Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2837▲ 84 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

3325 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.3%—Sugarcrm17/6/202317/6/2026
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Bean Manipulation vulnerability has been identified in the REST API. By using a crafted request, custom PHP code can be injected through the REST API because of missing input validation. Regular user privileges can be used to…
ModificadaAlta (8.8)1.3%—Sugarcrm17/6/202317/6/2026
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnerability has been identified in the Notes module. By using crafted requests, custom PHP code can be injected and executed through the Notes module because of missing input validation. Regular user…
ModificadaCrítica (9.8)1.4%—Tp-link Archer Ax10 Firmware16/6/20239/7/2026
TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4.
ModificadaAlta (7.5)4.0%💥 ExploitCdata ARC16/6/202317/6/2026
CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).
ModificadaMedia (6.1)0.34%—Faceted Search Project Faceted Search16/6/202317/6/2026
The ke_search (aka Faceted Search) extension before 4.0.3, 4.1.x through 4.6.x before 4.6.6, and 5.x before 5.0.2 for TYPO3 allows XSS via indexed data.
ModificadaCrítica (9.1)0.90%—Microfocus Arcsight Logger13/6/202317/6/2026
Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0.
ModificadaMedia (6.1)0.47%—Microfocus Arcsight Logger13/6/202317/6/2026
Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0
ModificadaMedia (4.4)0.54%—Advanced-woo-search Advanced WOO Search9/6/202317/6/2026
The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.77 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject…
ModificadaMedia (4.4)0.56%—Fibosearch9/6/202317/6/2026
The FiboSearch - AJAX Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.23.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…
ModificadaAlta (8.8)1.3%—Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+127/6/202317/6/2026
Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or…
ModificadaAlta (8.8)1.4%—Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+67/6/202317/6/2026
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
ModificadaMedia (4.3)0.46%—Webberzone Better Search7/6/202317/6/2026
The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to import settings via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
ModificadaMedia (4.3)0.70%—Eyecix Jobsearch WP JOB Board7/6/202317/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls.
ModificadaAlta (8.8)1.2%—Eyecix Jobsearch WP JOB Board7/6/202317/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site.
ModificadaMedia (5.3)0.85%—Eyecix Jobsearch WP JOB Board7/6/202317/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.
ModificadaMedia (6.1)0.62%—Local Service Search Engine Management System Project Local Service Search Engine Management System31/5/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_area of the component POST Parameter Handler. The manipulation of the argument area with the input…
ModificadaMedia (5.3)0.19%—Libarchive29/5/202317/6/2026
Libarchive hasta la versión 3.6.2 puede hacer que los directorios tengan permisos de escritura global. La llamada "umask()" dentro del archivo "archive_write_disk_posix.c" cambia la máscara de usuario de todo el proceso durante un periodo de tiempo muy corto; una condición de carrera con otro hilo puede llevar a un…
ModificadaAlta (7.1)0.30%—Opentext Archive Center Administration24/5/202317/6/2026
The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft…
ModificadaAlta (8.8)0.26%💥 PoCInternet-formation Wp-advanced-search24/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WordPress WP-Advanced-Search plugin <= 3.3.8 versions.
ModificadaAlta (8.8)0.25%—Archivist Project Archivist22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.
ModificadaMedia (6.7)1.8%💥 PoCTp-link Archer Vr1600v Firmware19/5/202317/6/2026
A command injection vulnerability exists in the administrative web portal in TP-Link Archer VR1600V devices running firmware Versions <= 0.1.0. 0.9.1 v5006.0 Build 220518 Rel.32480n which allows remote attackers, authenticated to the administrative web portal as an administrator user to open an operating system level…
ModificadaBaja (3.3)0.49%—Microsoft Azure ARC Jumpstart18/5/202317/6/2026
Azure Arc Jumpstart Information Disclosure Vulnerability
ModificadaMedia (4.8)0.37%—Webhammer WP Custom Fields Search18/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Don Benjamin WP Custom Fields Search plugin <= 1.2.34 versions.
ModificadaMedia (5.4)0.36%—Tychesoftwares Arconix Shortcodes16/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Arconix Shortcodes plugin <= 2.1.7 versions.
ModificadaCrítica (9.8)2.7%💥 ExploitPrestashop Possearchproducts12/5/202317/6/2026
Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().