Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1025 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.23% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS). | |
| Modificada | Media (5.5) | 0.23% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS). | |
| Modificada | Media (5.5) | 0.20% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error. | |
| Modificada | Media (5.5) | 0.21% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS). | |
| Modificada | Media (5.5) | 0.20% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error. | |
| Modificada | Alta (7.8) | 0.19% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code. | |
| Aplazada | Alta (7.3) | 0.96% | 💥 Exploit | Smartmodules Products AlertAI | 24/6/2024 | 17/6/2026 | SQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via the ProductsAlertAjaxProcessModuleFrontController::initContent method. | |
| Aplazada | Alta (8.8) | 0.40% | — | PrestashopAIFmemodules HelpdeskAI | 24/6/2024 | 17/6/2026 | SQL Injection vulnerability in the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via 'Tickets::getsearchedtickets()' | |
| Aplazada | Alta (7.5) | 10% | — | Promokit Facebook ModuleAIPrestashopAI | 19/6/2024 | 17/6/2026 | In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The ajax script facebookConnect.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Aplazada | Crítica (10) | 0.61% | — | Livechatpro Module Live Chat PROAI | 19/6/2024 | 17/6/2026 | In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token, the method `Lcp::saveTranslations()` suffer of a white writer that can inject PHP code into a PHP file. | |
| Aplazada | Crítica (10) | 0.51% | — | PrestashopAIFmemodules HelpdeskAI | 19/6/2024 | 17/6/2026 | In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php files. Methods `HelpdeskHelpdeskModuleFrontController::submitTicket()` and `HelpdeskHelpdeskModuleFrontController::replyTicket()` allow upload of .php files on a… | |
| Aplazada | Crítica (9.8) | 0.46% | — | JA Module JA MarketplaceAI | 19/6/2024 | 17/6/2026 | In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .php. In version 6.X, the method `JmarketplaceproductModuleFrontController::init()` and in version 8.X, the method `JmarketplaceSellerproductModuleFrontController::init()` allow… | |
| Aplazada | Media (6.8) | 0.34% | — | Paradox Ip150 Internet ModuleAI | 19/6/2024 | 17/6/2026 | The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system. | |
| Aplazada | Alta (7.5) | 0.76% | — | WP Magazine Modules LiteAI | 19/6/2024 | 17/6/2026 | The WP Magazine Modules Lite plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.2 via the 'blockLayout' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server,… | |
| Aplazada | Media (6.4) | 0.33% | — | Supreme Modules LiteAI | 1/6/2024 | 17/6/2026 | The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_one_id’ parameter in all versions up to, and including, 2.5.51 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 1.0% | — | Iris-evtx-moduleAIIris-webAI | 23/5/2024 | 17/6/2026 | IrisEVTXModule is an interface module for Evtx2Splunk and Iris in order to ingest Microsoft EVTX log files. The `iris-evtx-module` is a pipeline plugin of `iris-web` that processes EVTX files through IRIS web application. During the upload of an EVTX through this pipeline, the filename is not safely handled and may… | |
| Analizada | Media (6.7) | 0.37% | — | Intel TDX ModuleNetapp HCI Compute Node Bios | 16/5/2024 | 31/8/2026 | Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (8.2) | 0.38% | — | Intel TDX ModuleNetapp HCI Compute Node Bios | 16/5/2024 | 31/8/2026 | Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.4) | 0.56% | — | Supreme Modules LiteAI | 2/5/2024 | 17/6/2026 | The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via the ‘typing_cursor’ parameter in versions up to, and including, 2.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (7.5) | 0.99% | — | Fmemodules CustomfieldsAI | 30/4/2024 | 17/6/2026 | Directory Traversal vulnerability in FME Modules customfields v.2.2.7 and before allows a remote attacker to obtain sensitive information via the Custom Checkout Fields, Add Custom Fields to Checkout parameter of the ajax.php | |
| Aplazada | Alta (7.5) | 0.59% | — | FME Modules FileuploadsAI | 30/4/2024 | 9/7/2026 | An issue in FME Modules fileuploads v.2.0.3 and before and fixed in v2.0.4 allows a remote attacker to obtain sensitive information via the uploadfiles.php component. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Fmemodules PreorderandnoticationAI | 29/4/2024 | 17/6/2026 | SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbitrary SQL commands via the PreorderModel::getIdProductAttributesByIdAttributes() method. | |
| Aplazada | Alta (7.5) | 0.48% | — | Safe Software FME Modules EventsmanagerAI | 29/4/2024 | 17/6/2026 | An issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_customer component. | |
| Analizada | Crítica (9.8) | 0.59% | — | Folio Spring Module Core | 21/3/2024 | 17/6/2026 | A vulnerability was found in Folio Spring Module Core up to 1.1.5. It has been rated as critical. Affected by this issue is the function dropSchema of the file tenant/src/main/java/org/folio/spring/tenant/hibernate/HibernateSchemaService.java of the component Schema Name Handler. The manipulation leads to sql… | |
| Analizada | Alta (7.5) | 0.83% | — | Myprestamodules Orders (csv, Excel) Export PRO | 20/3/2024 | 17/6/2026 | An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component. |