Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

203 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.56%—Zabbix Frontend13/7/202317/6/2026
URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards.
ModificadaMedia (6.1)0.60%—Zabbix Frontend13/7/202317/6/2026
Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a website with a vulnerability that enables execution of malicious scripts.
ModificadaMedia (5.4)0.57%—Zabbix Frontend13/7/202317/6/2026
Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web…
ModificadaMedia (5.4)0.38%—Palantir Foundry Frontend10/7/202317/6/2026
A security defect was discovered in Foundry Frontend which enabled users to perform Stored XSS attacks in Slate if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.229.0. The service was rolled out to all affected Foundry instances. No further intervention is required.
ModificadaAlta (7.7)0.69%—Palantir Foundry FrontendPalantir Foundry Issues10/7/202317/6/2026
A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitting malformed data in an Issue that caused loss of frontend functionality to all issue participants. This defect was resolved with the release of Foundry Issues 2.510.0 and Foundry Frontend 6.228.0.
ModificadaMedia (4.3)0.79%—Webdevocean WP Quick Frontend Editor7/6/202317/6/2026
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and including, 5.5. This is due to missing capability checks in the plugin's page-editing functionality. This makes it possible for low-authenticated attackers, such as subscribers, to edit/create any page or…
ModificadaMedia (5.4)0.49%—Webdevocean WP Quick Frontend Editor7/6/202317/6/2026
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with minimal permissions like subscribers, to inject arbitrary web scripts…
ModificadaMedia (4.3)0.66%—Pluginmirror WP Quick Frontend Editor7/6/202317/6/2026
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Setting Changs in versions up to, and including, 5.5. This is due to lacking both a security nonce and a capabilities check. This makes it possible for low-authenticated attackers to change plugin settings even when they do not have the capabilities to…
ModificadaMedia (5.3)0.80%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due to lacking authorization protections, checks against users editing other's posts, and lacking a security nonce, all on the wpfm_edit_file_title_desc AJAX action. This…
ModificadaAlta (8.8)1.9%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for subscriber-level attackers to edit the plugin…
ModificadaMedia (6.1)0.76%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. This is due to lacking authentication protections and santisation all on the wpfm_edit_file_title_desc AJAX action. This makes it possible for unauthenticated attackers to…
ModificadaMedia (6.1)0.74%—Webdevocean WP Quick Frontend Editor7/6/202317/6/2026
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on the 'save_content_front' function that uses print_r on the user-supplied $_REQUEST values . This makes it possible for…
ModificadaMedia (5.3)0.88%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security nonce on the wpfm_delete_file AJAX action. This makes it possible for unauthenticated attackers to…
ModificadaCrítica (9.8)1.5%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for…
ModificadaMedia (5.3)0.68%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for unauthenticated…
ModificadaMedia (5.3)0.67%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email AJAX action. This makes it possible for unauthenticated attackers to send emails using the site with a…
ModificadaMedia (5.4)0.47%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking mishandling the use of user IDs that is accessible by the visitor. This makes it possible for unauthenticated or authenticated attackers to access the information and…
ModificadaMedia (5.4)0.43%—Accesspressthemes Frontend Post Wordpress Plugin5/6/202317/6/2026
The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to an arbitrary domain.
ModificadaAlta (8.8)0.25%—Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible5/4/202317/6/2026
The WCFM Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying knowledge bases, modifying…
ModificadaAlta (8.8)0.64%—Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible5/4/202317/6/2026
The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 due to missing capability checks on various AJAX actions. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to perform a…
ModificadaCrítica (9.8)0.45%—Change Password FOR Frontend Users Project Change Password FOR Frontend Users14/12/202217/6/2026
An issue was discovered in the fe_change_pwd (aka Change password for frontend users) extension before 2.0.5, and 3.x before 3.0.3, for TYPO3. The extension fails to revoke existing sessions for the current user when the password has been changed.
ModificadaCrítica (9.8)1.2%—Zabbix Frontend5/12/202217/6/2026
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker…
ModificadaCrítica (9.8)0.69%—Wedevs WP User Frontend21/11/202217/6/2026
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and AUTH_SALT constant (via an arbitrary…
ModificadaMedia (5.4)0.73%—Owasp Dependency-track Frontend25/10/202217/6/2026
@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Due to the common practice of providing vulnerability details in markdown format, the Dependency-Track…
ModificadaMedia (4.3)0.29%—Najeebmedia Frontend File Manager Plugin17/10/202217/6/2026
The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf