Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
199 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.63% | — | Skymoonlabs Moveto | 26/2/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. | |
| Modificada | Alta (7.1) | 0.54% | — | Progress Moveit Transfer | 17/1/2024 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead to computational errors within… | |
| Modificada | Alta (8) | 2.7% | — | Microsoft Azure Storage Mover | 9/1/2024 | 17/6/2026 | Azure Storage Mover Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 40% | 💥 Exploit | Codexonics Prime Mover | 8/1/2024 | 17/6/2026 | The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files. | |
| Modificada | Alta (7.2) | 1.2% | — | Oretnom23 Packers AND Movers Management System | 30/11/2023 | 17/6/2026 | SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manage_user&id file. | |
| Modificada | Alta (8.8) | 0.25% | — | Supremo Bulk Comment Remove | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mike Strand Bulk Comment Remove allows Cross Site Request Forgery.This issue affects Bulk Comment Remove: from n/a through 2. | |
| Modificada | Alta (7.2) | 0.70% | — | Progress Moveit Transfer | 29/11/2023 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associated with group administrators has been identified. It is possible for a group administrator to elevate a group members permissions to the role of an organization… | |
| Modificada | Media (6.1) | 0.51% | — | Progress Moveit Transfer | 29/11/2023 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a reflected cross-site scripting (XSS) vulnerability has been identified when MOVEit Gateway is used in conjunction with MOVEit Transfer. An attacker could craft a malicious payload targeting the system… | |
| Modificada | Alta (8.8) | 0.26% | — | Themelocation Remove ADD TO Cart Woocommerce | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themelocation Remove Add to Cart WooCommerce plugin <= 1.4.4. | |
| Modificada | Crítica (9.8) | 0.55% | — | Appjetty Copy OR Move Comments | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in biztechc Copy or Move Comments allows SQL Injection.This issue affects Copy or Move Comments: from n/a through 5.0.4. | |
| Modificada | Media (5.4) | 0.38% | — | Prasadkirpekar WP Meta AND Date Remover | 31/10/2023 | 17/6/2026 | The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform… | |
| Modificada | Crítica (9.8) | 0.63% | — | Oretnom23 Packers AND Movers Management System | 26/10/2023 | 17/6/2026 | Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id. | |
| Modificada | Media (6.1) | 0.39% | — | Appjetty Copy OR Move Comments | 25/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Biztechc Copy or Move Comments plugin <= 5.0.4 versions. | |
| Modificada | Alta (8.8) | 0.23% | — | Joakimling Remove Slug From Custom Post Type | 9/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Joakim Ling Remove slug from custom post type plugin <= 1.0.3 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Remove/hide Author, Date, Category Like Entry-meta Project Remove/hide Author, Date, Category Like Entry-meta | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Remove/hide Author, Date, Category Like Entry-Meta plugin <= 2.1 versions. | |
| Modificada | Crítica (9.8) | 0.99% | — | Oretnom23 Packers AND Movers Management System | 28/9/2023 | 17/6/2026 | Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php. | |
| Modificada | Alta (8.8) | 0.70% | — | Progress Moveit Transfer | 20/9/2023 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer… | |
| Modificada | Media (6.1) | 0.55% | — | Progress Moveit Transfer | 20/9/2023 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a reflected cross-site scripting (XSS) vulnerability has been identified in MOVEit Transfer's web interface. An attacker could craft a malicious payload targeting MOVEit Transfer users… | |
| Modificada | Alta (7.2) | 0.68% | — | Progress Moveit Transfer | 20/9/2023 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer web interface that could allow a MOVEit system administrator account to gain unauthorized access to the MOVEit… | |
| Modificada | Alta (7.5) | 1.1% | — | Aptosfoundation AptosMove Project MoveMystenlabs SUI | 8/9/2023 | 17/6/2026 | CMysten Labs Sui blockchain v1.2.0 was discovered to contain a stack overflow via the component /spec/openrpc.json. | |
| Modificada | Crítica (9.1) | 95% | 💥 Exploit | Progress Moveit Transfer | 5/7/2023 | 17/6/2026 | In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to… | |
| Modificada | Alta (7.5) | 72% | — | Progress Moveit Transfer | 5/7/2023 | 17/6/2026 | In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly. | |
| Modificada | Alta (8.1) | 81% | — | Progress Moveit Transfer | 5/7/2023 | 17/6/2026 | In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application that could allow an authenticated attacker to gain unauthorized… | |
| Modificada | Alta (7.8) | 0.24% | — | Trellix Move | 3/7/2023 | 17/6/2026 | An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe). The misconfiguration allowed an unauthorized local user to insert arbitrary code into the unquoted service path to obtain privilege escalation and stop antimalware services. | |
| Modificada | Media (4.3) | 0.39% | — | Websitescanner Remove Schema | 1/7/2023 | 17/6/2026 | The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the validate() function. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted… |