Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

164 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.47%—Digitalalertsystems Dasdec II FirmwareDigitalalertsystems One-net SE FirmwareDigitalalertsystems Dasdec I FirmwareDigitalalertsystems One-net Firmware+130/11/202217/6/2026
Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered…
ModificadaMedia (4.8)0.58%—Wpexperts WP Contact Slider31/10/202217/6/2026
The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (7.2)1.3%—Wpexperts Post Smtp26/9/202217/6/2026
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.
ModificadaMedia (4.8)0.68%—Wpexperts Post Smtp16/9/202217/6/2026
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed.
ModificadaMedia (4.8)0.59%—Wpexperts WP Contact Slider4/7/202217/6/2026
The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders, which could allow high privileged users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
ModificadaMedia (4.3)0.38%—Wpexperts NEW User Approve27/6/202217/6/2026
The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding invitation codes, which could allow attackers to add invitation codes (for bypassing the provided restrictions) and to change plugin settings by tricking admin users into visiting specially crafted…
ModificadaMedia (4.8)0.59%—Wp-experts Custom Share Buttons With Floating Sidebar20/6/202217/6/2026
The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
AnalizadaAlta (7.5)0.60%—Wpexperts ALL IN ONE Login30/5/202217/6/2026
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector
ModificadaMedia (4.8)0.60%—Wp-experts WP Social Buttons9/5/202217/6/2026
The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (4.3)0.43%—Wpexperts Mycred25/4/202217/6/2026
The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog
ModificadaMedia (4.3)0.34%—Wpexperts Mycred25/4/202217/6/2026
The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating arbitrary posts.
ModificadaMedia (4.3)0.78%—Wpexperts Mycred25/4/202217/6/2026
The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog
ModificadaMedia (4.3)0.43%—Madewithfuel Customize Wordpress Emails AND Alerts28/2/202217/6/2026
The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.).
ModificadaAlta (7.5)1.5%—Wp-experts Protect WP Admin24/1/202217/6/2026
The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitApache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+5114/12/202117/6/2026
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,…
ModificadaAlta (8.8)1.4%—Wpexperts Mycred29/11/202117/6/2026
The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user
ModificadaMedia (6.1)0.94%—Followistic Smart Email Alerts16/8/202117/6/2026
The Smart Email Alerts WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the api_key in the ~/views/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.10.
ModificadaMedia (5.3)0.98%—Ready Wireless Emergency Alerts2/11/201917/6/2026
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE System Information Block 12 (aka SIB12). NOTE: testing inside an RF-isolated shield box suggested that all LTE phones are…
ModificadaAlta (7.5)3.7%—S3bubble-amazon-s3-html-5-video-with-adverts10/10/201917/6/2026
The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaAlta (8.8)1.7%—Xpertsol Server Status BY Hostname/ip3/7/201917/6/2026
A SQL injection vulnerability in the Xpert Solution "Server Status by Hostname/IP" plugin 4.6 for WordPress allows an authenticated user to execute arbitrary SQL commands via GET parameters.
ModificadaAlta (7.8)1.5%—Signkorea Skcertservice21/12/201817/6/2026
SKCertService 2.5.5 and earlier contains a vulnerability that could allow remote attacker to execute arbitrary code. This vulnerability exists due to the way .dll files are loaded by SKCertService. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's…
ModificadaMedia (6.5)1.7%—Jexperts Channel Platform25/11/201417/6/2026
JExperts Channel Platform 5.0.33_CCB allows remote authenticated users to bypass access restrictions via crafted action and key parameters.
ModificadaMedia (4.3)1.9%—Jexperts Channel Platform13/11/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in JExperts Channel Platform 5.0.33_CCB allow remote attackers to inject arbitrary web script or HTML via the (1) usuario.nome variable in an editarUsuario action to usuario.do or (2) titulo.form variable in a novoChamado action to ticket.do.
ModificadaMedia (5.4)0.27%—Webpromoexperts20/10/201417/6/2026
The WebPromoExperts (aka ua.com.webpromoexperts) application 1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades