Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
4611 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | Rigorous-digital Dovetail | 8/8/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) almacenado con necesidad de autenticación (permisos de administrador o superior) en el plugin Rigorous & Factory Pattern Dovetail en versiones anteriores, e incluyendo, la 1.2.13. | |
| Modificada | Media (6.1) | 0.38% | — | Eggemplo Woocommerce Email Report | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in eggemplo Woocommerce Email Report plugin <= 2.4 versions. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | Availability Booking Calendar 5.0 de PHPJabbers es vulnerable a la toma de control de cuentas de usuario mediante el cambio de nombre de usuario/contraseña. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | Availability Booking Calendar 5.0 de PHP Jabbers es vulnerable al Control de Acceso Incorrecto. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | Availability Booking Calendar 5.0 de PHPJabbers es vulnerable a un Control de Acceso Incorrecto debido a una incorrecta validación de entrada del parámetro de contraseña. | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Phpjabbers Availability Booking Calendar | 3/8/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad en PHP Jabbers Availability Booking Calendar v5.0 y se ha clasificado como problemática. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo "/index.php". La manipulación del argumento "session_id" conduce a Cross-Site Scripting (XSS). El ataque puede lanzarse de… | |
| Modificada | Alta (7.2) | 1.1% | — | Phpgurukul Rail Pass Management System | 28/7/2023 | 17/6/2026 | Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-cateogry-detail.php file. | |
| Modificada | Alta (7.2) | 1.3% | — | Phpgurukul Rail Pass Management System | 28/7/2023 | 17/6/2026 | Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-pass-detail.php file. | |
| Modificada | Media (4.8) | 0.59% | — | Phpgurukul Rail Pass Management System | 28/7/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the emial parameter of admin-profile.php. | |
| Modificada | Media (4.8) | 0.58% | — | Phpgurukul Rail Pass Management System | 28/7/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the adminname parameter of admin-profile.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Phpgurukul Rail Pass Management System | 28/7/2023 | 17/6/2026 | Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-pass-detail.php file. | |
| Modificada | Alta (7.2) | 1.3% | — | Phpgurukul Rail Pass Management System | 28/7/2023 | 17/6/2026 | Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-enquiry.php file. | |
| Modificada | Alta (7.5) | 0.94% | — | Sailsjs Sails | 27/7/2023 | 17/6/2026 | Sails is a realtime MVC Framework for Node.js. In Sails apps prior to version 1.5.7,, an attacker can send a virtual request that will cause the node process to crash. This behavior was fixed in Sails v1.5.7. As a workaround, disable the sockets hook and remove the `sails.io.js` client. | |
| Modificada | Media (6.1) | 0.44% | — | Atmail | 27/7/2023 | 17/6/2026 | Atmail v5.62 permite ataques de tipo Cross-Site Scripting (XSS) a través del campo "mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms". | |
| Modificada | Media (6.1) | 1.6% | 💥 Exploit | Icewarp ServerIcewarp Mail Server | 27/7/2023 | 9/7/2026 | Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter. | |
| Modificada | Media (5.4) | 0.56% | — | Gzscripts Availability Booking Calendar PHP | 27/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in GZ Scripts Availability Booking Calendar PHP 1.0. This affects an unknown part of the file /index.php?controller=GzUser&action=edit&id=1 of the component Image Handler. The manipulation of the argument img leads to cross site scripting. It is possible… | |
| Modificada | Media (5.4) | 0.56% | — | Gzscripts Availability Booking Calendar PHP | 27/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in GZ Scripts Availability Booking Calendar PHP 1.0. Affected by this issue is some unknown functionality of the file index.php of the component HTTP POST Request Handler. The manipulation of the argument promo_code leads to cross site scripting. The… | |
| Modificada | Alta (8.8) | 0.25% | — | WP Reroute Email Project WP Reroute Email | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sajjad Hossain WP Reroute Email plugin <= 1.4.6 versions. | |
| Modificada | Baja (3.5) | 0.14% | — | BD Guardrails CQI Reporter | 13/7/2023 | 17/6/2026 | An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker. | |
| Modificada | Media (6.7) | 0.18% | — | BD Alaris Guardrails Editor | 13/7/2023 | 17/6/2026 | A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs. | |
| Modificada | Media (6.1) | 0.46% | — | WP Reroute Email Project WP Reroute Email | 12/7/2023 | 17/6/2026 | The WP Reroute Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.1) | 0.44% | — | Webdesignmunich Mail Queue | 12/7/2023 | 17/6/2026 | The Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.1) | 0.46% | — | Lanacodes Lana Email Logger | 12/7/2023 | 17/6/2026 | The Lana Email Logger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, Lana Email Logger due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Media (6.1) | 0.60% | — | Instareza Mail Control | 12/7/2023 | 17/6/2026 | The Mail Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 0.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.1) | 0.46% | — | Oacstudio Mailtree LOG Mail | 12/7/2023 | 17/6/2026 | The Mailtree Log Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… |