Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.33% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 31/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional allows Reflected XSS.This issue affects WOLF – WordPress Posts Bulk Editor and Manager Professional: from n/a through 1.0.8. | |
| Modificada | Alta (8.8) | 0.27% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 25/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7.1 versions. | |
| Modificada | Media (4.8) | 0.28% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 17/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7.1 versions. | |
| Modificada | Media (4.8) | 0.44% | — | Mrdemonwolf Livestream Notice | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MrDemonWolf Livestream Notice plugin <= 1.2.0 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Wolfgangertl Weebotlite | 25/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wolfgang Ertl weebotLite plugin <= 1.0.0 versions. | |
| Modificada | Media (6.1) | 0.21% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 18/8/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.6 versions. | |
| Modificada | Crítica (9.8) | 0.95% | — | Wolf18 Easyadmin8 | 15/8/2023 | 17/6/2026 | File Upload vulnerability in Wolf-leo EasyAdmin8 v.1.0 allows a remote attacker to execute arbtirary code via the upload type function. | |
| Modificada | Media (6.6) | 0.64% | — | Wolfcode Easyadmin8 | 20/7/2023 | 17/6/2026 | A vulnerability was found in EasyAdmin8 2.0.2.2. It has been classified as problematic. Affected is an unknown function of the file /admin/index/index.html#/admin/mall.goods/index.html of the component File Upload Module. The manipulation leads to unrestricted upload. The complexity of an attack is rather high. The… | |
| Modificada | Alta (8.8) | 0.65% | — | Wolfssl | 17/7/2023 | 17/6/2026 | If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default predictable buffer gets used for the IKM (Input Keying Material) value when generating the session master secret. Using a potentially known IKM value when generating the… | |
| Modificada | Alta (8.8) | 0.26% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Manager Professional | 22/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7 versions. | |
| Modificada | Alta (7.5) | 0.29% | — | Blitzwolf Bw-is22 Firmware | 24/5/2023 | 17/6/2026 | Weak security in the transmitter of Blitzwolf BW-IS22 Smart Home Security Alarm v1.0 allows attackers to gain full access to the system via a code replay attack. | |
| Modificada | Crítica (9.1) | 2.1% | — | Wolfssl | 7/11/2022 | 17/6/2026 | In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes. (WOLFSSL_CALLBACKS is only intended for debugging.) | |
| Modificada | Media (5.3) | 0.57% | — | Wolfssl | 15/10/2022 | 17/6/2026 | An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclosure. Users performing signing operations with private ECC keys, such as in server-side TLS connections, might leak faulty ECC signatures. These signatures can be processed via an advanced technique… | |
| Modificada | Alta (7.5) | 5.8% | — | Wolfssl | 29/9/2022 | 17/6/2026 | In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a previous TLS session. During the resumption Client Hello a Hello Retry Request must be triggered. Both Client Hellos are required to contain a list of duplicate cipher… | |
| Modificada | Media (5.9) | 0.74% | — | Wolfssl | 2/9/2022 | 17/6/2026 | wolfSSL through 5.0.0 allows an attacker to cause a denial of service and infinite loop in the client component by sending crafted traffic from a Machine-in-the-Middle (MITM) position. The root cause is that the client module accepts TLS messages that normally are only sent to TLS servers. | |
| Modificada | Media (5.9) | 2.3% | — | Wolfssl | 31/8/2022 | 17/6/2026 | An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is exploitable. Man-in-the-middle attackers or a malicious server can crash TLS 1.2 clients during a handshake. If an attacker injects a large ticket (more than 256 bytes) into a NewSessionTicket message… | |
| Modificada | Alta (7.5) | 2.7% | — | Wolfssl | 31/8/2022 | 17/6/2026 | An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its session, the server crashes with a segmentation fault. This occurs in the second session, which is created through TLS session resumption and reuses the initial struct WOLFSSL. If the… | |
| Modificada | Alta (7.5) | 1.4% | — | Wolfssl | 8/8/2022 | 17/6/2026 | wolfSSL before 5.4.0 allows remote attackers to cause a denial of service via DTLS because a check for return-routability can be skipped. | |
| Modificada | Crítica (9.8) | 1.9% | 💥 PoC | Wolfssh | 13/7/2022 | 17/6/2026 | WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR. | |
| Modificada | Media (6.8) | 0.86% | — | Joyebike Wolf 2022 Firmware | 29/6/2022 | 17/6/2026 | Joy ebike Wolf Manufacturing year 2022 is vulnerable to Denial of service, which allows remote attackers to jam the key fob request via RF. | |
| Modificada | Media (6.1) | 0.85% | — | Wolfcms Wolf CMS | 9/6/2022 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfcms/?/admin/user/add of the component User Add. The manipulation of the argument name leads to basic cross site scripting. The attack may be… | |
| Modificada | Media (6.5) | 0.65% | — | Joybike Wolf Firmware | 7/6/2022 | 17/6/2026 | joyebike Joy ebike Wolf Manufacturing year 2022 is vulnerable to Authentication Bypass by Capture-replay. | |
| Modificada | Alta (7.5) | 1.4% | 💥 PoC | Wolfssl | 24/2/2022 | 17/6/2026 | In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate. | |
| Modificada | Media (6.5) | 0.63% | — | Wolfssl | 24/2/2022 | 17/6/2026 | In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differs between the certificate_verify message and the certificate message. | |
| Modificada | Crítica (9.1) | 1.4% | — | Wolfssl | 18/1/2022 | 17/6/2026 | wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations. This affects connections (without AEAD) using AES-CBC or DES3 with TLS 1.1 or 1.2 or DTLS 1.1 or 1.2. This occurs because of misplaced memory initialization in BuildMessage in internal.c. |