Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
423 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.50% | — | Coderevolution Demo MY WordpressAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1. | |
| Modificada | Media (5.4) | 0.42% | — | Themepunch Slider Revolution | 2/5/2024 | 17/6/2026 | The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter in all versions up to, and including, 6.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Alta (8.8) | 0.64% | — | Coderevolution WP Setup WizardAI | 25/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodeRevolution WP Setup Wizard.This issue affects WP Setup Wizard: from n/a through 1.0.8.1. | |
| Analizada | Crítica (9.8) | 0.63% | — | Cs-technologies Evolution | 15/4/2024 | 17/6/2026 | Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or prompt to ask the user to change the… | |
| Analizada | Alta (7.5) | 0.50% | — | Cs-technologies Evolution | 15/4/2024 | 17/6/2026 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, allowing for an unauthenticated attacker to enumerate all users and their access levels | |
| Analizada | Alta (7.5) | 0.50% | — | Cs-technologies Evolution | 15/4/2024 | 17/6/2026 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS, allowing for an unauthenticated attacker to return the abacard field of any user | |
| Analizada | Alta (7.5) | 0.50% | — | Cs-technologies Evolution | 15/4/2024 | 17/6/2026 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an unauthenticated attacker to return the keys value of any user | |
| Analizada | Alta (7.5) | 0.50% | — | Cs-technologies Evolution | 15/4/2024 | 17/6/2026 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unauthenticated attacker to return the pin value of any user | |
| Analizada | Alta (7.5) | 0.50% | — | Cs-technologies Evolution | 15/4/2024 | 17/6/2026 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the card value data of any user | |
| Analizada | Alta (7.5) | 0.54% | — | Cs-technologies Evolution | 15/4/2024 | 17/6/2026 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller software | |
| Analizada | Alta (8.8) | 0.51% | — | Cs-technologies Evolution | 15/4/2024 | 17/6/2026 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in. | |
| Analizada | Crítica (9.8) | 0.58% | — | Cs-technologies Evolution | 15/4/2024 | 17/6/2026 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and add user profiles within the application, and gain full access of the site. | |
| Analizada | Media (4.3) | 0.28% | — | Devolutions ServerDevolutions Remote Desktop Manager | 9/4/2024 | 17/6/2026 | Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software… | |
| Analizada | Baja (3.6) | 0.24% | — | Devolutions Server | 9/4/2024 | 17/6/2026 | Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to forge the displayed group in the PAM JIT elevation checkout request via a specially crafted request. | |
| Analizada | Crítica (9.8) | 0.79% | — | Devolutions Server | 26/3/2024 | 17/6/2026 | Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions. | |
| Analizada | Alta (8.8) | 0.65% | — | Devolutions Server | 26/3/2024 | 17/6/2026 | Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to elevate themselves to unauthorized groups via a specially crafted request. | |
| Analizada | Media (5.9) | 0.42% | — | Devolutions Remote Desktop Manager | 13/3/2024 | 17/6/2026 | Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attacker that compromised a user endpoint, under specific circumstances, to access sensitive information via residual files in the temporary directory. | |
| Analizada | Media (6.3) | 0.40% | — | Devolutions Workspace | 7/3/2024 | 17/6/2026 | Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions | |
| Analizada | Media (4.3) | 0.34% | — | Devolutions Server | 5/3/2024 | 17/6/2026 | Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authenticated user with specific PAM permissions to make PAM credentials unavailable. | |
| Analizada | Media (5.5) | 0.23% | — | Devolutions Server | 5/3/2024 | 17/6/2026 | Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay authenticated after his user is disabled or deleted in the identity provider such as Okta or Microsoft O365. The user will stay… | |
| Modificada | Media (4.3) | 0.20% | — | Devolutions Server | 5/3/2024 | 17/6/2026 | Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notifications settings configured by an administrator. | |
| Analizada | Alta (7.6) | 0.36% | — | Devolutions Server | 5/3/2024 | 17/6/2026 | Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances | |
| Modificada | Media (5.4) | 0.29% | — | Devolutions Remote Desktop Manager | 31/1/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry. | |
| Modificada | Media (6.5) | 0.33% | — | Topazevolution Antifraud | 8/1/2024 | 17/6/2026 | The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named at a later time). | |
| Modificada | Alta (8.8) | 1.4% | — | Themepunch Slider Revolution | 8/1/2024 | 17/6/2026 | The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution. |