Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
153 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.5% | — | Tms-outsource Wpdatatables | 12/4/2021 | 17/6/2026 | The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to delete the data of another user that are present in the same table through id_key and id_val… | |
| Modificada | Alta (8.1) | 1.2% | — | Tms-outsource Wpdatatables | 12/4/2021 | 17/6/2026 | The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user that are present in the same table by taking over the user… | |
| Modificada | Crítica (9.8) | 4.6% | — | Wpdatatables | 8/2/2021 | 17/6/2026 | wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection. | |
| Modificada | Alta (7.3) | 3.7% | 💥 PoC | Datatables.net | 16/12/2020 | 17/6/2026 | All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806. | |
| Modificada | Alta (8.8) | 0.69% | — | Supsystic Data Tables Generator | 23/4/2020 | 17/6/2026 | The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS. | |
| Modificada | Alta (8.8) | 1.0% | — | Supsystic Data Tables Generator | 23/4/2020 | 17/6/2026 | The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions. | |
| Modificada | Crítica (9.8) | 14% | 💥 Exploit | Freereprintables Articlefr | 13/2/2020 | 17/6/2026 | A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information. | |
| Modificada | Media (5.5) | 0.58% | — | Freereprintables Articlefr | 15/1/2020 | 17/6/2026 | Directory traversal vulnerability in application/templates/amelia/loadjs.php in Free Reprintables ArticleFR 3.0.7 and earlier allows local users to read arbitrary files via the s parameter. | |
| Modificada | Alta (7.2) | 1.4% | — | Tms-outsource Wpdatatables Lite | 26/12/2019 | 17/6/2026 | SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.1) | 0.94% | — | Tms-outsource Wpdatatables Lite | 26/12/2019 | 17/6/2026 | Cross-site scripting vulnerability in wpDataTables Lite Version 2.0.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.8) | 1.0% | — | Websimon-tables Project Websimon-tables | 20/9/2019 | 17/6/2026 | The websimon-tables plugin through 1.3.4 for WordPress has wp-admin/tools.php edit_style id XSS. | |
| Modificada | Alta (8.8) | 1.9% | — | Jtrt Responsive Tables Project Jtrt Responsive Tables | 10/9/2019 | 17/6/2026 | The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-tables-admin.php tableId parameter. | |
| Modificada | Media (4.2) | 1.8% | — | Netfilter Iptables | 12/7/2019 | 17/6/2026 | A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted iptables-save file. This is related to add_param_to_argv in xshared.c. | |
| Modificada | Media (5.5) | 0.43% | — | Iptables-parse Project Iptables-parse Module | 7/6/2017 | 17/6/2026 | The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user. | |
| Modificada | Media (4.3) | 2.7% | — | Sprymedia Datatables | 11/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_testing/templates/6776.php. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Freereprintables Articlefr | 16/7/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request to dashboard/users/create/. | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Freereprintables Articlefr | 16/7/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to dashboard/settings/categories/, (2) title or (3) rel parameter to dashboard/settings/links/, or (4) url parameter to… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Freereprintables Articlefr | 27/1/2015 | 17/6/2026 | SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter to register/. | |
| Modificada | Media (4.3) | 1.9% | — | Freereprintables Articlefr | 27/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Free Reprintables ArticleFR 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the q parameter to search/v/. | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Wpdatatables | 2/12/2014 | 17/6/2026 | SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the table_id parameter in a get_wdtable action to wp-admin/admin-ajax.php. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Freereprintables Articlefr | 22/8/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) get or (2) set action to rate.php. | |
| Modificada | Alta (7.5) | 2.7% | — | Netfilter Iptables | 15/2/2014 | 16/6/2026 | extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant. | |
| Modificada | Media (4.3) | 1.3% | — | Stanislas Rolland Static Info Tables | 20/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Static Info Tables (static_info_tables) extension before 2.3.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 5.6% | 💥 Exploit | OTS Labs Otsturntables | 6/9/2007 | 16/6/2026 | Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a long file path in an m3u file. | |
| Modificada | Baja (1.2) | 0.30% | — | Giptables Firewall | 9/6/2005 | 16/6/2026 | GIPTables Firewall 1.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the temp.ip.addresses temporary file. |