Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

153 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)1.5%—Tms-outsource Wpdatatables12/4/202117/6/2026
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to delete the data of another user that are present in the same table through id_key and id_val…
ModificadaAlta (8.1)1.2%—Tms-outsource Wpdatatables12/4/202117/6/2026
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user that are present in the same table by taking over the user…
ModificadaCrítica (9.8)4.6%—Wpdatatables8/2/202117/6/2026
wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection.
ModificadaAlta (7.3)3.7%💥 PoCDatatables.net16/12/202017/6/2026
All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.
ModificadaAlta (8.8)0.69%—Supsystic Data Tables Generator23/4/202017/6/2026
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.
ModificadaAlta (8.8)1.0%—Supsystic Data Tables Generator23/4/202017/6/2026
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
ModificadaCrítica (9.8)14%💥 ExploitFreereprintables Articlefr13/2/202017/6/2026
A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.
ModificadaMedia (5.5)0.58%—Freereprintables Articlefr15/1/202017/6/2026
Directory traversal vulnerability in application/templates/amelia/loadjs.php in Free Reprintables ArticleFR 3.0.7 and earlier allows local users to read arbitrary files via the s parameter.
ModificadaAlta (7.2)1.4%—Tms-outsource Wpdatatables Lite26/12/201917/6/2026
SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.1)0.94%—Tms-outsource Wpdatatables Lite26/12/201917/6/2026
Cross-site scripting vulnerability in wpDataTables Lite Version 2.0.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.8)1.0%—Websimon-tables Project Websimon-tables20/9/201917/6/2026
The websimon-tables plugin through 1.3.4 for WordPress has wp-admin/tools.php edit_style id XSS.
ModificadaAlta (8.8)1.9%—Jtrt Responsive Tables Project Jtrt Responsive Tables10/9/201917/6/2026
The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-tables-admin.php tableId parameter.
ModificadaMedia (4.2)1.8%—Netfilter Iptables12/7/201917/6/2026
A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted iptables-save file. This is related to add_param_to_argv in xshared.c.
ModificadaMedia (5.5)0.43%—Iptables-parse Project Iptables-parse Module7/6/201717/6/2026
The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.
ModificadaMedia (4.3)2.7%—Sprymedia Datatables11/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_testing/templates/6776.php.
ModificadaMedia (6.8)1.9%💥 ExploitFreereprintables Articlefr16/7/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request to dashboard/users/create/.
ModificadaMedia (4.3)4.0%💥 ExploitFreereprintables Articlefr16/7/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to dashboard/settings/categories/, (2) title or (3) rel parameter to dashboard/settings/links/, or (4) url parameter to…
ModificadaAlta (7.5)1.3%💥 ExploitFreereprintables Articlefr27/1/201517/6/2026
SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter to register/.
ModificadaMedia (4.3)1.9%—Freereprintables Articlefr27/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in Free Reprintables ArticleFR 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the q parameter to search/v/.
ModificadaAlta (7.5)4.6%💥 ExploitWpdatatables2/12/201417/6/2026
SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the table_id parameter in a get_wdtable action to wp-admin/admin-ajax.php.
ModificadaAlta (7.5)2.3%💥 ExploitFreereprintables Articlefr22/8/201417/6/2026
Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) get or (2) set action to rate.php.
ModificadaAlta (7.5)2.7%—Netfilter Iptables15/2/201416/6/2026
extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.
ModificadaMedia (4.3)1.3%—Stanislas Rolland Static Info Tables20/8/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Static Info Tables (static_info_tables) extension before 2.3.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)5.6%💥 ExploitOTS Labs Otsturntables6/9/200716/6/2026
Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a long file path in an m3u file.
ModificadaBaja (1.2)0.30%—Giptables Firewall9/6/200516/6/2026
GIPTables Firewall 1.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the temp.ip.addresses temporary file.
Orbitaley — Vulnerabilidades