Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

157 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.77%—Wow-company Modal Window10/1/202217/6/2026
The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
ModificadaAlta (7.2)1.5%—Wow-company WOW Forms8/11/202117/6/2026
The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL statement, when deleting a form in the admin dashboard, leading to an authenticated SQL injection
ModificadaMedia (5.5)0.31%—Newmediacompany Smarty5/2/202117/6/2026
An issue was discovered in New Media Smarty before 9.10. Passwords are stored in the database in an obfuscated format that can be easily reversed. The file data.mdb contains these obfuscated passwords in the second column. NOTE: this is unrelated to the popular Smarty template engine product.
ModificadaMedia (6.8)1.2%—Company Cs-c2shw Firmware26/1/202117/6/2026
Rostelecom CS-C2SHW 5.0.082.1 is affected by: Bash command injection. The camera reads configuration from QR code (including network settings). The static IP configuration from QR code is copied to the file /config/ip-static and after reboot data from this file is inserted into bash command (without any escaping). So…
ModificadaAlta (7.5)1.1%—Company Cs-c2shw Firmware26/1/202117/6/2026
Denial of Service vulnerability in Rostelecom CS-C2SHW 5.0.082.1. AgentGreen service has a bug in parsing broadcast discovery UDP packet. Sending a packet of too small size will lead to an attempt of allocating buffer of negative size. As the result service AgentGreen will be terminated and started again later.
ModificadaCrítica (9.8)0.83%—Company Cs-c2shw Firmware26/1/202117/6/2026
Bash injection vulnerability and bypass of signature verification in Rostelecom CS-C2SHW 5.0.082.1. The camera reads firmware update configuration from SD card file vc\version.json. fw-sign parameter and from this configuration is directly inserted into a bash command. Firmware update is run automatically if there is…
ModificadaCrítica (9.8)1.3%—Company Cs-c2shw Firmware26/1/202117/6/2026
Heap overflow with full parsing of HTTP respose in Rostelecom CS-C2SHW 5.0.082.1. AgentUpdater service has a self-written HTTP parser and builder. HTTP parser has a heap buffer overflow (OOB write). In default configuration camera parses responses only from HTTPS URLs from config file, so vulnerable code is…
ModificadaCrítica (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModificadaMedia (6.1)4.2%💥 ExploitCybercompany Swipehq-payment-gateway-woocommerce27/12/201917/6/2026
Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.
ModificadaCrítica (9.8)1.1%—Sales & Company Management System Project Sales & Company Management System6/12/201817/6/2026
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the member/member_order.php type parameter, related to the O_state parameter.
ModificadaMedia (6.1)0.71%—Sales & Company Management System Project Sales & Company Management System6/12/201817/6/2026
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified in between the request for a validation code and the entry of the validation code, leading to storage of an XSS payload contained in the modified address.
ModificadaAlta (8.8)0.52%—Sales & Company Management System Project Sales & Company Management System6/12/201817/6/2026
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php?action=edit CSRF.
ModificadaAlta (7.5)0.92%—Sales & Company Management System Project Sales & Company Management System29/11/201817/6/2026
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in username checking between a component that does string validation, and a component that is supposed to query a MySQL database. Thus, it is possible to register a new account with a duplicate username, as…
ModificadaAlta (8.8)0.54%—Xiao5ucompany Project Xiao5ucompany6/8/201817/6/2026
Xiao5uCompany 1.7 has CSRF via admin/Admin.asp.
ModificadaMedia (6.1)0.68%—Xiao5ucompany Project Xiao5ucompany23/7/201817/6/2026
Feedback.asp in Xiao5uCompany 1.7 has XSS because the XSS protection mechanism in Safe.asp is insufficient (for example, it considers SCRIPT and IMG elements, but does not consider VIDEO elements).
ModificadaCrítica (9.8)1.2%—SSH Companywebsite Project SSH Companywebsite20/7/201817/6/2026
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image/jpeg content type.
ModificadaCrítica (9.8)1.1%—SSH Companywebsite Project SSH Companywebsite20/7/201817/6/2026
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeManageAction_queryNotice.action noticeInfo parameter.
ModificadaMedia (5.4)0.27%—Princetoncorporatesolutions Taking Your Company Public19/10/201417/6/2026
The Taking Your Company Public (aka biz.app4mobile.app_016e43d03ee54d1facd6c9532a00e724.app) application 1.28.44.441 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.8)1.5%—R-company Unzipper18/3/201417/6/2026
Directory traversal vulnerability in the R-Company Unzipper application 1.0.1 and earlier for Android allows remote attackers to overwrite or create arbitrary files via a crafted filename.
ModificadaBaja (2.1)0.94%—Devsaran Company27/3/201316/6/2026
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Company theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.8)1.6%—Cisco Unified Communications ManagerCisco Intercompany Media Engine29/8/201116/6/2026
Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 8.x before 8.5(1) and Cisco Intercompany Media Engine 8.x before 8.5(1) allows remote attackers to cause a denial of service (device reload) via crafted SAF packets, aka Bug…
ModificadaAlta (7.8)1.6%—Cisco Unified Communications ManagerCisco Intercompany Media Engine29/8/201116/6/2026
Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 8.x before 8.5(1) and Cisco Intercompany Media Engine 8.x before 8.5(1) allows remote attackers to cause a denial of service (device reload) via crafted SAF packets, aka Bug…
ModificadaMedia (5)1.2%—Impactsoftcompany Adpeeps22/7/201016/6/2026
index.php in AdPeeps 8.5d1 allows remote attackers to obtain sensitive information via (1) a view_adrates action with an invalid uid parameter, which reveals the installation path in an error message; or (2) an adminlogin action with a crafted uid parameter, which reveals the version number.
ModificadaMedia (4.3)1.9%💥 ExploitImpactsoftcompany Adpeeps22/7/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdPeeps 8.5d1 allow remote attackers to inject arbitrary web script or HTML via the (1) uid parameter, (2) uid parameter in a login_lookup action, (3) uid parameter in an adminlogin action, (4) campaignid parameter in a createcampaign action, (5) type…
ModificadaAlta (7.5)1.0%💥 ExploitWeentech Weencompany24/12/200916/6/2026
SQL injection vulnerability in index.php in weenCompany 4.0.0 allows remote attackers to execute arbitrary SQL commands via the moduleid parameter. NOTE: some of these details are obtained from third party information.
Orbitaley — Vulnerabilidades