Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

132 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)16%💥 ExploitSupsystic Contact Form5/5/202117/6/2026
The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
ModificadaMedia (6.1)18%💥 ExploitSupsystic Popup5/5/202117/6/2026
The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
ModificadaMedia (6.1)18%💥 ExploitSupsystic Ultimate Maps5/5/202117/6/2026
The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
ModificadaAlta (7.5)1.1%—Synopsys Hub-rest-api-python6/11/202017/6/2026
Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.
ModificadaAlta (8.8)0.69%—Supsystic Data Tables Generator23/4/202017/6/2026
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.
ModificadaAlta (8.8)1.0%—Supsystic Data Tables Generator23/4/202017/6/2026
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
ModificadaAlta (7.3)1.7%—Pricing Table BY Supsystic23/3/202017/6/2026
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table.
ModificadaAlta (8.8)0.68%—Pricing Table BY Supsystic25/2/202017/6/2026
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.
ModificadaMedia (6.1)0.92%—Pricing Table BY Supsystic25/2/202017/6/2026
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.
ModificadaAlta (8.8)0.69%—Supsystic Photo Gallery22/8/201917/6/2026
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
ModificadaAlta (8.8)0.68%—Supsystic Popup20/8/201917/6/2026
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
ModificadaAlta (8.8)0.65%—Newsletter BY Supsystic14/8/201917/6/2026
The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaAlta (8.8)1.9%—Inteno Iopsys11/4/201917/6/2026
An issue was discovered in the firewall3 component in Inteno IOPSYS 1.0 through 3.16. The attacker must make a JSON-RPC method call to add a firewall rule as an "include" and point the "path" argument to a malicious script or binary. This gets executed as root when the firewall changes are committed.
ModificadaCrítica (9.8)1.2%—Helpsystems Boks8/2/201917/6/2026
A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation.
ModificadaAlta (7.8)1.5%💥 ExploitIntenogroup Iopsys Firmware31/7/201817/6/2026
read_tmp and write_tmp in Inteno IOPSYS allow attackers to gain privileges after writing to /tmp/etc/smb.conf because /var is a symlink to /tmp.
ModificadaMedia (6.5)0.99%—Jenkins Synopsys Detect5/6/201817/6/2026
A exposure of sensitive information vulnerability exists in Jenkins Black Duck Detect Plugin 1.4.0 and older in DetectPostBuildStepDescriptor.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing…
ModificadaAlta (8.8)10%💥 ExploitIntenogroup Iopsys Firmware16/5/201817/6/2026
p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via requests on TCP port 9100.
ModificadaAlta (8.8)11%💥 ExploitIntenogroup Iopsys4/1/201817/6/2026
Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located on an SMB share. This issue existed because the /etc/uci-defaults directory was…
ModificadaMedia (6.8)1.3%—Saskia Bruckner Saskias Shopsystem10/3/201016/6/2026
Directory traversal vulnerability in content.php in Saskia's Shopsystem beta1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter.
ModificadaMedia (6.8)4.4%💥 ExploitShopsystem-forum K&S Shopsoftware29/4/200916/6/2026
Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/upload/.
ModificadaAlta (7.5)1.00%💥 ExploitPowie Psys28/11/200816/6/2026
SQL injection vulnerability in index.php in pSys 0.7.0 alpha allows remote attackers to execute arbitrary SQL commands via the shownews parameter.
ModificadaMedia (6.8)0.91%💥 ExploitPowergap Shopsystem10/8/200816/6/2026
SQL injection vulnerability in s03.php in Powergap Shopsystem, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the ag parameter.
ModificadaMedia (6.8)0.91%💥 ExploitPowie Psys10/7/200816/6/2026
SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showid parameter.
ModificadaMedia (4.3)1.3%—Phpsysinfo30/7/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.php in phpSysInfo 2.5.4-dev and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
Orbitaley — Vulnerabilidades