Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.58% | — | Davidlingren Media Library Assistant | 20/6/2024 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Modificada | Crítica (9.8) | 0.43% | — | Dino Physics School Assistant Project Dino Physics School Assistant | 30/5/2024 | 17/6/2026 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_item. Manipulating the argument id can result in SQL injection. | |
| Analizada | Crítica (9.8) | 0.56% | — | Dino Physics School Assistant Project Dino Physics School Assistant | 30/5/2024 | 17/6/2026 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Users.php?f=save. Manipulating the argument id can result in improper authorization. | |
| Analizada | Media (6.1) | 0.32% | — | Dino Physics School Assistant Project Dino Physics School Assistant | 30/5/2024 | 17/6/2026 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/Users.php?f=save. Manipulating the parameter middlename results in cross-site scripting. | |
| Analizada | Media (5.4) | 0.26% | — | Dino Physics School Assistant Project Dino Physics School Assistant | 30/5/2024 | 17/6/2026 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/SystemSettings.php?f=update_settings. Manipulating the parameter name results in cross-site scripting. | |
| Analizada | Crítica (9.8) | 0.53% | — | Dino Physics School Assistant Project Dino Physics School Assistant | 30/5/2024 | 17/6/2026 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/?page=borrow/view_borrow. Manipulating the argument id can result in SQL injection. | |
| Modificada | Crítica (9.8) | 0.54% | — | Dino Physics School Assistant Project Dino Physics School Assistant | 30/5/2024 | 17/6/2026 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/category/view_category.php. Manipulating the argument id can result in SQL injection. | |
| Analizada | Media (6.5) | 0.41% | — | Dino Physics School Assistant Project Dino Physics School Assistant | 30/5/2024 | 17/6/2026 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_category. Manipulating the argument id can result in SQL injection. | |
| Analizada | Media (5.3) | 0.24% | — | Dino Physics School Assistant Project Dino Physics School Assistant | 30/5/2024 | 17/6/2026 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_item. Manipulating the argument id can result in SQL injection. | |
| Analizada | Media (6.3) | 0.37% | — | Dino Physics School Assistant Project Dino Physics School Assistant | 30/5/2024 | 17/6/2026 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=save_item. Manipulating the argument id can result in SQL injection. | |
| Analizada | Crítica (9.8) | 0.65% | — | Dino Physics School Assistant Project Dino Physics School Assistant | 30/5/2024 | 17/6/2026 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_category. Manipulating the argument id can result in SQL injection. | |
| Analizada | Crítica (9.8) | 0.65% | — | Dino Physics School Assistant Project Dino Physics School Assistant | 30/5/2024 | 17/6/2026 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=save_category. Manipulating the argument id can result in SQL injection. | |
| Analizada | Media (5.4) | 0.36% | — | Dino Physics School Assistant Project Dino Physics School Assistant | 30/5/2024 | 17/6/2026 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts unidentified code within the file /classes/Users.php. Manipulating the argument id results in cross-site scripting. | |
| Analizada | Alta (7.8) | 0.54% | — | Dlink Network Assistant | 23/5/2024 | 17/6/2026 | D-Link Network Assistant Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of D-Link Network Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Media (6.1) | 0.33% | — | Davidlingren Media Library Assistant | 22/5/2024 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the lang parameter in all versions up to, and including, 3.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Media (6.5) | 0.53% | — | Davidlingren Media Library Assistant | 22/5/2024 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Analizada | Alta (7.3) | 0.21% | — | Intel Driver & Support Assistant | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.25% | — | Intel Driver & Support Assistant | 3/5/2024 | 17/6/2026 | Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Analizada | Alta (7.8) | 0.33% | — | Intel Driver & Support Assistant | 3/5/2024 | 17/6/2026 | Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Aplazada | Media (5.3) | 0.44% | — | Fastline Media LLC Assistant Every DAY Productivity AppsAI | 29/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Fastline Media LLC Assistant – Every Day Productivity Apps.This issue affects Assistant – Every Day Productivity Apps: from n/a through 1.4.9.1. | |
| Modificada | Alta (7.7) | 0.49% | — | Davidlingren Media Library Assistant | 9/4/2024 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Alta (8.5) | 0.52% | — | Codeisawesome Aikit Wordpress AI Writing Assistant Using Gpt3AI | 9/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeIsAwesome AIKit aikit-wordpress-ai-writing-assistant-using-gpt3.This issue affects AIKit: from n/a through <= 4.14.1. | |
| Modificada | Media (5.4) | 0.44% | — | Davidlingren Media Library Assistant | 29/3/2024 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Crítica (9.8) | 64% | 💥 Exploit | LG LED Assistant | 25/3/2024 | 17/6/2026 | This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant. | |
| Analizada | Crítica (9.8) | 51% | 💥 Exploit | LG LED Assistant | 25/3/2024 | 17/6/2026 | This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant. |