Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.21% | — | Sharkdropship Irivyou | 13/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Zizou1988 IRivYou plugin <= 2.2.1 versions. | |
| Modificada | Media (6.1) | 0.41% | — | MD Jakir Hosen Tiger Forms - Drag AND Drop Form Builder | 2/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MD Jakir Hosen Tiger Forms – Drag and Drop Form Builder plugin <= 2.0.0 versions. | |
| Modificada | Alta (7.2) | 0.45% | — | Hynotech Dropbox Folder Share | 16/9/2023 | 17/6/2026 | The Dropbox Folder Share plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.9.7 via the 'link' parameter. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify… | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modificada | Media (5.4) | 0.39% | — | Drop Shadow Boxes Project Drop Shadow Boxes | 25/7/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Steven Henty Drop Shadow Boxes plugin <= 1.7.10 versions. | |
| Modificada | Crítica (9.8) | 1.0% | — | Joommasters JMS Drop Mega Menu | 5/6/2023 | 17/6/2026 | PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php. | |
| Modificada | Alta (8.8) | 0.25% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Woocommerce Custom Checkout Fields Editor With Drag & Drop Project Woocommerce Custom Checkout Fields Editor With Drag & Drop | 9/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Umair Saleem Woocommerce Custom Checkout Fields Editor With Drag & Drop plugin <= 0.1 versions. | |
| Modificada | Crítica (9.8) | 1.2% | — | Brandsdistribution Bdroppy | 24/4/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component. | |
| Analizada | Media (4.8) | 0.53% | — | Backdropcms Backdrop CMS | 24/4/2023 | 17/6/2026 | A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via the name parameter. When a user is editing any content type (e.g., page, post, or card) as an admin, the stored XSS payload is executed upon selecting a… | |
| Modificada | Media (6.1) | 0.54% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 17/4/2023 | 17/6/2026 | The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a… | |
| Modificada | Crítica (9.8) | 3.0% | 💥 PoC | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 1/3/2023 | 17/6/2026 | A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack… | |
| Modificada | Media (5.4) | 0.57% | — | Getwpfunnels Drag & Drop Sales Funnel Builder | 6/2/2023 | 17/6/2026 | The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.1) | 0.52% | — | Backdropcms Basic Cart | 11/1/2023 | 16/6/2026 | A vulnerability was found in backdrop-contrib Basic Cart on Drupal. It has been classified as problematic. Affected is the function basic_cart_checkout_form_submit of the file basic_cart.cart.inc. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version… | |
| Modificada | Media (6.1) | 0.55% | — | Inkdrop | 9/1/2023 | 17/6/2026 | An issue in Inkdrop v5.4.1 allows attackers to execute arbitrary commands via uploading a crafted markdown file. | |
| Modificada | Crítica (9.8) | 0.70% | — | Dropbox Merou | 27/12/2022 | 17/6/2026 | A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_key.py of the component SSH Public Key Handler. The manipulation of the argument public_key_str leads to injection. It is possible to launch the attack remotely. The name… | |
| Modificada | Alta (7.8) | 0.31% | — | Freedom Securedrop | 16/12/2022 | 17/6/2026 | A vulnerability was found in Freedom of the Press SecureDrop. It has been rated as critical. Affected by this issue is some unknown functionality of the file gpg-agent.conf. The manipulation leads to symlink following. Local access is required to approach this attack. The name of the patch is… | |
| Modificada | Alta (7.5) | 0.89% | — | Syncee - Global Dropshipping | 5/12/2022 | 17/6/2026 | The Syncee WordPress plugin before 1.0.10 leaks the administrator token that can be used to take over the administrator's account. | |
| Modificada | Media (6.1) | 0.86% | — | Openedx Xblock-drag-and-drop-v2 | 28/11/2022 | 17/6/2026 | Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted. Version 3.0.0 contains a patch for this… | |
| Modificada | Media (4.8) | 2.1% | 💥 Exploit | Backdropcms Backdrop CMS | 23/11/2022 | 17/6/2026 | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content. | |
| Modificada | Media (4.8) | 0.83% | 💥 PoC | Backdropcms Backdrop | 22/11/2022 | 17/6/2026 | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' . | |
| Modificada | Media (4.8) | 2.7% | 💥 Exploit | Backdropcms Backdrop | 22/11/2022 | 17/6/2026 | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content. | |
| Modificada | Media (4.8) | 2.1% | 💥 Exploit | Backdropcms Backdrop CMS | 21/11/2022 | 17/6/2026 | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content. | |
| Modificada | Crítica (9.8) | 3.9% | 💥 Exploit | Opmc Woocommerce Dropshipping | 7/11/2022 | 17/6/2026 | The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection | |
| Modificada | Media (4.3) | 0.59% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 17/10/2022 | 17/6/2026 | The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form. |