Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
191 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (8.8) | 0.25% | — | Fugu Maintenance Switch | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fugu Maintenance Switch plugin <= 1.5.2 versions. | |
| Modificada | Alta (8.8) | 0.78% | — | Mainwp Maintenance Extension | 18/7/2023 | 17/6/2026 | Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP MainWP Maintenance Extension plugin <= 4.1.1 versions. | |
| Modificada | Media (4.3) | 0.48% | — | Wpconcern Coming Soon & Maintenance Mode Page | 12/7/2023 | 17/6/2026 | The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This is due to missing or incorrect nonce validation on the save_meta_box() function. This makes it possible for unauthenticated attackers to save meta boxes via a forged… | |
| Modificada | Alta (8.8) | 0.45% | — | Wpconcern Nifty Coming Soon & Maintenance Mode Page | 7/6/2023 | 17/6/2026 | The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This is due to confusing logic functions missing or having incorrect nonce validation. This makes it possible for unauthenticated attackers to gain and perform otherwise… | |
| Modificada | Media (6.1) | 0.77% | — | Wpshopmart Coming Soon Page & Maintenance Mode | 7/6/2023 | 17/6/2026 | The WordPress Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logo_width, logo_height, rcsp_logo_url, home_sec_link_txt, rcsp_headline and rcsp_description parameters in versions up to, and including, 1.8.1 due to insufficient input sanitization and output… | |
| Modificada | Media (5.3) | 0.81% | — | Wpshopmart Coming Soon Page & Maintenance Mode | 7/6/2023 | 17/6/2026 | The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthenticated settings reset in versions up to, and including 1.8.1 due to missing capability checks in the ~/functions/data-reset-post.php file which makes it possible for unauthenticated attackers to trigger a plugin settings reset. | |
| Modificada | Media (4.8) | 0.46% | — | Duplicator EZP Maintenance Mode | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Maintenance Mode plugin <= 1.0.1 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Fugu Maintenance Switch | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Fugu Maintenance Switch plugin <= 1.5.2 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Obox Launchpad - Coming Soon & Maintenance Mode Plugin | 17/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Obox Themes Launchpad – Coming Soon & Maintenance Mode plugin <= 1.0.13 versions. | |
| Modificada | Media (5.3) | 1.4% | 💥 Exploit | Niteothemes Coming Soon & Maintenance | 7/3/2023 | 17/6/2026 | The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode… | |
| Modificada | Crítica (9.8) | 0.60% | — | Accruent Maintenance Connection | 2/3/2023 | 9/7/2026 | Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function. | |
| Modificada | Alta (7.5) | 0.63% | — | Ronds Equipment Predictive Maintenance | 17/1/2023 | 17/6/2026 | RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials. In some circumstances, an attacker can exploit this vulnerability to execute operating system (OS) commands. | |
| Modificada | Media (6.5) | 0.70% | — | Ronds Equipment Predictive Maintenance | 17/1/2023 | 17/6/2026 | RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to specify file paths and download files. | |
| Modificada | Media (4.8) | 0.54% | — | Obox Launchpad - Coming Soon & Maintenance Mode Plugin | 13/1/2023 | 17/6/2026 | The Launchpad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings parameters in versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Modificada | Media (4.8) | 0.76% | — | WP Maintenance Project WP Maintenance | 21/7/2022 | 17/6/2026 | Authenticated Stored Cross-Site Scripting (XSS) vulnerability in Florent Maillefaud's WP Maintenance plugin <= 6.0.7 at WordPress. | |
| Modificada | Media (6.5) | 0.52% | — | Themeisle WP Maintenance Mode & Coming Soon | 11/7/2022 | 17/6/2026 | The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack | |
| Modificada | Media (4.8) | 0.59% | — | Colorlib Coming Soon & Maintenance Mode | 20/6/2022 | 17/6/2026 | The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Stored Cross-Site Scripting when unfiltered_html is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.53% | — | WP Maintenance Project WP Maintenance | 15/4/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) in WP Maintenance plugin <= 6.0.7 versions. | |
| Modificada | Media (6.1) | 0.88% | — | Edmonsoft Countdown, Coming Soon, Maintenance - Countdown & Clock | 14/3/2022 | 17/6/2026 | The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Media (4.3) | 0.47% | — | Wpdevart Coming Soon AND Maintenance Mode | 21/2/2022 | 17/6/2026 | The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack | |
| Modificada | Media (4.3) | 0.35% | — | Wpdevart Coming Soon AND Maintenance Mode | 21/2/2022 | 17/6/2026 | The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users | |
| Modificada | Media (6.1) | 0.68% | — | Compassplus Tranzware OnlineCompassplus Tranzware Online Financial Institution Maintenance Interface | 14/2/2022 | 17/6/2026 | A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2.19.4 25.The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to… | |
| Modificada | Media (5.3) | 1.1% | — | NEC Univerge Dt830 FirmwareNEC Univerge Dt820 FirmwareNEC Univerge Dt930 FirmwareNEC Univerge Dt900 Data Maintenance Tool+2 | 1/2/2022 | 17/6/2026 | UNIVERGE DT 820 V3.2.7.0 and prior, UNIVERGE DT 830 V5.2.7.0 and prior, UNIVERGE DT 930 V2.4.0.0 and prior, IP Phone Manager V8.9.1 and prior, Data Maintenance Tool for DT900 Series V5.3.0.0 and prior, Data Maintenance Tool for DT800 Series V4.2.0.0 and prior allows a remote attacker who can access to the internal… | |
| Modificada | Alta (8.8) | 0.64% | — | Fresenius-kabi Agilia Connect FirmwareFresenius-kabi Agilia Partner Maintenance SoftwareFresenius-kabi Vigilant CenteriumFresenius-kabi Vigilant Insight+2 | 21/1/2022 | 17/6/2026 | Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across all instances. An attacker in possession of the password may gain privileges on all installations of this software. |