Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

370 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.60%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the mass configuration…
ModificadaAlta (8.8)0.60%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the alert settings of…
ModificadaMedia (4.3)0.54%—Wpexperts Post Smtp12/7/202317/6/2026
The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.20. This is due to missing or incorrect nonce validation on the handleCsvExport() function. This makes it possible for unauthenticated attackers to trigger a CSV export via a forged request…
ModificadaMedia (6.1)0.50%—Wpexperts Post Smtp12/7/202317/6/2026
The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever…
ModificadaAlta (8.8)0.26%—Wepupil Quiz Expert - Easy Quiz Maker, Exam AND Test Manager11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WePupil Quiz Expert plugin <= 1.5.0 versions.
ModificadaMedia (6.1)0.73%💥 ExploitWp-experts Protect WP Admin4/7/202317/6/2026
The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.
ModificadaMedia (4.3)0.38%—Wpexpertdeveloper WP Private Content Plus1/7/202317/6/2026
The WP Private Content Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. This is due to missing or incorrect nonce validation on the save_groups() function. This makes it possible for unauthenticated attackers to add new group members via a forged request…
ModificadaMedia (4.8)0.40%—Wpexperts Password Protected23/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPExperts Password Protected plugin <= 2.6.2 versions.
ModificadaMedia (5.4)0.41%—Softexpert Excellence Suite14/6/202317/6/2026
SoftExpert Excellence Suite 2.1.9 is vulnerable to Cross Site Scripting (XSS) via query screens.
ModificadaAlta (7.8)0.60%—Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue14/6/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
ModificadaAlta (8.8)1.2%—Wpexperts Email Templates7/6/202317/6/2026
The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers to present phishing forms or conduct cross-site request forgery attacks against site administrators.
ModificadaMedia (5.4)0.44%—Wpexperts WP Multi Store Locator5/6/202317/6/2026
The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaCrítica (9.8)5.9%💥 ExploitSoftexpert Excellence Suite12/5/202317/6/2026
SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.
ModificadaAlta (8.8)0.32%—Schneider-electric Ecostruxure Power Monitoring Expert18/4/202317/6/2026
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account.
ModificadaAlta (8.1)0.82%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the appliance over SSH. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (7.8)0.59%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privilege escalation on the appliance when a maliciously crafted Operating System command is entered on the device. Affected products: StruxureWare Data Center Expert (V7.9.2…
ModificadaMedia (6.1)0.39%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpoint through the logging capabilities of the webserver. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (8.1)0.50%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer settings on DCE endpoints. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaMedia (6.1)0.40%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE file upload endpoint when tampering with parameters over HTTP. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaCrítica (9.8)1.2%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” parameter when maliciously crafted hostname syntax is entered. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaCrítica (9.8)1.2%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution when using a parameter of the DCE network settings endpoint. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaMedia (6.5)0.55%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE endpoints not being properly secured when a hacker is using a low privileged user. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (8.8)0.94%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install packages when a hacker is using a low privileged user account. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (8.8)0.84%—Schneider-electric Ecostruxure Control Expert18/4/202317/6/2026
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link provided through the web endpoints. Affected Products: EcoStruxure Control Expert (V15.1 and above)
ModificadaMedia (5.5)0.15%—Schneider-electric Ecostruxure Control Expert18/4/202317/6/2026
A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server service that is part of EcoStruxure Control Expert. Affected Products: EcoStruxure Control Expert (V15.1 and above)
Orbitaley — Vulnerabilidades