Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

393 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.25%—Dotcms25/7/202417/6/2026
The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. Those interested to see the vulnerability may spin up a…
ModificadaMedia (5.4)0.24%—Dotcamp Ultimate Blocks21/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks – Gutenberg Blocks Plugin allows Stored XSS.This issue affects Ultimate Blocks – Gutenberg Blocks Plugin: from n/a through 3.1.9.
ModificadaMedia (5.4)0.45%—Dotcamp Ultimate Blocks11/7/202417/6/2026
The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.4)0.49%—Dotcamp Ultimate Blocks2/7/202417/6/2026
The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
ModificadaMedia (5.4)0.28%—Dotcamp Ultimate Blocks2/7/202417/6/2026
The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title tag (postTitleTag) parameter in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
ModificadaMedia (5.4)0.32%—Dotonpaper DOT ON Paper Shortcodes21/6/202417/6/2026
The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
AplazadaMedia (6.4)0.30%—Dotcamp Ultimate BlocksAI19/6/202417/6/2026
The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tab anchor metabox in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (4.3)0.34%—Salesforce PardotAI11/6/202417/6/2026
Missing Authorization vulnerability in Salesforce Pardot.This issue affects Pardot: from n/a through 2.1.0.
ModificadaMedia (5.4)0.33%—Dotcamp WP Table Builder21/5/202417/6/2026
The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button element in all versions up to, and including, 1.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web…
AplazadaAlta (8.1)0.44%—DotmeshAI14/5/202417/6/2026
Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations outside the designated target folder. The routine…
AnalizadaMedia (5.4)0.35%—Dotcamp Ultimate Blocks14/5/202417/6/2026
The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
AplazadaCrítica (9.8)0.73%—Yvan Dotet Postgresql Query DeluxeAI6/5/202417/6/2026
A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allows a remote attacker to gain privileges via the query parameter to models/querydeluxe.py:QueryDeluxe::get_result_from_query.
AnalizadaMedia (4.5)0.50%—Dotcms1/4/202417/6/2026
System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment. OWASP Top 10 - A05) Insecure Design OWASP Top 10 - A05) Security…
AnalizadaMedia (4.5)0.47%—Dotcms1/4/202417/6/2026
In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone with that portlet and not just to CMS Admins. Users that get site admin but not a system admin, should not have access to the System Maintenance → Tools portlet.…
AnalizadaMedia (6.1)0.43%—Dotclear21/3/202417/6/2026
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel.
ModificadaAlta (7.5)0.71%—Chendotjs Lotos Webserver5/2/202417/6/2026
Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c.
ModificadaCrítica (9.8)0.73%—Chendotjs Lotos Webserver5/1/202417/6/2026
Lotos WebServer through 0.1.1 (commit 3eb36cc) has a use-after-free in buffer_avail() at buffer.h via a long URI, because realloc is mishandled.
ModificadaCrítica (9.8)1.2%💥 PoCClickbar Dot-diver6/11/202317/6/2026
Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions to work with object paths in dot notation. In versions prior to 1.0.2 there is a Prototype Pollution vulnerability in the `setByPath` function which can leads to remote code execution (RCE). This…
ModificadaMedia (6.1)0.36%—Dotcms17/10/202317/6/2026
In dotCMS, versions mentioned, a flaw in the NormalizationFilter does not strip double slashes (//) from URLs, potentially enabling bypasses for XSS and access controls. An example affected URL is https://demo.dotcms.com//html/portlet/ext/files/edit_text_inc.jsp , which should return a 404 response but didn't. The…
ModificadaAlta (8.8)0.26%—Dotsquares WP Custom Post Template10/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dotsquares WP Custom Post Template <= 1.0 versions.
ModificadaAlta (8.8)0.26%—Multidots Dynamic Pricing AND Discount Rules FOR Woocommerce4/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Dynamic Pricing and Discount Rules for WooCommerce plugin <= 2.4.0 versions.
ModificadaAlta (8.8)0.25%—Multidots Enhanced Ecommerce Google Analytics FOR Woocommerce4/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Enhanced Ecommerce Google Analytics for WooCommerce plugin <= 3.7.1 versions.
ModificadaMedia (6.5)0.22%—Multidots Banner Management FOR Woocommerce3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Banner Management For WooCommerce plugin <= 2.4.2 versions.
ModificadaMedia (6.5)0.22%—Multidots Product Attachment FOR Woocommerce3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <= 2.1.8 versions.
ModificadaMedia (6.5)0.22%—Multidots Fraud Prevention FOR Woocommerce3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Fraud Prevention For Woocommerce plugin <= 2.1.5 versions.
Orbitaley — Vulnerabilidades