Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

393 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.3%—Didotech Engineering & Lifecycle Management15/9/202317/6/2026
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the query parameter in models/base_client.py component.
ModificadaAlta (8.8)1.3%—Didotech Engineering & Lifecycle Management15/9/202317/6/2026
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the request parameter in models/base_client.py component.
ModificadaAlta (8.8)1.3%—Didotech Engineering & Lifecycle Management15/9/202317/6/2026
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the select parameter in models/base_client.py component.
ModificadaMedia (6.1)1.0%💥 ExploitAjaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+424/9/202317/6/2026
All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite…
ModificadaAlta (7.5)0.89%—Dotnetfoundation C# Language Server Protocol17/7/202317/6/2026
A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serialization/SerializerBase.cs of the component JSON Serializer. The manipulation leads to resource…
ModificadaAlta (7.5)1.1%—Dottie Project Dottie10/6/202317/6/2026
Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the set() function and the current variable in the /dottie.js file.
ModificadaMedia (4.8)0.40%—Dotcamp WP Table Builder3/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Table Builder plugin <= 1.4.6 versions.
ModificadaMedia (5.4)0.43%—Dnnsoftware Dotnetnuke12/4/202317/6/2026
An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file.
ModificadaAlta (7.5)0.95%—Dot-lens Project Dot-lens6/3/202317/6/2026
All versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file.
ModificadaMedia (5.3)0.88%—Dotcms1/2/202317/6/2026
In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to download a large file. If done repeatedly, this will result in Tomcat request-thread exhaustion and ultimately a denial of any other requests.
ModificadaMedia (6.5)8.5%—Dotcms1/2/202317/6/2026
An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the dotCMS API can lead to Remote Code Execution.
ModificadaAlta (8.8)0.64%💥 PoCDotcms1/2/202317/6/2026
An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token generation leads to account takeover.
ModificadaMedia (6.5)0.87%—Dotcms1/2/202317/6/2026
In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to block any SSRF access to local IP addresses or private subnets. In resolving this URL, the TempFileAPI follows any 302 redirects that the remote URL returns. Because there is no re-validation of the…
ModificadaAlta (7.2)0.95%—Thedotstore Conditional Payment Methods FOR Woocommerce16/1/202317/6/2026
The Conditional Payment Methods for WooCommerce WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by [high privilege users such as admin|users with a role as low as admin.
ModificadaAlta (7.5)0.76%—Dottech Smart Campus System3/12/202217/6/2026
A vulnerability, which was classified as problematic, has been found in Dot Tech Smart Campus System. Affected by this issue is some unknown functionality of the file /services/Card/findUser. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the…
ModificadaMedia (6.1)1.3%—Dotcms10/11/202217/6/2026
dotCMS before 22.06 allows remote attackers to bypass intended access control and obtain sensitive information by using a semicolon in a URL to introduce a matrix parameter. (This is also fixed in 5.3.8.12, 21.06.9, and 22.03.2 for LTS users.) Some Java application frameworks, including those used by Spring or Tomcat,…
ModificadaCrítica (9.8)1.0%—Dotpdn Paint.net12/10/202217/6/2026
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).
ModificadaCrítica (9.8)1.0%—Dotpdn Paint.net12/10/202217/6/2026
dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).
ModificadaMedia (4.9)1.3%—Dnnsoftware Dotnetnuke30/9/202217/6/2026
Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.
ModificadaMedia (5.4)0.70%—Jenkins Dotci21/9/202217/6/2026
Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.
ModificadaCrítica (9.8)1.1%—Jenkins Dotci21/9/202217/6/2026
A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.
ModificadaCrítica (9.8)1.7%—Jenkins Dotci21/9/202217/6/2026
Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
ModificadaCrítica (9.8)1.4%—Dotnetcore Agileconfig18/8/202217/6/2026
Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.
ModificadaMedia (6.1)0.65%—Dotcms5/8/202217/6/2026
A Reflected Cross-site scripting (XSS) issue was discovered in dotCMS Core through 22.06. This occurs in the admin portal when the configuration has XSS_PROTECTION_ENABLED=false. NOTE: the vendor disputes this because the current product behavior, in effect, has XSS_PROTECTION_ENABLED=true in all configurations
ModificadaMedia (5.4)0.67%—Dnnsoftware Dotnetnuke20/7/202217/6/2026
DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.
Orbitaley — Vulnerabilidades