Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
329 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.29% | — | BEN Moody Srcset Responsive Images FOR WordpressAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ben.moody SrcSet Responsive Images for WordPress truenorth-srcset allows Reflected XSS.This issue affects SrcSet Responsive Images for WordPress: from n/a through <= 1.4. | |
| Aplazada | Alta (7.1) | 0.27% | — | Minerva Infotech Responsive Data TableAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Minerva Infotech Responsive Data Table responsive-data-table allows Reflected XSS.This issue affects Responsive Data Table: from n/a through <= 1.3. | |
| Aplazada | Media (4.4) | 0.24% | — | NKS Responsive-filterable-portfolioAI | 9/11/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Nks Responsive Filterable Portfolio responsive-filterable-portfolio allows Server Side Request Forgery.This issue affects Responsive Filterable Portfolio: from n/a through <= 1.0.22. | |
| Analizada | Crítica (9.8) | 0.53% | — | Dfactory Responsive Lightbox | 23/10/2024 | 17/6/2026 | Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Lightbox: from n/a through 2.4.7. | |
| Aplazada | Media (5.9) | 0.27% | — | Dfactory Responsive LightboxAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dFactory Responsive Lightbox responsive-lightbox allows Stored XSS.This issue affects Responsive Lightbox: from n/a through <= 2.4.8. | |
| Analizada | Alta (7.2) | 0.38% | — | Lopalopa Responsive School Management System | 28/8/2024 | 17/6/2026 | A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter of the Admin Login Page | |
| Analizada | Media (6.9) | 0.65% | — | Fabian Responsive Hotel Site | 27/8/2024 | 17/6/2026 | A vulnerability was found in code-projects Responsive Hotel Site 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument name/phone/email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.4) | 0.33% | — | Dfactory Responsive Lightbox | 22/8/2024 | 17/6/2026 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping affecting the rl_upload_image AJAX endpoint. This makes it possible for authenticated attackers,… | |
| Analizada | Media (5.4) | 0.28% | — | Kirstyburgoine Responsive Video | 21/8/2024 | 17/6/2026 | The Responsive video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's video settings function in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.25% | — | Cyberchimps Responsive Blocks | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Responsive Blocks – WordPress Gutenberg Blocks: from n/a through 1.8.8. | |
| Analizada | Media (5.3) | 0.41% | — | Lopalopa Responsive School Management System | 8/8/2024 | 17/6/2026 | A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter. | |
| Analizada | Media (4.8) | 0.51% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/smsa/add_class_submit.php" in Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "class_name" parameter field. | |
| Analizada | Crítica (9.8) | 0.59% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter. | |
| Analizada | Media (6.1) | 0.48% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /smsa/student_login.php in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter. | |
| Modificada | Media (6.1) | 0.46% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/admin_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter. | |
| Modificada | Media (6.1) | 0.48% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/teacher_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via the "error" parameter. | |
| Modificada | Media (5.3) | 0.48% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view STUDENT details. | |
| Analizada | Media (5.3) | 0.55% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details. | |
| Analizada | Media (5.3) | 0.47% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details. | |
| Modificada | Media (5.3) | 0.51% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details. | |
| Analizada | Media (6.5) | 0.39% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve student registration. | |
| Modificada | Media (6.5) | 0.45% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve Teacher registration. | |
| Analizada | Media (5.3) | 0.64% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view SUBJECT details. | |
| Analizada | Media (5.3) | 0.54% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new subject entry. | |
| Analizada | Media (5.3) | 0.43% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new class entry. |