Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

318 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.34%—Ays-pro Survey Maker19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS.This issue affects Survey Maker: from n/a through 4.0.5.
AplazadaMedia (5.4)0.20%—Expresstechsoftware Quiz AND Survey MasterAI16/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.18.
AnalizadaAlta (7.5)0.58%—Ecomiz Survey TMA23/2/202417/6/2026
In the module "Survey TMA" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without restriction.
ModificadaMedia (5.4)0.39%—Quizandsurveymaster Quiz AND Survey Master23/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master plugin <= 8.1.13 versions.
ModificadaMedia (5.4)0.68%—Limesurvey18/11/202317/6/2026
Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component.
ModificadaMedia (4.1)1.1%—Microsoft Send Customer Voice Survey From Dynamics 36514/11/202317/6/2026
Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability
ModificadaAlta (8.8)0.31%—Expresstech Quiz AND Survey Master13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions.
ModificadaCrítica (9.8)1.3%—Diaowen Dwsurvey1/9/202317/6/2026
File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.
ModificadaMedia (5.4)0.55%—Expresstech Quiz AND Survey Master7/8/202317/6/2026
The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (7.5)0.86%💥 PoCNgsurvey2/8/202317/6/2026
Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys.
ModificadaAlta (7.5)1.2%💥 PoCNgsurvey2/8/202317/6/2026
Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey contains a "Text Field", "Comment Field" or "Contact Details".
ModificadaMedia (5.4)0.38%—Otrs Survey24/7/202317/6/2026
An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module…
ModificadaMedia (6.1)0.56%—Diaowen Dwsurvey20/6/202317/6/2026
Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.action file.
ModificadaAlta (8.1)0.79%—Expresstech Quiz AND Survey Master9/6/202317/6/2026
The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated attackers to delete…
ModificadaCrítica (9.1)2.0%—Expresstech Quiz AND Survey Master9/6/202317/6/2026
The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files.
ModificadaMedia (6.1)0.46%—Ays-pro Survey Maker5/6/202317/6/2026
The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.69%—Microsoft Send Customer Voice Survey From Dynamics 36511/4/202317/6/2026
Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability
AnalizadaCrítica (9.8)2.7%⚠ Explotación activa3rdmill Novi Survey11/4/202317/6/2026
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
ModificadaMedia (6.1)0.36%—Survey Application System Project Survey Application System7/4/202317/6/2026
A vulnerability was found in SourceCodester Survey Application System 1.0 and classified as problematic. This issue affects some unknown processing of the component Add New Handler. The manipulation of the argument Title with the input <script>prompt(document.domain)</script> leads to cross site scripting. The attack…
ModificadaAlta (8.8)0.38%—Expresstech Quiz AND Survey Master14/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.7 versions.
ModificadaMedia (5.4)0.48%—Limesurvey27/1/202317/6/2026
LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description or…
ModificadaCrítica (9.8)1.3%—Limesurvey27/1/202317/6/2026
An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (8.8)2.3%—Ays-pro Survey Maker20/1/202317/6/2026
The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action.
ModificadaMedia (6.1)0.75%—Ays-pro Survey Maker3/1/202317/6/2026
The "Survey Maker – Best WordPress Survey Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via survey answers in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
ModificadaMedia (5.3)0.73%—Expresstech Quiz AND Survey Master29/11/202217/6/2026
The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input validation that allows attackers to inject content other than the specified value (i.e. a number, file path, etc..). This makes it…
Orbitaley — Vulnerabilidades