Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

332 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.60%—Wpexpertdeveloper WP Private Content Plus28/2/202417/6/2026
The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 3.6. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view…
ModificadaMedia (5.4)0.31%—Myagileprivacy MY Agile Privacy10/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyAgilePrivacy My Agile Privacy – The only GDPR solution for WordPress that you can truly trust allows Stored XSS.This issue affects My Agile Privacy – The only GDPR solution for WordPress that you can truly trust:…
ModificadaAlta (7.5)33%—Cisco Secure EndpointCisco Secure Endpoint Private CloudFedoraproject Fedora7/2/202417/6/2026
A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker…
ModificadaMedia (5.4)0.29%—Epiph Embed Privacy1/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Epiphyt Embed Privacy allows Stored XSS.This issue affects Embed Privacy: from n/a through 1.8.0.
ModificadaMedia (5.4)0.31%—Michielvaneerd Private Google Calendars8/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google Calendars: from n/a through 20231125.
ModificadaAlta (7.5)0.58%—Priva TOP Control Suite2/1/202417/6/2026
The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate the login credentials for the Priva TopControll suite.
ModificadaMedia (5.4)0.42%—Qualys Private Cloud Platform8/12/202317/6/2026
A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details.
ModificadaMedia (6.5)1.7%—M-privacy Mprivacy-toolsM-privacy Tightgatevnc22/11/202317/6/2026
In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, a Directory Traversal in the print function of the VNC service allows authenticated attackers (with access to a VNC session) to automatically transfer malicious PDF documents by moving them into the .spool directory, and then sending a signal to the…
ModificadaAlta (8.8)1.4%—M-privacy Mprivacy-toolsM-privacy Rsbac-policy-tgproM-privacy Tightgatevnc22/11/202317/6/2026
In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control of their desktop, including the ability…
ModificadaMedia (4.4)0.17%—Cisco Secure EndpointCisco Secure Endpoint Private Cloud22/11/202317/6/2026
A vulnerability in the endpoint software of Cisco Secure Endpoint for Windows could allow an authenticated, local attacker to evade endpoint protection within a limited time window. This vulnerability is due to a timing issue that occurs between various software components. An attacker could exploit this vulnerability…
ModificadaMedia (5.4)0.53%—Epiph Embed Privacy20/11/202317/6/2026
The `Embed Privacy` plugin for WordPress that prevents the loading of embedded external content is vulnerable to Stored Cross-Site Scripting via `embed_privacy_opt_out` shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
ModificadaMedia (4.3)0.49%—Userprivatefiles Wordpress File Sharing Plugin31/10/202317/6/2026
The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced
ModificadaAlta (7.5)0.46%—Tencent Enterprise Wechat Privatization12/10/202317/6/2026
There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000.
ModificadaMedia (4.8)0.99%💥 PoCUserprivatefiles Wordpress File Sharing Plugin5/9/202317/6/2026
The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,…
ModificadaAlta (7.5)3.4%—Cisco Secure EndpointCisco Secure Endpoint Private Cloud18/8/202317/6/2026
A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error in the memory management of an affected device. An attacker could exploit this vulnerability by submitting a…
ModificadaAlta (7.5)1.2%—Cisco Secure EndpointCisco Secure Endpoint Private CloudFedoraproject Fedora16/8/202317/6/2026
A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may…
ModificadaCrítica (9.1)0.95%—Cisco Intersight Private Virtual Appliance16/8/202317/6/2026
Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to exploit these vulnerabilities. These vulnerabilities are due…
ModificadaCrítica (9.1)0.95%—Cisco Intersight Private Virtual Appliance16/8/202317/6/2026
Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to exploit these vulnerabilities. These vulnerabilities are due…
ModificadaAlta (8.3)0.49%—Troplo Privateuploader14/8/202317/6/2026
PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did not correctly verify whether the user was an administrator (High Level) or moderator (Low Level) causing the request to continue processing. The response would be a 403…
ModificadaAlta (8.8)0.33%—Johnkolbert Absolute Privacy10/8/202317/6/2026
The Absolute Privacy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing nonce validation on the 'abpr_profileShortcode' function. This makes it possible for unauthenticated attackers to change user email and password via a forged request…
ModificadaMedia (5.4)0.56%—Okta Imprivata Privileged Access Management20/7/202317/6/2026
Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS.
ModificadaMedia (4.3)0.38%—Wpexpertdeveloper WP Private Content Plus1/7/202317/6/2026
The WP Private Content Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. This is due to missing or incorrect nonce validation on the save_groups() function. This makes it possible for unauthenticated attackers to add new group members via a forged request…
ModificadaAlta (7.4)0.31%—Westerndigital Sandisk Privateaccess24/3/202317/6/2026
SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data.
ModificadaMedia (5.3)7.0%💥 PoCCisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security1/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.…
ModificadaCrítica (9.8)29%—Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+11/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability…
Orbitaley — Vulnerabilidades