Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

2526 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.32%—Internetmarketingninjas Internal Link Building27/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Internet Marketing Ninjas Internal Link Building plugin <= 1.2.3 versions.
ModificadaAlta (8.8)0.27%—Internetmarketingninjas Internal Link Building25/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Internet Marketing Ninjas Internal Link Building plugin <= 1.2.3 versions.
ModificadaMedia (6.1)0.51%—Martmbithi Internet Banking System23/10/202317/6/2026
A vulnerability, which was classified as problematic, has been found in CodeAstro Internet Banking System 1.0. This issue affects some unknown processing of the file pages_view_client.php. The manipulation of the argument acc_name with the input Johnnie Reyes'"()&%<zzz><ScRiPt >alert(5646)</ScRiPt> leads to cross site…
ModificadaMedia (6.1)0.51%—Martmbithi Internet Banking System23/10/202317/6/2026
A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects unknown code of the file pages_deposit_money.php. The manipulation of the argument account_number with the input 421873905--><ScRiPt%20>alert(9523)</ScRiPt><!-- leads to cross site scripting. The…
ModificadaMedia (6.1)0.51%—Martmbithi Internet Banking System23/10/202317/6/2026
A vulnerability classified as problematic has been found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_withdraw_money.php. The manipulation of the argument account_number with the input 287359614--><ScRiPt%20>alert(1234)</ScRiPt><!-- leads to cross site scripting. It is…
ModificadaMedia (6.1)0.47%—Martmbithi Internet Banking System22/10/202317/6/2026
A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file pages_transfer_money.php. The manipulation of the argument account_number with the input 357146928--><ScRiPt%20>alert(9206)</ScRiPt><!-- leads to cross…
ModificadaMedia (6.1)0.51%—Martmbithi Internet Banking System22/10/202317/6/2026
A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file pages_reset_pwd.php. The manipulation of the argument email with the input testing%40example.com'%26%25<ScRiPt%20>alert(9860)</ScRiPt> leads to…
ModificadaMedia (6.1)0.51%—Martmbithi Internet Banking System22/10/202317/6/2026
A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been classified as problematic. Affected is an unknown function of the file pages_system_settings.php. The manipulation of the argument sys_name with the input <ScRiPt >alert(991)</ScRiPt> leads to cross site scripting. It is possible to launch…
ModificadaCrítica (9.8)0.65%—Martmbithi Internet Banking System22/10/202317/6/2026
A vulnerability was found in CodeAstro Internet Banking System 1.0 and classified as critical. This issue affects some unknown processing of the file pages_reset_pwd.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public…
ModificadaCrítica (9.8)1.1%—Electionservicesco Internet Election Service10/10/202317/6/2026
Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled…
ModificadaAlta (8.8)0.21%—Bainternet Shortcodes UI10/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Bainternet ShortCodes UI plugin <= 1.9.8 versions.
ModificadaAlta (8.8)0.99%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with…
ModificadaCrítica (9.1)0.56%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.
ModificadaCrítica (9.8)0.42%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.
ModificadaAlta (7.7)0.47%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.
ModificadaAlta (8.8)0.73%—Resortdata Internet Reservation Module Next Generation7/9/202317/6/2026
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an attacker generate the daily password and…
ModificadaCrítica (9.8)0.39%—Zscaler Internet Access Admin Portal31/8/202317/6/2026
An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6.2r.
ModificadaAlta (7.8)0.18%—Eset Endpoint AntivirusEset Endpoint SecurityEset Internet SecurityEset Mail Security+414/8/202317/6/2026
The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions.
ModificadaMedia (4.6)0.23%—Samsung Internet10/8/202317/6/2026
Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication.
ModificadaMedia (6.5)0.58%—Samsung Internet6/7/202317/6/2026
Improper configuration in Samsung Internet prior to version 21.0.0.41 allows attacker to bypass SameSite Cookie.
ModificadaAlta (7.8)0.37%—Trendmicro Antivirus+ Security 2021Trendmicro Internet Security 2021Trendmicro Maximum Security 2021Trendmicro Premium Security 2021+826/6/202317/6/2026
Trend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow an attacker to use a specific executable file as an execution and/or persistence mechanism which could execute a malicious program each time the executable file is started.
ModificadaAlta (8.8)0.26%💥 PoCInternet-formation Wp-advanced-search24/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WordPress WP-Advanced-Search plugin <= 3.3.8 versions.
ModificadaAlta (7.8)0.19%—Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security24/5/202317/6/2026
Unquoted Search Path or Element vulnerability in the Vulnerability Scan component of Bitdefender Total Security, Bitdefender Internet Security, and Bitdefender Antivirus Plus allows an attacker to elevate privileges to SYSTEM. This issue affects: Bitdefender Total Security versions prior to 26.0.10.45. Bitdefender…
ModificadaMedia (5.5)0.18%—IBM MQ Internet Pass-thru14/11/202217/6/2026
IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be read by a local user.
ModificadaAlta (7.5)0.40%—F-secure Elements Endpoint Detection AND ResponseF-secure Elements Endpoint ProtectionF-secure AtlantF-secure Internet Gatekeeper+212/10/202217/6/2026
Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crashes. This can lead to a possible scanning engine crash.