Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2840▲ 88 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

3325 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.32%—Tp-link Archer C7 Firmware11/5/202317/6/2026
A vulnerability has been found in TP-Link Archer C7v2 v2_en_us_180114 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component GET Request Parameter Handler. The manipulation leads to denial of service. The attack can only be done within the local network. The…
ModificadaMedia (4.8)0.37%—WP Search Analytics Project WP Search Analytics10/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cornel Raiu WP Search Analytics plugin <= 1.4.5 versions.
ModificadaMedia (5.4)0.44%—Esri Portal FOR Arcgis10/5/202317/6/2026
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data rendered).
ModificadaAlta (8.8)0.27%—Esri Portal FOR Arcgis9/5/202317/6/2026
There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authorized user into executing unwanted actions.
AnalizadaMedia (6.1)0.54%—Esri Portal FOR Arcgis9/5/202317/6/2026
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
AnalizadaMedia (6.1)0.50%—Esri Portal FOR Arcgis9/5/202317/6/2026
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and before which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
AnalizadaMedia (6.1)0.49%—Esri Portal FOR Arcgis9/5/202317/6/2026
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
ModificadaMedia (5.4)0.32%—Esri Portal FOR Arcgis9/5/202317/6/2026
Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to access.
ModificadaMedia (5.5)0.15%—SAP S4coreSAP Vendor Master Hierarchy9/5/202317/6/2026
Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to…
ModificadaMedia (5.9)0.46%—Amazon OpensearchAmazon Opensearch Security8/5/202317/6/2026
OpenSearch is open-source software suite for search, analytics, and observability applications. Prior to versions 1.3.10 and 2.7.0, there is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to…
ModificadaMedia (6.1)0.38%—Catchthemes Darcie4/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Catch Themes Darcie theme <= 1.1.5 versions.
ModificadaMedia (5.4)0.29%—Archerirm Archer1/5/202317/6/2026
Archer Platform 6.8 before 6.12 P6 HF1 (6.12.0.6.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. 6.11.P4 (6.11.0.4) is also a fixed release.
ModificadaMedia (6.1)0.41%—Arc2 Project Arc226/4/202316/6/2026
ARC (aka ARC2) through 2011-12-01 allows reflected XSS via the end_point.php query parameter in an output=htmltab action.
ModificadaCrítica (9.8)0.75%—Arc2 Project Arc226/4/202316/6/2026
ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause.
ModificadaMedia (4.8)0.37%—Simple Yearly Archive Project Simple Yearly Archive25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Oliver Schlöbe Simple Yearly Archive plugin <= 2.1.8 versions.
ModificadaMedia (4.8)0.37%—Archivist - Custom Archive Templates Project Archivist - Custom Archive Templates25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.
ModificadaMedia (6.1)0.46%—Wp-dreams Ajax Search24/4/202317/6/2026
The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting them back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.49%—Wp-dreams Ajax Search24/4/202317/6/2026
The Ajax Search Lite WordPress plugin before 4.11.1, Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape a parameter before outputting it back in a response of an AJAX action, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (5.4)0.36%—Ultimate WP Query Search Filter Project Ultimate WP Query Search Filter23/4/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in TC Ultimate WP Query Search Filter plugin <= 1.0.10 versions.
ModificadaMedia (6.5)0.84%—Archerydms Archery19/4/202317/6/2026
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. User input coming from the `variable_name` and `variable_value` parameter value in the `sql/instance.py` `param_edit` endpoint is passed to a…
ModificadaMedia (6.5)0.83%—Archerydms Archery19/4/202317/6/2026
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. User input coming from the `db_name` in the `sql/data_dictionary.py` `table_list` endpoint is passed to the methods that follow in a given SQL…
ModificadaMedia (6.5)0.84%—Archerydms Archery19/4/202317/6/2026
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. Affected versions are subject to SQL injection in the `data_dictionary.py` `table_info`. User input coming from the `db_name` in and the…
ModificadaMedia (6.5)0.83%—Archerydms Archery19/4/202317/6/2026
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. Affected versions are subject to SQL injection in the `optimize_sqltuningadvisor` method of `sql_optimize.py`. User input coming from the…
ModificadaMedia (6.5)0.83%—Archerydms Archery19/4/202317/6/2026
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases.Affected versions are subject to SQL injection in the `explain` method in `sql_optimize.py`. User input coming from the `db_name` parameter…
ModificadaMedia (6.5)0.83%—Archerydms Archery19/4/202317/6/2026
Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. Affected versions are subject to SQL injection in the `sql_api/api_workflow.py` endpoint `ExecuteCheck` which passes unfiltered input to the…