Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Upload File | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Upload File extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Stripe | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Stripe extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Software Licensing | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Software Licensing extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Simple Shipping | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Simple Shipping extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Reviews | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Recurring Payments | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Recurring Payments extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Alta (7.2) | 1.9% | — | Awesome Filterable Portfolio Project Awesome Filterable Portfolio | 10/10/2019 | 17/6/2026 | The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat_id parameter. | |
| Modificada | Alta (7.2) | 1.9% | — | Brinidesigner Awesome Filterable Portfolio | 10/10/2019 | 17/6/2026 | The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via the item_id parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Getawesomesupport Awesome Support | 20/8/2019 | 17/6/2026 | The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies. | |
| Modificada | Media (6.1) | 0.91% | — | Getawesomesupport Awesome Support | 20/8/2019 | 17/6/2026 | The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages. | |
| Modificada | Media (6.1) | 0.97% | — | Awesomemotive Easy Digital Downloads | 16/8/2019 | 17/6/2026 | The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging. | |
| Modificada | Crítica (9.8) | 2.0% | — | Awesomemotive Easy Digital Downloads | 16/8/2019 | 17/6/2026 | The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection. | |
| Modificada | Crítica (10) | 1.9% | — | Neo4j Awesome Procedures ON Cyper | 20/12/2018 | 17/6/2026 | neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c. | |
| Modificada | Crítica (9.8) | 60% | 💥 Exploit | Awesomemotive Duplicator | 19/9/2018 | 17/6/2026 | An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution. | |
| Modificada | Alta (7.5) | 1.0% | — | Supercoolawesomemoney Super Cool Awesome Money | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Super Cool Awesome Money (SCAM), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Media (6.1) | 3.3% | 💥 Exploit | Awesomemotive Duplicator | 26/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Awesomewidgets Rasta Weed Widgets HD | 22/9/2014 | 17/6/2026 | The Rasta Weed Widgets HD (aka aw.awesomewidgets.rastaweed) application 4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.34% | — | Awesome Antivirus 2014 Project Awesome Antivirus 2014 | 9/9/2014 | 17/6/2026 | The Awesome Antivirus 2014 (aka com.yoursite.top5antivirus2014) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Awesomeseating BUY Tickets | 9/9/2014 | 17/6/2026 | The Buy Tickets (aka com.xcr.android.buytickets) application 2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Awesomephp Mega File Manager | 30/6/2009 | 16/6/2026 | Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps,… | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Amazoop AwesomJoomla COM AwesomMambo COM Awesom | 6/2/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the amazOOP Awesom! (com_awesom) 0.3.2component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter in a viewlist task. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Awesometemplateengine | 10/1/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow remote attackers to inject arbitrary web script or HTML via the (1) data[title], (2) data[message], (3) data[table][1][item], (4) data[table][1][url], or (5) data[poweredby] parameter. |