Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2840▲ 88 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
3325 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.32% | — | Tp-link Archer C7 Firmware | 11/5/2023 | 17/6/2026 | A vulnerability has been found in TP-Link Archer C7v2 v2_en_us_180114 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component GET Request Parameter Handler. The manipulation leads to denial of service. The attack can only be done within the local network. The… | |
| Modificada | Media (4.8) | 0.37% | — | WP Search Analytics Project WP Search Analytics | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cornel Raiu WP Search Analytics plugin <= 1.4.5 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Esri Portal FOR Arcgis | 10/5/2023 | 17/6/2026 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data rendered). | |
| Modificada | Alta (8.8) | 0.27% | — | Esri Portal FOR Arcgis | 9/5/2023 | 17/6/2026 | There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authorized user into executing unwanted actions. | |
| Analizada | Media (6.1) | 0.54% | — | Esri Portal FOR Arcgis | 9/5/2023 | 17/6/2026 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. | |
| Analizada | Media (6.1) | 0.50% | — | Esri Portal FOR Arcgis | 9/5/2023 | 17/6/2026 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and before which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. | |
| Analizada | Media (6.1) | 0.49% | — | Esri Portal FOR Arcgis | 9/5/2023 | 17/6/2026 | There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks. | |
| Modificada | Media (5.4) | 0.32% | — | Esri Portal FOR Arcgis | 9/5/2023 | 17/6/2026 | Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to access. | |
| Modificada | Media (5.5) | 0.15% | — | SAP S4coreSAP Vendor Master Hierarchy | 9/5/2023 | 17/6/2026 | Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to… | |
| Modificada | Media (5.9) | 0.46% | — | Amazon OpensearchAmazon Opensearch Security | 8/5/2023 | 17/6/2026 | OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10 and 2.7.0, there is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to… | |
| Modificada | Media (6.1) | 0.38% | — | Catchthemes Darcie | 4/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Catch Themes Darcie theme <= 1.1.5 versions. | |
| Modificada | Media (5.4) | 0.29% | — | Archerirm Archer | 1/5/2023 | 17/6/2026 | Archer Platform 6.8 before 6.12 P6 HF1 (6.12.0.6.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. 6.11.P4 (6.11.0.4) is also a fixed release. | |
| Modificada | Media (6.1) | 0.41% | — | Arc2 Project Arc2 | 26/4/2023 | 16/6/2026 | ARC (aka ARC2) through 2011-12-01 allows reflected XSS via the end_point.php query parameter in an output=htmltab action. | |
| Modificada | Crítica (9.8) | 0.75% | — | Arc2 Project Arc2 | 26/4/2023 | 16/6/2026 | ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause. | |
| Modificada | Media (4.8) | 0.37% | — | Simple Yearly Archive Project Simple Yearly Archive | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Archivist - Custom Archive Templates Project Archivist - Custom Archive Templates | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Wp-dreams Ajax Search | 24/4/2023 | 17/6/2026 | The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting them back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 0.49% | — | Wp-dreams Ajax Search | 24/4/2023 | 17/6/2026 | The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.4) | 0.36% | — | Ultimate WP Query Search Filter Project Ultimate WP Query Search Filter | 23/4/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in TC Ultimate WP Query Search Filter plugin <= 1.0.10 versions. | |
| Modificada | Media (6.5) | 0.84% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. User input coming from the `variable_name` and `variable_value` parameter value in the `sql/instance.py` `param_edit` endpoint is passed to a… | |
| Modificada | Media (6.5) | 0.83% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. User input coming from the `db_name` in the `sql/data_dictionary.py` `table_list` endpoint is passed to the methods that follow in a given SQL… | |
| Modificada | Media (6.5) | 0.84% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. Affected versions are subject to SQL injection in the `data_dictionary.py` `table_info`. User input coming from the `db_name` in and the… | |
| Modificada | Media (6.5) | 0.83% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. Affected versions are subject to SQL injection in the `optimize_sqltuningadvisor` method of `sql_optimize.py`. User input coming from the… | |
| Modificada | Media (6.5) | 0.83% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases.Affected versions are subject to SQL injection in the `explain` method in `sql_optimize.py`. User input coming from the `db_name` parameter… | |
| Modificada | Media (6.5) | 0.83% | — | Archerydms Archery | 19/4/2023 | 17/6/2026 | Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. Affected versions are subject to SQL injection in the `sql_api/api_workflow.py` endpoint `ExecuteCheck` which passes unfiltered input to the… |