Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

128 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.9%—Tipsandtricks-hq ALL IN ONE WP Security & Firewall14/8/201917/6/2026
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
ModificadaMedia (6.1)0.92%—Tipsandtricks-hq ALL IN ONE WP Security & Firewall13/8/201917/6/2026
The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
ModificadaMedia (6.1)0.92%—Tipsandtricks-hq ALL IN ONE WP Security & Firewall13/8/201917/6/2026
The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)0.92%—Tipsandtricks-hq ALL IN ONE WP Security & Firewall13/8/201917/6/2026
The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.
ModificadaMedia (6.1)0.92%—Tipsandtricks-hq ALL IN ONE WP Security & Firewall13/8/201917/6/2026
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.
ModificadaMedia (6.1)0.93%—Tipsandtricks-hq ALL IN ONE WP Security & Firewall13/8/201917/6/2026
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
ModificadaCrítica (9.8)2.7%—Css-tricks Chat24/2/201917/6/2026
An issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection vulnerability.
ModificadaBaja (3.5)0.95%—Trick Question Project Trick Question15/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Trick Question module before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with the "Administer Trick Question" permission to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)1.1%—Tips AND Tricks HQ ALL IN ONE Wordpress Security AND Firewall7/3/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete logs of 404 (aka Not Found) HTTP status codes.
ModificadaMedia (6)1.5%—Tips AND Tricks HQ ALL IN ONE Wordpress Security AND Firewall7/3/201517/6/2026
SQL injection vulnerability in the All In One WP Security & Firewall plugin before 3.8.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.5)4.2%💥 ExploitTips AND Tricks HQ ALL IN ONE Wordpress Security AND Firewall2/10/201417/6/2026
Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby or (2) order parameter in the aiowpsec page to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow…
ModificadaMedia (5.4)0.27%—9jacompass EPL HAT Trick27/9/201417/6/2026
The EPL Hat Trick (aka com.hat.trick.goal) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.8)1.1%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart13/5/201416/6/2026
Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings.
ModificadaBaja (2.1)1.1%—Patrick Przybilla Addtoany14/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Share Buttons (AddToAny) module 6.x-3.x before 6.x-3.4 for Drupal allows remote authenticated users with the administer addtoany permission to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.5)1.3%—Brad Fitzpatrick Djabberd22/6/201116/6/2026
XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than…
ModificadaMedia (5)1.1%—Brad Fitzpatrick Djabberd21/6/201116/6/2026
DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
ModificadaMedia (6.8)1.2%—Thetricky COM Messaging22/7/201016/6/2026
Directory traversal vulnerability in the Messaging (com_messaging) component before 1.5.1 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter in a messages action to index.php. NOTE: the provenance of this information is…
ModificadaAlta (7.5)1.0%—Patrick Bauerochse REF List15/1/201016/6/2026
SQL injection vulnerability in the Customer Reference List (ref_list) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.3%—Patrick Przybilla Addtoany20/11/200916/6/2026
Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x before 5.x-2.4 and 6.x before 6.x-2.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via a node title.
ModificadaMedia (4.3)1.1%—Patrick Matthai Pnopaste17/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste 1.0 allows remote attackers to inject arbitrary web script or HTML via the language parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)1.2%—Lobacher Patrick Simplefilebrowser27/2/200916/6/2026
Unspecified vulnerability in the TYPO3 Simple File Browser (simplefilebrowser) extension 1.0.2 and earlier allows remote attackers to obtain sensitive information via unknown attack vectors.
ModificadaBaja (3.7)0.46%—Monkey Trickle3/2/200916/6/2026
Untrusted search path vulnerability in trickle 1.07 allows local users to execute arbitrary code via a Trojan horse trickle-overload.so in the current working directory, which is referenced in the LD_PRELOAD path.
ModificadaMedia (6.9)0.33%—Kegel Winetricks28/1/200916/6/2026
winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file.
ModificadaMedia (4.3)1.7%💥 ExploitPatrick Michaelis Wili-cms26/9/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to inject arbitrary web script or HTML via (1) the query string to relocate.php, (2) the globals[pageid] parameter in example-view/inc/print_button.php, and other unspecified vectors.
ModificadaMedia (5)2.8%💥 ExploitPatrick Michaelis Wili-cms26/9/200616/6/2026
Patrick Michaelis Wili-CMS allows remote attackers to obtain sensitive information via a direct request for (1) thumbnail.php, (2) functions/admin/all.php, (3) functions/admin/init_session.php, (4) functions/all.php, and (5) certain files in example-view/admin_templates/, which reveals the path in various error…
Orbitaley — Vulnerabilidades