Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
313 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.40% | — | Brainstormforce Spectra | 28/3/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6. | |
| Aplazada | Alta (7.1) | 0.32% | — | Brainstormforce Starter Templates Elementor Wordpress Beaver Builder TemplatesAIBrainstormforce Premium Starter TemplatesAI | 28/3/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates, Brainstorm Force Premium Starter Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4; Premium Starter Templates:… | |
| Aplazada | Media (6.5) | 0.36% | — | Stormhillmedia Mybooktable BookstoreAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stormhill Media MyBookTable Bookstore allows Stored XSS.This issue affects MyBookTable Bookstore: from n/a through 3.3.7. | |
| Aplazada | Media (5.9) | 0.36% | — | Brainstormforce AstraAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra allows Stored XSS.This issue affects Astra: from n/a through 4.6.4. | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Wyrestorm Apollo Vx20 Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request. | |
| Modificada | Crítica (9.1) | 51% | 💥 Exploit | Wyrestorm Apollo Vx20 Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request. | |
| Modificada | Alta (7.5) | 4.1% | 💥 Exploit | Wyrestorm Apollo Vx20 Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts. | |
| Analizada | Media (4.3) | 0.45% | — | Brainstormforce Schema | 25/3/2024 | 17/6/2026 | The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode | |
| Modificada | Media (5.4) | 0.51% | — | Brainstormforce Elementor Header & Footer Builder | 13/3/2024 | 17/6/2026 | The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flyout_layout attribute in all versions up to, and including, 1.6.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access… | |
| Analizada | Media (4.8) | 0.41% | — | Stormshield Network Security | 29/2/2024 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a login disclaimer with malicious… | |
| Analizada | Alta (7.3) | 0.51% | — | Stormshield Network Security | 29/2/2024 | 17/6/2026 | In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage… | |
| Modificada | Media (4.3) | 0.32% | — | Brainstormforce Ultimate Addons FOR Beaver Builder | 17/1/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite.This issue affects Ultimate Addons for Beaver Builder – Lite: from n/a through 1.5.5. | |
| Modificada | Alta (8.8) | 0.22% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page Builder | 29/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brain Storm Force Ultimate Addons for WPBakery Page Builder.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.17. | |
| Modificada | Media (5.4) | 0.33% | — | Brainstormforce WP Remote Site Search | 29/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force WP Remote Site Search allows Stored XSS.This issue affects WP Remote Site Search: from n/a through 1.0.4. | |
| Modificada | Alta (8.8) | 0.66% | — | Brainstormforce Astra | 29/12/2023 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through 4.3.1. | |
| Modificada | Alta (7.5) | 0.29% | — | Stormshield Network Security | 26/12/2023 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and potentially sends these logs to the… | |
| Modificada | Alta (7.5) | 0.53% | — | Stormshield Network Security | 25/12/2023 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible. | |
| Modificada | Media (6.5) | 0.29% | — | Stormshield Network Security | 21/12/2023 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.21, 4.4.0 through 4.6.8, and 4.7.0. Sending a crafted ICMP packet may lead to a crash of the ASQ engine. | |
| Modificada | Media (5.3) | 0.40% | — | Stormshield Network Security | 21/12/2023 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access commands. | |
| Modificada | Media (5.4) | 0.56% | — | Brainstormforce Spectra | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Spectra – WordPress Gutenberg Blocks: from n/a through 2.7.9. | |
| Modificada | Media (5.4) | 0.40% | — | Brainstormforce Starter Templates | 7/12/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4. | |
| Modificada | Alta (8.8) | 0.30% | — | Brainstormforce Cartflows | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC CartFlows Pro allows Cross Site Request Forgery.This issue affects CartFlows Pro: from n/a through 1.11.12. | |
| Modificada | Alta (8.8) | 0.30% | — | Brainstormforce Schema | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro: from n/a through 2.7.7. | |
| Modificada | Alta (8.8) | 0.26% | — | Stormhillmedia Mybook Table Bookstore | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stormhill Media MyBookTable Bookstore by Stormhill Media allows Cross Site Request Forgery.This issue affects MyBookTable Bookstore by Stormhill Media: from n/a through 3.3.4. | |
| Modificada | Media (5.5) | 0.35% | — | Apache Storm | 23/11/2023 | 17/6/2026 | On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method File.createTempFile on unix-like… |