Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

423 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.50%—Coderevolution Demo MY WordpressAI17/5/202417/6/2026
Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1.
ModificadaMedia (5.4)0.42%—Themepunch Slider Revolution2/5/202417/6/2026
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter in all versions up to, and including, 6.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that…
AplazadaAlta (8.8)0.64%—Coderevolution WP Setup WizardAI25/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodeRevolution WP Setup Wizard.This issue affects WP Setup Wizard: from n/a through 1.0.8.1.
AnalizadaCrítica (9.8)0.63%—Cs-technologies Evolution15/4/202417/6/2026
Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or prompt to ask the user to change the…
AnalizadaAlta (7.5)0.50%—Cs-technologies Evolution15/4/202417/6/2026
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, allowing for an unauthenticated attacker to enumerate all users and their access levels
AnalizadaAlta (7.5)0.50%—Cs-technologies Evolution15/4/202417/6/2026
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS, allowing for an unauthenticated attacker to return the abacard field of any user
AnalizadaAlta (7.5)0.50%—Cs-technologies Evolution15/4/202417/6/2026
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an unauthenticated attacker to return the keys value of any user
AnalizadaAlta (7.5)0.50%—Cs-technologies Evolution15/4/202417/6/2026
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unauthenticated attacker to return the pin value of any user
AnalizadaAlta (7.5)0.50%—Cs-technologies Evolution15/4/202417/6/2026
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the card value data of any user
AnalizadaAlta (7.5)0.54%—Cs-technologies Evolution15/4/202417/6/2026
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller software
AnalizadaAlta (8.8)0.51%—Cs-technologies Evolution15/4/202417/6/2026
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in.
AnalizadaCrítica (9.8)0.58%—Cs-technologies Evolution15/4/202417/6/2026
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and add user profiles within the application, and gain full access of the site.
AnalizadaMedia (4.3)0.28%—Devolutions ServerDevolutions Remote Desktop Manager9/4/202417/6/2026
Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software…
AnalizadaBaja (3.6)0.24%—Devolutions Server9/4/202417/6/2026
Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to forge the displayed group in the PAM JIT elevation checkout request via a specially crafted request.
AnalizadaCrítica (9.8)0.79%—Devolutions Server26/3/202417/6/2026
Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions.
AnalizadaAlta (8.8)0.65%—Devolutions Server26/3/202417/6/2026
Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to elevate themselves to unauthorized groups via a specially crafted request.
AnalizadaMedia (5.9)0.42%—Devolutions Remote Desktop Manager13/3/202417/6/2026
Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attacker that compromised a user endpoint, under specific circumstances, to access sensitive information via residual files in the temporary directory.
AnalizadaMedia (6.3)0.40%—Devolutions Workspace7/3/202417/6/2026
Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions
AnalizadaMedia (4.3)0.34%—Devolutions Server5/3/202417/6/2026
Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authenticated user with specific PAM permissions to make PAM credentials unavailable.
AnalizadaMedia (5.5)0.23%—Devolutions Server5/3/202417/6/2026
Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay authenticated after his user is disabled or deleted in the identity provider such as Okta or Microsoft O365. The user will stay…
ModificadaMedia (4.3)0.20%—Devolutions Server5/3/202417/6/2026
Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notifications settings configured by an administrator.
AnalizadaAlta (7.6)0.36%—Devolutions Server5/3/202417/6/2026
Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances
ModificadaMedia (5.4)0.29%—Devolutions Remote Desktop Manager31/1/202417/6/2026
Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.
ModificadaMedia (6.5)0.33%—Topazevolution Antifraud8/1/202417/6/2026
The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named at a later time).
ModificadaAlta (8.8)1.4%—Themepunch Slider Revolution8/1/202417/6/2026
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.