Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
199 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 97% | 💥 Exploit | Progress Moveit Transfer | 16/6/2023 | 17/6/2026 | In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's… | |
| Modificada | Crítica (9.1) | 13% | — | Progress Moveit Transfer | 12/6/2023 | 17/6/2026 | In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Progress Moveit CloudProgress Moveit Transfer | 2/6/2023 | 17/6/2026 | In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending… | |
| Modificada | Media (6.1) | 0.61% | — | Moveit | 11/5/2023 | 17/6/2026 | The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact." | |
| Modificada | Media (4.8) | 0.37% | — | Wp-master Feed Changer & Remover | 20/3/2023 | 17/6/2026 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in WP-master.Ir Feed Changer & Remover plugin <= 0.2 versions. | |
| Modificada | Media (5.4) | 0.53% | 💥 PoC | Inhabit Move CRM | 22/12/2022 | 17/6/2026 | Inhabit Systems Pty Ltd Move CRM version 4, build 260 was discovered to contain a cross-site scripting (XSS) vulnerability via the User profile component. | |
| Modificada | Media (5.4) | 0.52% | — | Thememove Insight Core | 14/3/2022 | 17/6/2026 | The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it to unserialize(), nor sanitise and escape it before outputting it in the response. As a result, it… | |
| Modificada | Media (4.8) | 0.65% | — | Wpchill Remove Footer Credit | 14/2/2022 | 17/6/2026 | The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. | |
| Modificada | Media (5.4) | 0.33% | — | Wpchill Remove Footer Credit | 14/2/2022 | 17/6/2026 | The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XSS issue as well due to the lack of sanitisation | |
| Modificada | Media (4.3) | 0.49% | — | Quantumcloud Comment Link Remove AND Other Comment Tools | 13/9/2021 | 17/6/2026 | The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments | |
| Modificada | Crítica (9.8) | 1.9% | — | Progress Moveit Transfer | 7/8/2021 | 17/6/2026 | In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web application could allow an unauthenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able… | |
| Modificada | Alta (8.8) | 1.5% | — | Progress Moveit Transfer | 5/8/2021 | 17/6/2026 | In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVEit Transfer web application could allow an authenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able… | |
| Modificada | Alta (8.8) | 1.1% | — | Progress Moveit Transfer | 9/6/2021 | 17/6/2026 | In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2.2), 2020.x before 2020.0.5 (12.0.5), 2020.1.x before 2020.1.4 (12.1.4), and 2021.x before 2021.0.1 (13.0.1), a SQL injection vulnerability exists in SILUtility.vb in MOVEit.DMZ.WebApp in the MOVEit… | |
| Modificada | Alta (8.8) | 1.2% | — | Progress Moveit Transfer | 18/5/2021 | 17/6/2026 | In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in the MOVEit Transfer web app that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an… | |
| Modificada | Media (5.4) | 0.83% | — | Koa-remove-trailing-slashes Project Koa-remove-trailing-slashes | 17/5/2021 | 17/6/2026 | The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::removeTrailingSlashes(), as the web server uses relative… | |
| Modificada | Media (6.7) | 1.1% | — | Qnap Malware Remover | 13/5/2021 | 17/6/2026 | A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue does not affect: QNAP Systems Inc.… | |
| Modificada | Media (5.4) | 1.5% | 💥 PoC | Progress Moveit Transfer | 17/11/2020 | 17/6/2026 | In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS). | |
| Modificada | Alta (7.8) | 0.33% | — | Schneider-electric Somove | 31/8/2020 | 17/6/2026 | Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script is launched. | |
| Modificada | Media (6.1) | 1.9% | — | Progress Moveit Automation | 14/5/2020 | 17/6/2026 | An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately sanitize malicious input, which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS. This affects 2018 - 2018.0 prior to 2018.0.3, 2018 SP1 - 2018.2 prior… | |
| Modificada | Alta (8.8) | 2.0% | — | Jenkins Cryptomove | 9/3/2020 | 17/6/2026 | Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the OS user account running Jenkins. | |
| Modificada | Crítica (9) | 1.7% | — | Progess Moveit TransferProgress Moveit Transfer | 14/2/2020 | 17/6/2026 | In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS. | |
| Modificada | Alta (8.8) | 1.2% | — | Progess Moveit TransferProgress Moveit Transfer | 14/2/2020 | 17/6/2026 | In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injection vulnerabilities have been found in the REST API that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database via the REST API. Depending on the database engine being used… | |
| Modificada | Crítica (9.8) | 1.5% | — | Ipswitch Moveit Transfer | 31/10/2019 | 17/6/2026 | In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL database is being used. | |
| Modificada | Crítica (9.8) | 1.9% | — | Ipswitch Moveit Transfer | 31/10/2019 | 17/6/2026 | In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine… | |
| Modificada | Crítica (9.4) | 5.2% | 💥 Exploit | Ipswitch Moveit Transfer | 24/9/2019 | 17/6/2026 | MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to… |