Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
236 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.3% | 💥 Exploit | Flatpress | 11/10/2022 | 9/7/2026 | Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php. | |
| Modificada | Alta (7.2) | 1.7% | — | Flatpress | 29/9/2022 | 9/7/2026 | Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function. | |
| Modificada | Media (5.4) | 1.8% | 💥 Exploit | Flatpress | 23/6/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content. | |
| Modificada | Alta (8.8) | 1.4% | — | Flatcore-cms | 16/6/2022 | 17/6/2026 | flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code. | |
| Modificada | Crítica (9.8) | 19% | — | Flatcore-cms | 15/6/2022 | 17/6/2026 | flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities. | |
| Modificada | Media (5.4) | 0.48% | — | Flatcore-cms | 13/6/2022 | 17/6/2026 | flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page. | |
| Modificada | Media (6.1) | 0.71% | — | Flatcore-cms | 6/6/2022 | 17/6/2026 | FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sections. | |
| Modificada | Alta (7.5) | 1.1% | — | Batflat | 1/3/2022 | 17/6/2026 | Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database. | |
| Modificada | Media (5.4) | 0.71% | — | Flatpress | 15/2/2022 | 17/6/2026 | Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function. | |
| Modificada | Media (6.5) | 1.7% | — | FlatpakFlatpak-builderFedoraproject FedoraRedhat Enterprise Linux+1 | 13/1/2022 | 17/6/2026 | Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At this point the build directory will have the full access that is specified in the manifest, so running… | |
| Modificada | Alta (8.6) | 1.3% | — | FlatpakFedoraproject FedoraRedhat Enterprise LinuxDebian Linux | 12/1/2022 | 17/6/2026 | Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the case that there's a null byte in the… | |
| Modificada | Media (6.1) | 0.76% | — | Duogeek Duofaq-responsive-flat-simple-faq | 14/12/2021 | 17/6/2026 | The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/duogeek/duogeek-panel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.4.8. | |
| Modificada | Media (4.8) | 0.64% | — | Flat Preloader Project Flat Preloader | 1/11/2021 | 17/6/2026 | The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | |
| Modificada | Media (5.4) | 0.51% | — | Flat Preloader Project Flat Preloader | 1/11/2021 | 17/6/2026 | The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the frontend or backend depending on the… | |
| Modificada | Media (6.6) | 1.1% | — | Flatcore-cms | 28/10/2021 | 17/6/2026 | flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type | |
| Modificada | Alta (7.8) | 0.44% | — | FlatpakDebian LinuxFedoraproject Fedora | 8/10/2021 | 17/6/2026 | Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS services into treating the… | |
| Modificada | Media (5.4) | 1.7% | — | Flatcore-cms | 23/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function. | |
| Modificada | Alta (7.2) | 46% | 💥 Exploit | Flatcore-cms | 23/8/2021 | 17/6/2026 | Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code. | |
| Modificada | Crítica (9.1) | 0.99% | — | Netless Flat Server | 13/8/2021 | 17/6/2026 | The remove API in v1/controller/cloudStorage/alibabaCloud/remove/index.ts in netless Agora Flat Server before 2021-07-30 mishandles file ownership. | |
| Modificada | Crítica (9.8) | 1.2% | — | Libp2p-deflate | 8/8/2021 | 17/6/2026 | An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust. An uninitialized buffer is passed to AsyncRead::poll_read(), which is a user-provided trait function. | |
| Modificada | Alta (8.8) | 0.76% | — | Flatpress | 30/7/2021 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php. | |
| Modificada | Crítica (9.8) | 3.3% | — | Safe-flat Project Safe-flat | 26/4/2021 | 17/6/2026 | Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Media (5.4) | 0.62% | — | Batflat | 11/3/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Navigation in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name. | |
| Modificada | Media (5.4) | 0.62% | — | Batflat | 11/3/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Snippets in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name. | |
| Modificada | Media (5.4) | 0.62% | — | Batflat | 11/3/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Galleries in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the field name. |