Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
230 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 3.3% | 💥 PoC | ComposerAI | 10/6/2024 | 17/6/2026 | Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24… | |
| Aplazada | Alta (8.8) | 1.1% | — | ComposerAI | 10/6/2024 | 17/6/2026 | Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code. Patches for this issue are available in… | |
| Modificada | Media (5.4) | 0.28% | — | Visualcomposer Visual Composer Website Builder | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer.This issue affects Visual Composer Website Builder: from n/a through <= 45.8.0. | |
| Aplazada | Media (6.4) | 0.29% | — | Tagdiv ComposerAI | 4/6/2024 | 17/6/2026 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button shortcode in all versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.7) | 0.38% | — | Page Builder Live ComposerAI | 26/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.38. | |
| Aplazada | Media (6.5) | 0.31% | — | Sharabindu QR Code ComposerAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sharabindu QR Code Composer allows Stored XSS.This issue affects QR Code Composer: from n/a through 2.0.3. | |
| Aplazada | Media (5.4) | 0.20% | — | Page Builder Live ComposerAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.35. | |
| Aplazada | Media (6.1) | 0.19% | — | Osbuild-composerAI | 19/3/2024 | 17/6/2026 | A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be installed into an image being built. | |
| Aplazada | Media (5.9) | 0.34% | — | Visualcomposer Visual Composer Website BuilderAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer.This issue affects Visual Composer Website Builder: from n/a through <= 45.6.0. | |
| Modificada | Media (5.4) | 0.41% | — | Visualcomposer Visual Composer Website Builder | 13/3/2024 | 17/6/2026 | The Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fields in all versions up to, and including, 45.6.0 due to insufficient input sanitization and output escaping… | |
| Aplazada | Crítica (9.4) | 2.1% | — | Simulia AbaqusAISimulia IsightAICatia ComposerAI3DS 3dexperienceAI | 1/3/2024 | 17/6/2026 | An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x, SIMULIA Abaqus from Release 2022 through Release 2024, SIMULIA Isight from Release 2022 through Release 2024 and CATIA Composer from Release R2023 through Release… | |
| Modificada | Alta (7.8) | 0.28% | — | Getcomposer Composer | 9/2/2024 | 17/6/2026 | Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of Composer and in the context of the executing user. As such, under certain conditions arbitrary code execution may lead to local privilege escalation,… | |
| Modificada | Media (6.1) | 0.23% | — | Tagdiv Composer | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in tagDiv tagDiv Composer allows Cross-Site Scripting (XSS).This issue affects tagDiv Composer: from n/a before 4.4. | |
| Analizada | Alta (8.8) | 1.5% | — | Getcomposer ComposerDebian LinuxFedoraproject Fedora | 29/9/2023 | 17/6/2026 | Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `register_argc_argv` enabled in php.ini. Versions 2.6.4, 2.2.22 and 1.10.27 patch… | |
| Modificada | Alta (8.8) | 0.72% | — | Getcomposer Composer | 21/9/2023 | 17/6/2026 | Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because of the way that dist packages are cached. The cache key is derived from the package name, the dist type, and certain… | |
| Modificada | Media (4.8) | 0.44% | — | Tagdiv Composer | 11/9/2023 | 17/6/2026 | The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not validate and escape some settings, which could allow users with Admin privileges to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for… | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | Tagdiv Composer | 11/9/2023 | 17/6/2026 | The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site… | |
| Modificada | Media (4.8) | 0.73% | — | Visualcomposer Visual Composer Website Builder | 7/6/2023 | 17/6/2026 | The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser. | |
| Modificada | Media (4.8) | 0.64% | — | King-theme Page Builder Kingcomposer | 7/6/2023 | 17/6/2026 | The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via shortcode in versions before 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever… | |
| Modificada | Alta (8.8) | 1.5% | — | King-theme Page Builder King Composer | 7/6/2023 | 17/6/2026 | The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and including, 2.9.3 via the 'process_bulk_action' function in the 'kingcomposer/includes/kc.extensions.php' file. This makes it possible for authenticated users with author level permissions and above to… | |
| Modificada | Alta (8.8) | 1.2% | — | King-theme Page Builder Kingcomposer | 7/6/2023 | 17/6/2026 | The Page Builder: KingComposer plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.9.3. This is due to a security nonce being leaked in the '/wp-admin/index.php' page. This makes it possible for authenticated attackers to change arbitrary WordPress options, delete arbitrary… | |
| Modificada | Media (6.1) | 0.51% | — | Tagdiv Composer | 15/5/2023 | 17/6/2026 | The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.4) | 0.59% | — | GitlabABB Drive Composer | 12/1/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on… | |
| Modificada | Crítica (9.8) | 3.8% | 💥 Exploit | Newsmag Project NewsmagNewspaper Project NewspaperTagdiv Composer Project Tagdiv Composer | 14/11/2022 | 17/6/2026 | The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address | |
| Modificada | Alta (7.8) | 0.38% | — | Autodesk Subassembly Composer | 14/10/2022 | 17/6/2026 | A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. |