Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.60% | — | Wpexpertdeveloper WP Private Content Plus | 28/2/2024 | 17/6/2026 | The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 3.6. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view… | |
| Modificada | Media (5.4) | 0.31% | — | Myagileprivacy MY Agile Privacy | 10/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyAgilePrivacy My Agile Privacy – The only GDPR solution for WordPress that you can truly trust allows Stored XSS.This issue affects My Agile Privacy – The only GDPR solution for WordPress that you can truly trust:… | |
| Modificada | Alta (7.5) | 33% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudFedoraproject Fedora | 7/2/2024 | 17/6/2026 | A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker… | |
| Modificada | Media (5.4) | 0.29% | — | Epiph Embed Privacy | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Epiphyt Embed Privacy allows Stored XSS.This issue affects Embed Privacy: from n/a through 1.8.0. | |
| Modificada | Media (5.4) | 0.31% | — | Michielvaneerd Private Google Calendars | 8/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google Calendars: from n/a through 20231125. | |
| Modificada | Alta (7.5) | 0.58% | — | Priva TOP Control Suite | 2/1/2024 | 17/6/2026 | The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate the login credentials for the Priva TopControll suite. | |
| Modificada | Media (5.4) | 0.42% | — | Qualys Private Cloud Platform | 8/12/2023 | 17/6/2026 | A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details. | |
| Modificada | Media (6.5) | 1.7% | — | M-privacy Mprivacy-toolsM-privacy Tightgatevnc | 22/11/2023 | 17/6/2026 | In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, a Directory Traversal in the print function of the VNC service allows authenticated attackers (with access to a VNC session) to automatically transfer malicious PDF documents by moving them into the .spool directory, and then sending a signal to the… | |
| Modificada | Alta (8.8) | 1.4% | — | M-privacy Mprivacy-toolsM-privacy Rsbac-policy-tgproM-privacy Tightgatevnc | 22/11/2023 | 17/6/2026 | In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control of their desktop, including the ability… | |
| Modificada | Media (4.4) | 0.17% | — | Cisco Secure EndpointCisco Secure Endpoint Private Cloud | 22/11/2023 | 17/6/2026 | A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authenticated, local attacker to evade endpoint protection within a limited time window. This vulnerability is due to a timing issue that occurs between various software components. An attacker could exploit this vulnerability… | |
| Modificada | Media (5.4) | 0.53% | — | Epiph Embed Privacy | 20/11/2023 | 17/6/2026 | The `Embed Privacy` plugin for WordPress that prevents the loading of embedded external content is vulnerable to Stored Cross-Site Scripting via `embed_privacy_opt_out` shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Modificada | Media (4.3) | 0.49% | — | Userprivatefiles Wordpress File Sharing Plugin | 31/10/2023 | 17/6/2026 | The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced | |
| Modificada | Alta (7.5) | 0.46% | — | Tencent Enterprise Wechat Privatization | 12/10/2023 | 17/6/2026 | There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000. | |
| Modificada | Media (4.8) | 0.99% | 💥 PoC | Userprivatefiles Wordpress File Sharing Plugin | 5/9/2023 | 17/6/2026 | The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Modificada | Alta (7.5) | 3.4% | — | Cisco Secure EndpointCisco Secure Endpoint Private Cloud | 18/8/2023 | 17/6/2026 | A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error in the memory management of an affected device. An attacker could exploit this vulnerability by submitting a… | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudFedoraproject Fedora | 16/8/2023 | 17/6/2026 | A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may… | |
| Modificada | Crítica (9.1) | 0.95% | — | Cisco Intersight Private Virtual Appliance | 16/8/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to exploit these vulnerabilities. These vulnerabilities are due… | |
| Modificada | Crítica (9.1) | 0.95% | — | Cisco Intersight Private Virtual Appliance | 16/8/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to exploit these vulnerabilities. These vulnerabilities are due… | |
| Modificada | Alta (8.3) | 0.49% | — | Troplo Privateuploader | 14/8/2023 | 17/6/2026 | PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did not correctly verify whether the user was an administrator (High Level) or moderator (Low Level) causing the request to continue processing. The response would be a 403… | |
| Modificada | Alta (8.8) | 0.33% | — | Johnkolbert Absolute Privacy | 10/8/2023 | 17/6/2026 | The Absolute Privacy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing nonce validation on the 'abpr_profileShortcode' function. This makes it possible for unauthenticated attackers to change user email and password via a forged request… | |
| Modificada | Media (5.4) | 0.56% | — | Okta Imprivata Privileged Access Management | 20/7/2023 | 17/6/2026 | Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS. | |
| Modificada | Media (4.3) | 0.38% | — | Wpexpertdeveloper WP Private Content Plus | 1/7/2023 | 17/6/2026 | The WP Private Content Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. This is due to missing or incorrect nonce validation on the save_groups() function. This makes it possible for unauthenticated attackers to add new group members via a forged request… | |
| Modificada | Alta (7.4) | 0.31% | — | Westerndigital Sandisk Privateaccess | 24/3/2023 | 17/6/2026 | SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data. | |
| Modificada | Media (5.3) | 7.0% | 💥 PoC | Cisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.… | |
| Modificada | Crítica (9.8) | 29% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+1 | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability… |