Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

318 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)1.0%—Limesurvey3/9/202417/6/2026
An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php function
AnalizadaMedia (4.8)0.43%—Limesurvey3/9/202417/6/2026
A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file.
AnalizadaMedia (4.7)0.43%—Expresstech Quiz AND Survey Master26/8/202417/6/2026
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.
AplazadaMedia (5.5)0.35%—WordsurveyAI21/8/202417/6/2026
The WordSurvey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sounding_title’ parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject…
AnalizadaMedia (5.1)0.90%—Limesurvey17/8/202417/6/2026
A vulnerability was found in LimeSurvey 6.3.0-231016 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php of the component File Upload. The manipulation of the argument size leads to denial of service. The attack may be launched remotely. The exploit has been…
AnalizadaMedia (5.9)0.33%—Expresstech Quiz AND Survey Master3/8/202417/6/2026
The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
AnalizadaBaja (2.1)0.56%—Limesurvey21/7/202417/6/2026
A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey General Settings Handler. This manipulation of the argument Language…
ModificadaMedia (5.4)0.38%—Expresstech Quiz AND Survey Master11/7/202417/6/2026
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks
AnalizadaAlta (8.8)0.29%—Limesurvey9/7/202417/6/2026
Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of POST requests, but the same check isn't performed in the equivalent GET requests.
ModificadaAlta (8.8)0.59%—Expresstech Quiz AND Survey Master2/7/202417/6/2026
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role
AnalizadaMedia (5.5)0.35%—Expresstech Quiz AND Survey Master1/7/202417/6/2026
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.3)0.31%—Expresstech Quiz AND Survey Master14/6/202417/6/2026
Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16.
ModificadaMedia (6.5)0.48%—Expresstech Quiz AND Survey Master7/6/202417/6/2026
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AnalizadaMedia (4.8)0.42%—Ays-pro Survey Maker21/5/202417/6/2026
The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AplazadaMedia (6.1)0.28%—Surveyjs Form LibraryAI18/5/202417/6/2026
question_image.ts in SurveyJS Form Library before 1.10.4 allows contentMode=youtube XSS via the imageLink property.
AnalizadaAlta (8.8)0.70%—Surveyking14/5/202417/6/2026
An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.
AnalizadaCrítica (9.1)0.73%—Surveyking14/5/202417/6/2026
SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.
AnalizadaMedia (4.3)0.42%—Surveyking14/5/202417/6/2026
An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.
AplazadaMedia (5.9)0.34%—Expresstechsoftware Quiz AND Survey MasterAI11/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 8.2.2.
AnalizadaMedia (5.3)0.26%—Ays-pro Survey Maker3/4/202417/6/2026
Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.
AnalizadaMedia (6.1)0.36%—Ays-pro Survey Maker3/4/202417/6/2026
Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product with the administrative privilege.
AnalizadaMedia (6.1)0.68%—Limesurvey3/4/202417/6/2026
Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.
ModificadaMedia (5.4)0.39%—Ays-pro Survey Maker27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Reflected XSS.This issue affects Survey Maker: from n/a through 4.0.6.
AplazadaCrítica (9.3)2.0%💥 ExploitExpresstechlabs Quiz AND Survey MasterAI26/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.
AnalizadaMedia (6.1)0.51%—Devsoftbaltic Survey-creator21/3/202417/6/2026
Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute arbitrary code and obtain sensitive information via the title parameter in form.