Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

237 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.56%—Send PDF FOR Contact Form 7 Project Send PDF FOR Contact Form 76/2/202317/6/2026
The Send PDF for Contact Form 7 WordPress plugin before 0.9.9.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege…
ModificadaMedia (4.8)0.68%—Projectsend1/2/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository projectsend/projectsend prior to r1606.
ModificadaCrítica (9.8)1.5%—HP Color Laserjet Cm4540 MFP Cc419a FirmwareHP Color Laserjet Cm4540 MFP Cc420a FirmwareHP Color Laserjet Cm4540 MFP Cc421a FirmwareHP Color Laserjet Cm5525 MFP Ce707a Firmware+269612/12/202217/6/2026
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.
ModificadaMedia (5.7)1.1%—Projectsend27/6/202217/6/2026
A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_download. The manipulation of the argument client/file leads to information disclosure. It is possible to initiate the attack remotely.
ModificadaAlta (7.4)2.0%—F5 NginxSendmailVsftpd Project VsftpdFedoraproject Fedora+123/3/202217/6/2026
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to…
ModificadaMedia (6.5)0.68%—Sysend.js Project Sysend.js14/3/202217/6/2026
sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that use cross-origin communication may have their communications intercepted. Impact is limited by the communication occurring in the same browser. This issue has been patched in sysend.js version 1.10.0.…
ModificadaAlta (8.8)1.5%—Talariax Sendquick Alert Plus Server Admin14/11/202117/6/2026
A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers to obtain sensitive information via a Roster Time to Roster Management.
ModificadaAlta (8.8)1.7%—AIR Sender Project AIR Sender22/10/202117/6/2026
Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted file.
ModificadaMedia (5.4)0.64%—Projectsend11/10/202117/6/2026
Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds() function. A low privilege user can call this function through process.php file and execute scripting code.
ModificadaCrítica (9.8)2.4%—Projectsend11/10/202117/6/2026
Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upload/files/ folder.
ModificadaMedia (6.5)1.4%—Projectsend11/10/202117/6/2026
Projectsend version r1295 is affected by a directory traversal vulnerability. A user with Uploader role can add value `2` for `chunks` parameter to bypass `fileName` sanitization.
ModificadaAlta (8.1)0.95%—Projectsend11/10/202117/6/2026
Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can download and edit all files of users in application.
ModificadaAlta (8.8)0.47%—Barco Mirrorop Windows Sender7/9/202117/6/2026
Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achieve remote code execution on any computer that tries to update Windows Sender due to the fact that the upgrade mechanism is not secured (is not protected with TLS).
ModificadaMedia (4.3)0.70%—Sendgrid30/7/202117/6/2026
The SendGrid WordPress plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/lib/class-sendgrid-statistics.php file which allows authenticated users to export statistic for a WordPress multi-site main site, in versions up to and including 1.11.8.
ModificadaAlta (7.8)0.44%—Barco Mirrorop Windows Sender21/7/202117/6/2026
An issue was discovered in Barco MirrorOp Windows Sender before 2.5.4.70. An attacker in the local network is able to achieve Remote Code Execution (with user privileges of the local user) on any device that tries to connect to a WePresent presentation system.
ModificadaMedia (6.6)1.3%—Sendit Project Sendit14/6/202117/6/2026
The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL statement, therefore leading to Blind SQL Injection.
ModificadaAlta (7.5)2.4%💥 PoCProjectsend26/1/20219/7/2026
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).
ModificadaCrítica (9.8)4.2%—Node-key-sender Project Node-key-sender2/4/202017/6/2026
node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.
ModificadaAlta (8.8)1.9%—Pressified Sendpress26/9/201917/6/2026
The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter.
ModificadaMedia (6.1)1.4%💥 ExploitBestwebsoft Sender21/8/201917/6/2026
The sender plugin before 1.2.1 for WordPress has multiple XSS issues.
ModificadaMedia (6.5)0.75%—Send-anywhere Send Anywhere22/7/201917/6/2026
The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user via /data/data/com.estmob.android.sendanywhere/shared_prefs/sendanywhere_device.xml.
ModificadaAlta (8.8)1.3%—Projectsend22/5/201917/6/2026
CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.
ModificadaMedia (6.1)0.80%—Projectsend22/5/201917/6/2026
An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page.
ModificadaMedia (6.1)1.2%—Projectsend26/4/201917/6/2026
Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web script or HTML.
ModificadaAlta (7.5)1.1%—Projectsend26/4/201917/6/2026
ProjectSend before r1070 writes user passwords to the server logs.
Orbitaley — Vulnerabilidades