Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 38% | — | Microweber | 27/12/2022 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2. | |
| Modificada | Media (6.1) | 0.51% | — | Microweber | 22/12/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2. | |
| Modificada | Media (6.1) | 0.63% | — | Microweber | 21/12/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2. | |
| Modificada | Media (6.1) | 0.71% | — | Microweber | 25/11/2022 | 17/6/2026 | Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter. | |
| Modificada | Alta (8.8) | 1.4% | — | Microweber | 22/11/2022 | 17/6/2026 | Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack. | |
| Modificada | Alta (8.8) | 0.76% | — | Automattic Crowdsignal Dashboard | 17/11/2022 | 17/6/2026 | Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress. | |
| Modificada | Crítica (9.8) | 0.95% | — | Atlassian Crowd | 17/11/2022 | 17/6/2026 | Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by IPs specified under the crowd application… | |
| Modificada | Alta (7.5) | 0.86% | — | Trianglemicroworks IEC 60870-6 Software LibraryTrianglemicroworks IEC 61850 Software Library | 11/10/2022 | 17/6/2026 | The Triangle Microworks IEC 61850 Library (Any client or server using the C language library with a version number of 11.2.0 or earlier and any client or server using the C++, C#, or Java language library with a version number of 5.0.1 or earlier) and 60870-6 (ICCP/TASE.2) Library (Any client or server using a C++… | |
| Modificada | Media (6.1) | 0.72% | — | Microweber | 20/9/2022 | 17/6/2026 | HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input. | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Microweber | 20/9/2022 | 17/6/2026 | Code Injection in GitHub repository microweber/microweber prior to 1.3.2. | |
| Modificada | Alta (7.5) | 1.4% | — | Crowcpp Crow | 22/8/2022 | 17/6/2026 | HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfilling a request for a static file smaller than 16 KB. | |
| Modificada | Crítica (9.8) | 2.9% | — | Crowcpp Crow | 22/8/2022 | 17/6/2026 | HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code execution when HTTP pipelining is used. The HTTP parser supports HTTP pipelining, but the asynchronous Connection layer is unaware of HTTP pipelining. Specifically, the Connection layer is unaware that it has begun processing a… | |
| Modificada | Baja (2.7) | 4.9% | 💥 Exploit | Crowdstrike Falcon | 22/8/2022 | 17/6/2026 | A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problematic. Affected is an unknown function of the component Uninstallation Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.46% | — | Microweber | 11/8/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1. | |
| Modificada | Media (6.1) | 0.63% | — | Automattic Crowdsignal Dashboard | 8/8/2022 | 17/6/2026 | The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 4.0% | 💥 PoC | Crowcpp Crow | 4/8/2022 | 17/6/2026 | Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service. | |
| Modificada | Media (5.4) | 0.31% | — | Crowdfavorite Progressive License | 1/8/2022 | 17/6/2026 | The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the settings, this could lead to Stored XSS issue which will be… | |
| Modificada | Crítica (9.8) | 1.6% | — | Pycrowdtangle Project Pycrowdtangle | 22/7/2022 | 17/6/2026 | The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party. | |
| Modificada | Media (6.1) | 0.95% | — | Microweber | 22/7/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21. | |
| Modificada | Media (4.8) | 0.67% | — | Microweber | 22/7/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21. | |
| Modificada | Alta (8.8) | 2.4% | — | Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+7 | 20/7/2022 | 17/6/2026 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource… | |
| Modificada | Crítica (9.8) | 5.5% | — | Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+7 | 20/7/2022 | 17/6/2026 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting.… | |
| Modificada | Alta (8.8) | 0.94% | — | Microweber | 15/7/2022 | 17/6/2026 | An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini. | |
| Modificada | Crítica (9.8) | 1.2% | — | Microweber | 11/7/2022 | 17/6/2026 | Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20. | |
| Modificada | Media (6.1) | 0.53% | — | Microweber | 9/7/2022 | 17/6/2026 | Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user. |