Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 14/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues. | |
| Modificada | Media (6.1) | 0.92% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 13/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages. | |
| Modificada | Media (6.1) | 0.92% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 13/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.92% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 13/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages. | |
| Modificada | Media (6.1) | 0.92% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 13/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances. | |
| Modificada | Media (6.1) | 0.93% | — | Tipsandtricks-hq ALL IN ONE WP Security & Firewall | 13/8/2019 | 17/6/2026 | The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature. | |
| Modificada | Crítica (9.8) | 2.7% | — | Css-tricks Chat2 | 4/2/2019 | 17/6/2026 | An issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection vulnerability. | |
| Modificada | Baja (3.5) | 0.95% | — | Trick Question Project Trick Question | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Trick Question module before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with the "Administer Trick Question" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 1.1% | — | Tips AND Tricks HQ ALL IN ONE Wordpress Security AND Firewall | 7/3/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete logs of 404 (aka Not Found) HTTP status codes. | |
| Modificada | Media (6) | 1.5% | — | Tips AND Tricks HQ ALL IN ONE Wordpress Security AND Firewall | 7/3/2015 | 17/6/2026 | SQL injection vulnerability in the All In One WP Security & Firewall plugin before 3.8.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.5) | 4.2% | 💥 Exploit | Tips AND Tricks HQ ALL IN ONE Wordpress Security AND Firewall | 2/10/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby or (2) order parameter in the aiowpsec page to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow… | |
| Modificada | Media (5.4) | 0.27% | — | 9jacompass EPL HAT Trick | 27/9/2014 | 17/6/2026 | The EPL Hat Trick (aka com.hat.trick.goal) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 1.1% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 13/5/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings. | |
| Modificada | Baja (2.1) | 1.1% | — | Patrick Przybilla Addtoany | 14/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Share Buttons (AddToAny) module 6.x-3.x before 6.x-3.4 for Drupal allows remote authenticated users with the administer addtoany permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.5) | 1.3% | — | Brad Fitzpatrick Djabberd | 22/6/2011 | 16/6/2026 | XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than… | |
| Modificada | Media (5) | 1.1% | — | Brad Fitzpatrick Djabberd | 21/6/2011 | 16/6/2026 | DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | |
| Modificada | Media (6.8) | 1.2% | — | Thetricky COM Messaging | 22/7/2010 | 16/6/2026 | Directory traversal vulnerability in the Messaging (com_messaging) component before 1.5.1 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter in a messages action to index.php. NOTE: the provenance of this information is… | |
| Modificada | Alta (7.5) | 1.0% | — | Patrick Bauerochse REF List | 15/1/2010 | 16/6/2026 | SQL injection vulnerability in the Customer Reference List (ref_list) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Patrick Przybilla Addtoany | 20/11/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x before 5.x-2.4 and 6.x before 6.x-2.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via a node title. | |
| Modificada | Media (4.3) | 1.1% | — | Patrick Matthai Pnopaste | 17/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste 1.0 allows remote attackers to inject arbitrary web script or HTML via the language parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 1.2% | — | Lobacher Patrick Simplefilebrowser | 27/2/2009 | 16/6/2026 | Unspecified vulnerability in the TYPO3 Simple File Browser (simplefilebrowser) extension 1.0.2 and earlier allows remote attackers to obtain sensitive information via unknown attack vectors. | |
| Modificada | Baja (3.7) | 0.46% | — | Monkey Trickle | 3/2/2009 | 16/6/2026 | Untrusted search path vulnerability in trickle 1.07 allows local users to execute arbitrary code via a Trojan horse trickle-overload.so in the current working directory, which is referenced in the LD_PRELOAD path. | |
| Modificada | Media (6.9) | 0.33% | — | Kegel Winetricks | 28/1/2009 | 16/6/2026 | winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Patrick Michaelis Wili-cms | 26/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to inject arbitrary web script or HTML via (1) the query string to relocate.php, (2) the globals[pageid] parameter in example-view/inc/print_button.php, and other unspecified vectors. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Patrick Michaelis Wili-cms | 26/9/2006 | 16/6/2026 | Patrick Michaelis Wili-CMS allows remote attackers to obtain sensitive information via a direct request for (1) thumbnail.php, (2) functions/admin/all.php, (3) functions/admin/init_session.php, (4) functions/all.php, and (5) certain files in example-view/admin_templates/, which reveals the path in various error… |