Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
370 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.62% | — | Softnext Mail SQR Expert | 15/12/2023 | 17/6/2026 | Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a special URL. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file extension under specific system paths, to access and modify partial system… | |
| Modificada | Alta (8) | 0.68% | — | Softnext Mail SQR Expert | 15/12/2023 | 17/6/2026 | Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a spcific function. A remote attacker authenticated as a localhost can exploit this vulnerability to perform command injection attacks, to execute arbitrary system command, manipulate system or… | |
| Modificada | Media (5.3) | 0.60% | — | Softnext Mail SQR Expert | 15/12/2023 | 17/6/2026 | Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response. | |
| Modificada | Alta (7.5) | 1.3% | — | Softnext Mail SQR Expert | 15/12/2023 | 17/6/2026 | Softnext Mail SQR Expert has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files. | |
| Modificada | Media (4.8) | 0.39% | — | Wpexperts Rocket Maintenance Mode & Coming Soon Page | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpexpertsio Rocket Maintenance Mode & Coming Soon Page allows Stored XSS.This issue affects Rocket Maintenance Mode & Coming Soon Page: from n/a through 4.3. | |
| Modificada | Media (5.4) | 0.39% | — | Wpexperts Mycred | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin allows Stored XSS.This issue affects myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin: from n/a through 2.6.1. | |
| Modificada | Alta (7.2) | 0.70% | — | Wpexperts License Manager FOR Woocommerce | 30/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LicenseManager License Manager for WooCommerce license-manager-for-woocommerce allows SQL Injection.This issue affects License Manager for WooCommerce: from n/a through 2.2.10. | |
| Modificada | Media (6.1) | 0.51% | — | Wpexperts Post Smtp | 27/11/2023 | 17/6/2026 | The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users. | |
| Modificada | Alta (8.8) | 0.29% | — | Wpexpertplugins Post Meta Data Manager | 21/11/2023 | 17/6/2026 | The Post Meta Data Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the pmdm_wp_ajax_delete_meta, pmdm_wp_delete_user_meta, and pmdm_wp_delete_user_meta functions. This makes it possible for unauthenticated… | |
| Modificada | Media (6.1) | 0.41% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 15/11/2023 | 17/6/2026 | A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload. | |
| Modificada | Media (6.1) | 0.45% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 15/11/2023 | 17/6/2026 | A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed. | |
| Modificada | Alta (8.8) | 0.28% | — | Wpexperts Email Templates Customizer AND Designer | 7/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpexpertsio Email Templates Customizer and Designer for WordPress and WooCommerce email-templates allows Cross Site Request Forgery.This issue affects Email Templates Customizer and Designer for WordPress and WooCommerce: from n/a through 1.4.2. | |
| Modificada | Alta (7.5) | 0.46% | — | Wpexpertplugins Post Meta Data Manager | 28/10/2023 | 17/6/2026 | The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_delete_user_meta, pmdm_wp_delete_term_meta, and pmdm_wp_ajax_delete_meta functions in versions up to, and including, 1.2.0. This makes it possible for unauthenticated… | |
| Modificada | Alta (8.8) | 0.53% | — | Wpexpertplugins Post Meta Data Manager | 28/10/2023 | 17/6/2026 | The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_change_user_meta and pmdm_wp_change_post_meta functions in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with subscriber-level… | |
| Modificada | Media (5.4) | 0.46% | — | Wpexperts User Avatar-reloaded | 16/10/2023 | 17/6/2026 | The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks. | |
| Modificada | Crítica (9.8) | 0.92% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation With Advanced ReportsSchneider-electric Ecostruxure Power Scada Operation With Advanced Reports | 4/10/2023 | 17/6/2026 | A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application. | |
| Modificada | Crítica (9.8) | 2.0% | — | Wibu Codemeter RuntimeTrumpf OseonTrumpf ProgrammingtubeTrumpf Teczonebend+20 | 13/9/2023 | 17/6/2026 | A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system. | |
| Modificada | Media (6.1) | 0.38% | — | Wp-experts Wp-categories-widget | 4/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP-EXPERTS.IN TEAM WP Categories Widget plugin <= 2.2 versions. | |
| Analizada | Alta (7.5) | 0.84% | — | Wpexperts ALL IN ONE Login | 21/8/2023 | 17/6/2026 | The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protection offered. | |
| Modificada | Alta (8.8) | 0.39% | — | Wpexperts Post Smtp | 17/7/2023 | 17/6/2026 | The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability resend an email to an arbitrary address (for example a password reset email could be resent to an attacker controlled… | |
| Modificada | Alta (8.8) | 0.25% | — | Wpexperts Mycred | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in myCred plugin <= 2.5 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Wpexperts WP PDF Generator | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpexperts.Io WP PDF Generator plugin <= 1.2.2 versions. | |
| Modificada | Media (5.5) | 0.21% | — | Ecostruxure OPC UA Server Expert | 12/7/2023 | 17/6/2026 | A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server. | |
| Modificada | Alta (7.2) | 0.86% | — | Schneider-electric Struxureware Data Center Expert | 12/7/2023 | 17/6/2026 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored. | |
| Modificada | Alta (7.2) | 0.86% | — | Schneider-electric Struxureware Data Center Expert | 12/7/2023 | 17/6/2026 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages. |