injection vulnerability in index.php in pSys 0.7.0 alpha allows remote attackers to execute arbitrary SQL commands via the shownews parameter. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Powergap Shopsystem | 10/8/2008 | 16/6/2026 | SQL injection vulnerability in s03.php in Powergap Shopsystem, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the ag parameter. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Powie Psys | 10/7/2008 | 16/6/2026 | SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showid parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Phpsysinfo | 30/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in phpSysInfo 2.5.4-dev and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. |