Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
393 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.25% | — | Dotcms | 25/7/2024 | 17/6/2026 | The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. Those interested to see the vulnerability may spin up a… | |
| Modificada | Media (5.4) | 0.24% | — | Dotcamp Ultimate Blocks | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks – Gutenberg Blocks Plugin allows Stored XSS.This issue affects Ultimate Blocks – Gutenberg Blocks Plugin: from n/a through 3.1.9. | |
| Modificada | Media (5.4) | 0.45% | — | Dotcamp Ultimate Blocks | 11/7/2024 | 17/6/2026 | The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.49% | — | Dotcamp Ultimate Blocks | 2/7/2024 | 17/6/2026 | The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Media (5.4) | 0.28% | — | Dotcamp Ultimate Blocks | 2/7/2024 | 17/6/2026 | The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title tag (postTitleTag) parameter in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.32% | — | Dotonpaper DOT ON Paper Shortcodes | 21/6/2024 | 17/6/2026 | The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Media (6.4) | 0.30% | — | Dotcamp Ultimate BlocksAI | 19/6/2024 | 17/6/2026 | The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tab anchor metabox in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.34% | — | Salesforce PardotAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Salesforce Pardot.This issue affects Pardot: from n/a through 2.1.0. | |
| Modificada | Media (5.4) | 0.33% | — | Dotcamp WP Table Builder | 21/5/2024 | 17/6/2026 | The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button element in all versions up to, and including, 1.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (8.1) | 0.44% | — | DotmeshAI | 14/5/2024 | 17/6/2026 | Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations outside the designated target folder. The routine… | |
| Analizada | Media (5.4) | 0.35% | — | Dotcamp Ultimate Blocks | 14/5/2024 | 17/6/2026 | The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Crítica (9.8) | 0.73% | — | Yvan Dotet Postgresql Query DeluxeAI | 6/5/2024 | 17/6/2026 | A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allows a remote attacker to gain privileges via the query parameter to models/querydeluxe.py:QueryDeluxe::get_result_from_query. | |
| Analizada | Media (4.5) | 0.50% | — | Dotcms | 1/4/2024 | 17/6/2026 | System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment. OWASP Top 10 - A05) Insecure Design OWASP Top 10 - A05) Security… | |
| Analizada | Media (4.5) | 0.47% | — | Dotcms | 1/4/2024 | 17/6/2026 | In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone with that portlet and not just to CMS Admins. Users that get site admin but not a system admin, should not have access to the System Maintenance → Tools portlet.… | |
| Analizada | Media (6.1) | 0.43% | — | Dotclear | 21/3/2024 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel. | |
| Modificada | Alta (7.5) | 0.71% | — | Chendotjs Lotos Webserver | 5/2/2024 | 17/6/2026 | Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c. | |
| Modificada | Crítica (9.8) | 0.73% | — | Chendotjs Lotos Webserver | 5/1/2024 | 17/6/2026 | Lotos WebServer through 0.1.1 (commit 3eb36cc) has a use-after-free in buffer_avail() at buffer.h via a long URI, because realloc is mishandled. | |
| Modificada | Crítica (9.8) | 1.2% | 💥 PoC | Clickbar Dot-diver | 6/11/2023 | 17/6/2026 | Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions to work with object paths in dot notation. In versions prior to 1.0.2 there is a Prototype Pollution vulnerability in the `setByPath` function which can leads to remote code execution (RCE). This… | |
| Modificada | Media (6.1) | 0.36% | — | Dotcms | 17/10/2023 | 17/6/2026 | In dotCMS, versions mentioned, a flaw in the NormalizationFilter does not strip double slashes (//) from URLs, potentially enabling bypasses for XSS and access controls. An example affected URL is https://demo.dotcms.com//html/portlet/ext/files/edit_text_inc.jsp , which should return a 404 response but didn't. The… | |
| Modificada | Alta (8.8) | 0.26% | — | Dotsquares WP Custom Post Template | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dotsquares WP Custom Post Template <= 1.0 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Multidots Dynamic Pricing AND Discount Rules FOR Woocommerce | 4/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Dynamic Pricing and Discount Rules for WooCommerce plugin <= 2.4.0 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Multidots Enhanced Ecommerce Google Analytics FOR Woocommerce | 4/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Enhanced Ecommerce Google Analytics for WooCommerce plugin <= 3.7.1 versions. | |
| Modificada | Media (6.5) | 0.22% | — | Multidots Banner Management FOR Woocommerce | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Banner Management For WooCommerce plugin <= 2.4.2 versions. | |
| Modificada | Media (6.5) | 0.22% | — | Multidots Product Attachment FOR Woocommerce | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <= 2.1.8 versions. | |
| Modificada | Media (6.5) | 0.22% | — | Multidots Fraud Prevention FOR Woocommerce | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Fraud Prevention For Woocommerce plugin <= 2.1.5 versions. |