Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.55% | — | Apusthemes WP Private Messaging | 21/2/2023 | 17/6/2026 | The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID. | |
| Modificada | Media (5.3) | 0.73% | — | Lcweb Privatecontent | 30/1/2023 | 17/6/2026 | The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side validation in versions up to, and including, 8.4.3. This is due to the plugin checking if an IP had been blocklist via client-side scripts rather than server-side. This makes it possible for… | |
| Modificada | Baja (3.3) | 0.18% | — | Intel Wlan Authentication AND Privacy Infrastructure | 11/11/2022 | 17/6/2026 | Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (8.8) | 1.0% | — | Mediajedi User Private Files | 8/8/2022 | 23/6/2026 | The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded. | |
| Modificada | Crítica (9.8) | 0.69% | — | Private Cloud Management Platform Project Private Cloud Management Platform | 5/8/2022 | 17/6/2026 | A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Handler. The manipulation leads to improper authentication. It is possible to launch the attack… | |
| Modificada | Media (4.3) | 0.43% | — | Zatzlabs MY Private Site | 27/6/2022 | 17/6/2026 | The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (5.4) | 0.55% | — | Private Messages Project Private Messages | 15/6/2022 | 17/6/2026 | Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress <= 2.1.10 at WordPress. | |
| Modificada | Media (4.3) | 0.40% | — | Private Messages Project Private Messages | 15/6/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Private Messages For WordPress plugin <= 2.1.10 at WordPress allows attackers to send messages. | |
| Modificada | Media (4.3) | 0.43% | — | Private Files Project Private Files | 13/6/2022 | 17/6/2026 | The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow attackers to make a logged in admin perform such action via a CSRF attack and make the blog public | |
| Modificada | Alta (7.5) | 0.95% | — | Jamf Private Access | 7/6/2022 | 17/6/2026 | Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in the internal infrastructure, aka WND-44801. | |
| Modificada | Media (6.1) | 1.4% | — | Privatebin | 11/4/2022 | 17/6/2026 | PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In PrivateBin < v1.4.0 a cross-site scripting (XSS) vulnerability was found. The vulnerability is present in all versions from v0.21 of the project, which was at the time still called ZeroBin. The issue is… | |
| Modificada | Media (6.1) | 0.80% | — | Inpsyde Akismet Privacy Policies | 28/3/2022 | 17/6/2026 | The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Baja (2.5) | 0.27% | — | Mirmay File ManagerMirmay Secure Private Browser | 28/3/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in Mirmay Secure Private Browser and File Manager up to 2.5. Affected is the Auto Lock. A race condition leads to a local authentication bypass. The exploit has been disclosed to the public and may be used. | |
| Modificada | Alta (7.5) | 7.9% | — | JenkinsXstreamFedoraproject FedoraDebian Linux+7 | 1/2/2022 | 17/6/2026 | XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input… | |
| Modificada | Media (6.6) | 98% | 💥 PoC | Apache Log4jOracle Communications Diameter Signaling RouterOracle Communications Interactive Session RecorderOracle Primavera Gateway+18 | 28/12/2021 | 17/6/2026 | Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (8.8) | 1.7% | — | Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+39 | 11/10/2021 | 17/6/2026 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the… | |
| Modificada | Alta (7.5) | 7.4% | — | Apache Santuario XML Security FOR JavaApache CXFApache TomeeDebian Linux+14 | 19/9/2021 | 25/8/2026 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a… | |
| Modificada | Alta (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 21/7/2021 | 25/8/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modificada | Alta (7.8) | 0.36% | — | Openvpn Private Tunnel | 26/5/2021 | 17/6/2026 | Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks in /tmp. | |
| Modificada | Media (5.5) | 0.38% | — | Dekart Private Disk | 16/2/2021 | 17/6/2026 | In Dekart Private Disk 2.15, invalid use of the Type3 user buffer for IOCTL codes using METHOD_NEITHER results in arbitrary memory dereferencing. | |
| Modificada | Alta (7.5) | 1.5% | — | Privateoctopus Picoquic | 8/2/2021 | 17/6/2026 | picoquic (before 3rd of July 2020) allows attackers to cause a denial of service (infinite loop) via a crafted QUIC frame, related to the picoquic_decode_frames and picoquic_decode_stream_frame functions and epoch==3. | |
| Modificada | Alta (7.5) | 11% | — | Apache ActivemqApache ArtemisNetapp Oncommand Workflow AutomationDebian Linux+4 | 27/1/2021 | 17/6/2026 | The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no… | |
| Modificada | Media (4.8) | 8.3% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkOracle Blockchain Platform+13 | 28/11/2020 | 17/6/2026 | In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely… | |
| Modificada | Crítica (9.8) | 3.1% | — | Private-ip Project Private-ip | 23/11/2020 | 17/6/2026 | Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker can perform a large range of requests to ARIN reserved IP ranges, resulting in an indeterminable number of critical attack vectors, allowing remote attackers to request… |