Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

199 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.63%—Skymoonlabs Moveto26/2/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.
ModificadaAlta (7.1)0.54%—Progress Moveit Transfer17/1/202417/6/2026
In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead to computational errors within…
ModificadaAlta (8)2.7%—Microsoft Azure Storage Mover9/1/202417/6/2026
Azure Storage Mover Remote Code Execution Vulnerability
ModificadaAlta (7.5)40%💥 ExploitCodexonics Prime Mover8/1/202417/6/2026
The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.
ModificadaAlta (7.2)1.2%—Oretnom23 Packers AND Movers Management System30/11/202317/6/2026
SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manage_user&id file.
ModificadaAlta (8.8)0.25%—Supremo Bulk Comment Remove30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mike Strand Bulk Comment Remove allows Cross Site Request Forgery.This issue affects Bulk Comment Remove: from n/a through 2.
ModificadaAlta (7.2)0.70%—Progress Moveit Transfer29/11/202317/6/2026
In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associated with group administrators has been identified. It is possible for a group administrator to elevate a group members permissions to the role of an organization…
ModificadaMedia (6.1)0.51%—Progress Moveit Transfer29/11/202317/6/2026
In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a reflected cross-site scripting (XSS) vulnerability has been identified when MOVEit Gateway is used in conjunction with MOVEit Transfer. An attacker could craft a malicious payload targeting the system…
ModificadaAlta (8.8)0.26%—Themelocation Remove ADD TO Cart Woocommerce13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in themelocation Remove Add to Cart WooCommerce plugin <= 1.4.4.
ModificadaCrítica (9.8)0.55%—Appjetty Copy OR Move Comments6/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in biztechc Copy or Move Comments allows SQL Injection.This issue affects Copy or Move Comments: from n/a through 5.0.4.
ModificadaMedia (5.4)0.38%—Prasadkirpekar WP Meta AND Date Remover31/10/202317/6/2026
The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform…
ModificadaCrítica (9.8)0.63%—Oretnom23 Packers AND Movers Management System26/10/202317/6/2026
Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id.
ModificadaMedia (6.1)0.39%—Appjetty Copy OR Move Comments25/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Biztechc Copy or Move Comments plugin <= 5.0.4 versions.
ModificadaAlta (8.8)0.23%—Joakimling Remove Slug From Custom Post Type9/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Joakim Ling Remove slug from custom post type plugin <= 1.0.3 versions.
ModificadaAlta (8.8)0.25%—Remove/hide Author, Date, Category Like Entry-meta Project Remove/hide Author, Date, Category Like Entry-meta6/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Remove/hide Author, Date, Category Like Entry-Meta plugin <= 2.1 versions.
ModificadaCrítica (9.8)0.99%—Oretnom23 Packers AND Movers Management System28/9/202317/6/2026
Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.
ModificadaAlta (8.8)0.70%—Progress Moveit Transfer20/9/202317/6/2026
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer…
ModificadaMedia (6.1)0.55%—Progress Moveit Transfer20/9/202317/6/2026
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a reflected cross-site scripting (XSS) vulnerability has been identified in MOVEit Transfer's web interface. An attacker could craft a malicious payload targeting MOVEit Transfer users…
ModificadaAlta (7.2)0.68%—Progress Moveit Transfer20/9/202317/6/2026
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer web interface that could allow a MOVEit system administrator account to gain unauthorized access to the MOVEit…
ModificadaAlta (7.5)1.1%—Aptosfoundation AptosMove Project MoveMystenlabs SUI8/9/202317/6/2026
CMysten Labs Sui blockchain v1.2.0 was discovered to contain a stack overflow via the component /spec/openrpc.json.
ModificadaCrítica (9.1)95%💥 ExploitProgress Moveit Transfer5/7/202317/6/2026
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to…
ModificadaAlta (7.5)72%—Progress Moveit Transfer5/7/202317/6/2026
In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.
ModificadaAlta (8.1)81%—Progress Moveit Transfer5/7/202317/6/2026
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application that could allow an authenticated attacker to gain unauthorized…
ModificadaAlta (7.8)0.24%—Trellix Move3/7/202317/6/2026
An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe). The misconfiguration allowed an unauthorized local user to insert arbitrary code into the unquoted service path to obtain privilege escalation and stop antimalware services.
ModificadaMedia (4.3)0.39%—Websitescanner Remove Schema1/7/202317/6/2026
The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the validate() function. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted…
Orbitaley — Vulnerabilidades