Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)38%—Microweber27/12/202217/6/2026
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.
ModificadaMedia (6.1)0.51%—Microweber22/12/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.
ModificadaMedia (6.1)0.63%—Microweber21/12/202217/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2.
ModificadaMedia (6.1)0.71%—Microweber25/11/202217/6/2026
Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.
ModificadaAlta (8.8)1.4%—Microweber22/11/202217/6/2026
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
ModificadaAlta (8.8)0.76%—Automattic Crowdsignal Dashboard17/11/202217/6/2026
Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.
ModificadaCrítica (9.8)0.95%—Atlassian Crowd17/11/202217/6/2026
Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by IPs specified under the crowd application…
ModificadaAlta (7.5)0.86%—Trianglemicroworks IEC 60870-6 Software LibraryTrianglemicroworks IEC 61850 Software Library11/10/202217/6/2026
The Triangle Microworks IEC 61850 Library (Any client or server using the C language library with a version number of 11.2.0 or earlier and any client or server using the C++, C#, or Java language library with a version number of 5.0.1 or earlier) and 60870-6 (ICCP/TASE.2) Library (Any client or server using a C++…
ModificadaMedia (6.1)0.72%—Microweber20/9/202217/6/2026
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.
ModificadaMedia (6.1)1.9%💥 ExploitMicroweber20/9/202217/6/2026
Code Injection in GitHub repository microweber/microweber prior to 1.3.2.
ModificadaAlta (7.5)1.4%—Crowcpp Crow22/8/202217/6/2026
HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfilling a request for a static file smaller than 16 KB.
ModificadaCrítica (9.8)2.9%—Crowcpp Crow22/8/202217/6/2026
HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code execution when HTTP pipelining is used. The HTTP parser supports HTTP pipelining, but the asynchronous Connection layer is unaware of HTTP pipelining. Specifically, the Connection layer is unaware that it has begun processing a…
ModificadaBaja (2.7)4.9%💥 ExploitCrowdstrike Falcon22/8/202217/6/2026
A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problematic. Affected is an unknown function of the component Uninstallation Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. The exploit has been…
ModificadaMedia (5.4)0.46%—Microweber11/8/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1.
ModificadaMedia (6.1)0.63%—Automattic Crowdsignal Dashboard8/8/202217/6/2026
The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
ModificadaCrítica (9.8)4.0%💥 PoCCrowcpp Crow4/8/202217/6/2026
Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service.
ModificadaMedia (5.4)0.31%—Crowdfavorite Progressive License1/8/202217/6/2026
The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the settings, this could lead to Stored XSS issue which will be…
ModificadaCrítica (9.8)1.6%—Pycrowdtangle Project Pycrowdtangle22/7/202217/6/2026
The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.
ModificadaMedia (6.1)0.95%—Microweber22/7/202217/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.
ModificadaMedia (4.8)0.67%—Microweber22/7/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.
ModificadaAlta (8.8)2.4%—Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+720/7/202217/6/2026
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource…
ModificadaCrítica (9.8)5.5%—Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+720/7/202217/6/2026
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting.…
ModificadaAlta (8.8)0.94%—Microweber15/7/202217/6/2026
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.
ModificadaCrítica (9.8)1.2%—Microweber11/7/202217/6/2026
Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.
ModificadaMedia (6.1)0.53%—Microweber9/7/202217/6/2026
Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.
Orbitaley — Vulnerabilidades