Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.28% | — | Ays-pro Survey Maker | 8/10/2024 | 17/6/2026 | The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Modificada | Media (6.1) | 0.57% | — | Limesurvey | 7/10/2024 | 5/7/2026 | Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component. | |
| Modificada | Media (6.1) | 0.57% | — | Limesurvey | 7/10/2024 | 5/7/2026 | Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields. | |
| Modificada | Media (4.8) | 0.40% | — | Expresstech Quiz AND Survey Master | 23/9/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Crítica (9.8) | 0.79% | — | Endress Echo Curve ViewerEndress Fieldcare Sfe500 PackageEndress Field Xpert Smt79 FirmwareEndress Field Xpert Smt77 Firmware+2 | 10/9/2024 | 17/6/2026 | An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context. | |
| Analizada | Media (6.1) | 1.00% | — | C-mor Video Surveillance | 5/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper input validation, the C-MOR web interface is vulnerable to reflected cross-site scripting (XSS) attacks. It was found out that different functions are prone to reflected cross-site scripting attacks due to insufficient user input… | |
| Analizada | Alta (8.8) | 0.67% | — | C-mor Video Surveillance | 5/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that sensitive information, for example login credentials of cameras, is stored in cleartext. Thus, an attacker with filesystem access, for example exploiting a path traversal attack,… | |
| Analizada | Alta (8.8) | 0.92% | — | C-mor Video Surveillance | 5/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous files, for instance PHP code, to the C-MOR system. By analyzing the C-MOR web interface, it was found out that the upload functionality for backup files allows an… | |
| Analizada | Alta (7.1) | 1.3% | — | C-mor Video Surveillance | 5/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the C-MOR system via a path traversal attack. It was found out that different functionalities are vulnerable to path traversal attacks, due to insufficient user… | |
| Analizada | Alta (8.8) | 0.92% | — | C-mor Video Surveillance | 5/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation attack. The Linux user www-data running the C-MOR web interface can execute some OS commands as root via Sudo without having to enter… | |
| Analizada | Media (6.8) | 0.39% | — | C-mor Video Surveillance | 4/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanisms, the C-MOR web interface is vulnerable to cross-site request forgery (CSRF) attacks. The C-MOR web interface offers no protection against cross-site request forgery (CSRF) attacks. | |
| Analizada | Media (5.4) | 0.82% | — | C-mor Video Surveillance | 4/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper input validation, the C-MOR web interface is vulnerable to persistent cross-site scripting (XSS) attacks. It was found out that the camera configuration is vulnerable to a persistent cross-site scripting attack due to… | |
| Analizada | Alta (8.1) | 1.3% | — | C-mor Video Surveillance | 4/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper validation of user-supplied data, different functionalities of the C-MOR web interface are vulnerable to SQL injection attacks. This kind of attack allows an authenticated user to execute arbitrary SQL commands in the… | |
| Analizada | Alta (8.1) | 0.65% | — | C-mor Video Surveillance | 4/9/2024 | 17/6/2026 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low privileged users can use administrative functions of the C-MOR web interface. It was found out that different functions are only available to administrative users. However, access those functions is… | |
| Modificada | Media (6.5) | 0.50% | — | Limesurvey | 3/9/2024 | 17/6/2026 | A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain. | |
| Analizada | Alta (8.8) | 1.0% | — | Limesurvey | 3/9/2024 | 17/6/2026 | An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php function | |
| Analizada | Media (4.8) | 0.43% | — | Limesurvey | 3/9/2024 | 17/6/2026 | A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file. | |
| Analizada | Media (5.4) | 0.26% | — | Azurecurve Toggle Show/hide | 29/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in azurecurve azurecurve Toggle Show/Hide allows Stored XSS.This issue affects azurecurve Toggle Show/Hide: from n/a through 2.1.3. | |
| Analizada | Media (4.7) | 0.43% | — | Expresstech Quiz AND Survey Master | 26/8/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks. | |
| Aplazada | Media (5.5) | 0.35% | — | WordsurveyAI | 21/8/2024 | 17/6/2026 | The WordSurvey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sounding_title’ parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject… | |
| Analizada | Media (5.1) | 0.90% | — | Limesurvey | 17/8/2024 | 17/6/2026 | A vulnerability was found in LimeSurvey 6.3.0-231016 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php of the component File Upload. The manipulation of the argument size leads to denial of service. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.9) | 0.33% | — | Expresstech Quiz AND Survey Master | 3/8/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Media (5.4) | 0.24% | — | Pixelcurve EdubinAI | 1/8/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in pixelcurve Edubin edubin.This issue affects Edubin: from n/a through <= 9.2.0. | |
| Analizada | Baja (2.1) | 0.56% | — | Limesurvey | 21/7/2024 | 17/6/2026 | A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey General Settings Handler. This manipulation of the argument Language… | |
| Modificada | Media (5.4) | 0.38% | — | Expresstech Quiz AND Survey Master | 11/7/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks |