Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.56% | — | Send PDF FOR Contact Form 7 Project Send PDF FOR Contact Form 7 | 6/2/2023 | 17/6/2026 | The Send PDF for Contact Form 7 WordPress plugin before 0.9.9.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege… | |
| Modificada | Media (4.8) | 0.68% | — | Projectsend | 1/2/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository projectsend/projectsend prior to r1606. | |
| Modificada | Crítica (9.8) | 1.5% | — | HP Color Laserjet Cm4540 MFP Cc419a FirmwareHP Color Laserjet Cm4540 MFP Cc420a FirmwareHP Color Laserjet Cm4540 MFP Cc421a FirmwareHP Color Laserjet Cm5525 MFP Ce707a Firmware+2696 | 12/12/2022 | 17/6/2026 | Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR. | |
| Modificada | Media (5.7) | 1.1% | — | Projectsend | 27/6/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_download. The manipulation of the argument client/file leads to information disclosure. It is possible to initiate the attack remotely. | |
| Modificada | Alta (7.4) | 2.0% | — | F5 NginxSendmailVsftpd Project VsftpdFedoraproject Fedora+1 | 23/3/2022 | 17/6/2026 | ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to… | |
| Modificada | Media (6.5) | 0.68% | — | Sysend.js Project Sysend.js | 14/3/2022 | 17/6/2026 | sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that use cross-origin communication may have their communications intercepted. Impact is limited by the communication occurring in the same browser. This issue has been patched in sysend.js version 1.10.0.… | |
| Modificada | Alta (8.8) | 1.5% | — | Talariax Sendquick Alert Plus Server Admin | 14/11/2021 | 17/6/2026 | A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers to obtain sensitive information via a Roster Time to Roster Management. | |
| Modificada | Alta (8.8) | 1.7% | — | AIR Sender Project AIR Sender | 22/10/2021 | 17/6/2026 | Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted file. | |
| Modificada | Media (5.4) | 0.64% | — | Projectsend | 11/10/2021 | 17/6/2026 | Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds() function. A low privilege user can call this function through process.php file and execute scripting code. | |
| Modificada | Crítica (9.8) | 2.4% | — | Projectsend | 11/10/2021 | 17/6/2026 | Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upload/files/ folder. | |
| Modificada | Media (6.5) | 1.4% | — | Projectsend | 11/10/2021 | 17/6/2026 | Projectsend version r1295 is affected by a directory traversal vulnerability. A user with Uploader role can add value `2` for `chunks` parameter to bypass `fileName` sanitization. | |
| Modificada | Alta (8.1) | 0.95% | — | Projectsend | 11/10/2021 | 17/6/2026 | Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can download and edit all files of users in application. | |
| Modificada | Alta (8.8) | 0.47% | — | Barco Mirrorop Windows Sender | 7/9/2021 | 17/6/2026 | Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achieve remote code execution on any computer that tries to update Windows Sender due to the fact that the upgrade mechanism is not secured (is not protected with TLS). | |
| Modificada | Media (4.3) | 0.70% | — | Sendgrid | 30/7/2021 | 17/6/2026 | The SendGrid WordPress plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/lib/class-sendgrid-statistics.php file which allows authenticated users to export statistic for a WordPress multi-site main site, in versions up to and including 1.11.8. | |
| Modificada | Alta (7.8) | 0.44% | — | Barco Mirrorop Windows Sender | 21/7/2021 | 17/6/2026 | An issue was discovered in Barco MirrorOp Windows Sender before 2.5.4.70. An attacker in the local network is able to achieve Remote Code Execution (with user privileges of the local user) on any device that tries to connect to a WePresent presentation system. | |
| Modificada | Media (6.6) | 1.3% | — | Sendit Project Sendit | 14/6/2021 | 17/6/2026 | The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL statement, therefore leading to Blind SQL Injection. | |
| Modificada | Alta (7.5) | 2.4% | 💥 PoC | Projectsend | 26/1/2021 | 9/7/2026 | reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter). | |
| Modificada | Crítica (9.8) | 4.2% | — | Node-key-sender Project Node-key-sender | 2/4/2020 | 17/6/2026 | node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function. | |
| Modificada | Alta (8.8) | 1.9% | — | Pressified Sendpress | 26/9/2019 | 17/6/2026 | The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Bestwebsoft Sender | 21/8/2019 | 17/6/2026 | The sender plugin before 1.2.1 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.5) | 0.75% | — | Send-anywhere Send Anywhere | 22/7/2019 | 17/6/2026 | The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user via /data/data/com.estmob.android.sendanywhere/shared_prefs/sendanywhere_device.xml. | |
| Modificada | Alta (8.8) | 1.3% | — | Projectsend | 22/5/2019 | 17/6/2026 | CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel. | |
| Modificada | Media (6.1) | 0.80% | — | Projectsend | 22/5/2019 | 17/6/2026 | An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page. | |
| Modificada | Media (6.1) | 1.2% | — | Projectsend | 26/4/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Alta (7.5) | 1.1% | — | Projectsend | 26/4/2019 | 17/6/2026 | ProjectSend before r1070 writes user passwords to the server logs. |