Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
393 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.3% | — | Didotech Engineering & Lifecycle Management | 15/9/2023 | 17/6/2026 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the query parameter in models/base_client.py component. | |
| Modificada | Alta (8.8) | 1.3% | — | Didotech Engineering & Lifecycle Management | 15/9/2023 | 17/6/2026 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the request parameter in models/base_client.py component. | |
| Modificada | Alta (8.8) | 1.3% | — | Didotech Engineering & Lifecycle Management | 15/9/2023 | 17/6/2026 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the select parameter in models/base_client.py component. | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modificada | Alta (7.5) | 0.89% | — | Dotnetfoundation C# Language Server Protocol | 17/7/2023 | 17/6/2026 | A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serialization/SerializerBase.cs of the component JSON Serializer. The manipulation leads to resource… | |
| Modificada | Alta (7.5) | 1.1% | — | Dottie Project Dottie | 10/6/2023 | 17/6/2026 | Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the set() function and the current variable in the /dottie.js file. | |
| Modificada | Media (4.8) | 0.40% | — | Dotcamp WP Table Builder | 3/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Table Builder plugin <= 1.4.6 versions. | |
| Modificada | Media (5.4) | 0.43% | — | Dnnsoftware Dotnetnuke | 12/4/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file. | |
| Modificada | Alta (7.5) | 0.95% | — | Dot-lens Project Dot-lens | 6/3/2023 | 17/6/2026 | All versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file. | |
| Modificada | Media (5.3) | 0.88% | — | Dotcms | 1/2/2023 | 17/6/2026 | In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to download a large file. If done repeatedly, this will result in Tomcat request-thread exhaustion and ultimately a denial of any other requests. | |
| Modificada | Media (6.5) | 8.5% | — | Dotcms | 1/2/2023 | 17/6/2026 | An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the dotCMS API can lead to Remote Code Execution. | |
| Modificada | Alta (8.8) | 0.64% | 💥 PoC | Dotcms | 1/2/2023 | 17/6/2026 | An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token generation leads to account takeover. | |
| Modificada | Media (6.5) | 0.87% | — | Dotcms | 1/2/2023 | 17/6/2026 | In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to block any SSRF access to local IP addresses or private subnets. In resolving this URL, the TempFileAPI follows any 302 redirects that the remote URL returns. Because there is no re-validation of the… | |
| Modificada | Alta (7.2) | 0.95% | — | Thedotstore Conditional Payment Methods FOR Woocommerce | 16/1/2023 | 17/6/2026 | The Conditional Payment Methods for WooCommerce WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by [high privilege users such as admin|users with a role as low as admin. | |
| Modificada | Alta (7.5) | 0.76% | — | Dottech Smart Campus System | 3/12/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Dot Tech Smart Campus System. Affected by this issue is some unknown functionality of the file /services/Card/findUser. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 1.3% | — | Dotcms | 10/11/2022 | 17/6/2026 | dotCMS before 22.06 allows remote attackers to bypass intended access control and obtain sensitive information by using a semicolon in a URL to introduce a matrix parameter. (This is also fixed in 5.3.8.12, 21.06.9, and 22.03.2 for LTS users.) Some Java application frameworks, including those used by Spring or Tomcat,… | |
| Modificada | Crítica (9.8) | 1.0% | — | Dotpdn Paint.net | 12/10/2022 | 17/6/2026 | dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2). | |
| Modificada | Crítica (9.8) | 1.0% | — | Dotpdn Paint.net | 12/10/2022 | 17/6/2026 | dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2). | |
| Modificada | Media (4.9) | 1.3% | — | Dnnsoftware Dotnetnuke | 30/9/2022 | 17/6/2026 | Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0. | |
| Modificada | Media (5.4) | 0.70% | — | Jenkins Dotci | 21/9/2022 | 17/6/2026 | Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Jenkins Dotci | 21/9/2022 | 17/6/2026 | A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits. | |
| Modificada | Crítica (9.8) | 1.7% | — | Jenkins Dotci | 21/9/2022 | 17/6/2026 | Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.4% | — | Dotnetcore Agileconfig | 18/8/2022 | 17/6/2026 | Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access. | |
| Modificada | Media (6.1) | 0.65% | — | Dotcms | 5/8/2022 | 17/6/2026 | A Reflected Cross-site scripting (XSS) issue was discovered in dotCMS Core through 22.06. This occurs in the admin portal when the configuration has XSS_PROTECTION_ENABLED=false. NOTE: the vendor disputes this because the current product behavior, in effect, has XSS_PROTECTION_ENABLED=true in all configurations | |
| Modificada | Media (5.4) | 0.67% | — | Dnnsoftware Dotnetnuke | 20/7/2022 | 17/6/2026 | DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload. |