Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
375 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.36% | — | Oracle Customer Interaction History | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer Interaction… | |
| Modificada | Media (5.4) | 0.33% | — | Jhayghost Ideal Interactive MAP | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jhayghost Ideal Interactive Map allows Stored XSS.This issue affects Ideal Interactive Map: from n/a through 1.2.4. | |
| Modificada | Alta (8.8) | 0.48% | — | Ubeeinteractive Ddw365 Firmware | 21/1/2024 | 17/6/2026 | Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by using the first six characters of the SSID and the last six of the… | |
| Modificada | Media (6.1) | 0.33% | — | Oracle Customer Interaction History | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer Interaction… | |
| Modificada | Alta (8.8) | 1.4% | 💥 PoC | Qodeinteractive Qode Essential Addons | 29/12/2023 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.5.2. | |
| Modificada | Media (6.1) | 0.41% | — | Fla-shop Interactive World MAP | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fla-shop.Com Interactive World Map plugin <= 3.2.0 versions. | |
| Modificada | Media (5.4) | 0.41% | — | Qodeinteractive QI Addons FOR Elementor | 14/11/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Qode Interactive Qi Addons For Elementor plugin <= 1.6.3 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Wpmapplugins Basic Interactive World MAP | 8/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Map Plugins Basic Interactive World Map plugin <= 2.0 versions. | |
| Modificada | Media (5.4) | 0.54% | — | Tryinteract Interact\ | 7/11/2023 | 17/6/2026 | The Interact: Embed A Quiz On Your Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'interact-quiz' shortcode in all versions up to, and including, 3.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Alta (7.2) | 0.68% | — | Click5interactive Sitemap BY Click5 | 6/11/2023 | 17/6/2026 | The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it. | |
| Modificada | Alta (8.8) | 0.21% | — | Fla-shop Interactive World MAP | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fla-shop.Com Interactive World Map plugin <= 3.2.0 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Qodeinteractive Bridge Core | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Qode Interactive Bridge Core plugin <= 3.0.9 versions. | |
| Modificada | Alta (7.8) | 0.18% | — | Schneider-electric Interactive Graphical Scada System | 14/9/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content. | |
| Modificada | Media (5.4) | 0.45% | — | Interactsoftware Interact | 11/9/2023 | 17/6/2026 | Interact 7.9.79.5 allows stored Cross-site Scripting (XSS) attacks in several locations, allowing an attacker to store a JavaScript payload. | |
| Modificada | Media (6.1) | 0.54% | — | Projectdiscovery Interactsh | 28/6/2023 | 17/6/2026 | Interactsh is an open-source tool for detecting out-of-band interactions. Domains configured with interactsh server prior to version 1.0.0 were vulnerable to subdomain takeover for a specific subdomain, i.e `app.` Interactsh server used to create cname entries for `app` pointing to `projectdiscovery.github.io` as… | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Squarepiginteractive Fusioninvoice | 25/5/2023 | 17/6/2026 | Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details. | |
| Modificada | Alta (8.8) | 0.25% | — | Wpmart Interactive SVG Image MAP Builder | 10/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro for WordPress - Interactive SVG Image Map Builder plugin < 5.6.9 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Interactive GEO Maps Project Interactive GEO Maps | 25/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Carlos Moreira Interactive Geo Maps plugin <= 1.5.8 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Interactive Polish MAP Project Interactive Polish MAP | 4/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcin Pietrzak Interactive Polish Map plugin <= 1.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Wpmart Interactive SVG Image MAP Builder | 28/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mehjabin Orthi Interactive SVG Image Map Builder plugin <= 1.0 versions. | |
| Modificada | Media (5.4) | 0.52% | — | Interactive GEO Maps Project Interactive GEO Maps | 7/2/2023 | 17/6/2026 | The Interactive Geo Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the action content parameter in versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with editor… | |
| Modificada | Crítica (9.8) | 2.1% | — | Schneider-electric Interactive Graphical Scada System | 1/2/2023 | 17/6/2026 | A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to… | |
| Modificada | Crítica (9.8) | 1.2% | — | Schneider-electric Interactive Graphical Scada System | 1/2/2023 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22073) | |
| Modificada | Crítica (9.8) | 1.3% | — | Schneider-electric Interactive Graphical Scada System | 30/1/2023 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted log data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to… | |
| Modificada | Crítica (9.1) | 0.47% | — | Schneider-electric Interactive Graphical Scada System | 30/1/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read specific files in the IGSS project report directory, potentially leading to a denial-of-service condition when an attacker sends specific messages. Affected Products: IGSS Data Server -… |