Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

413 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.60%—Jfrog ArtifactoryAI5/8/202417/6/2026
JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.
ModificadaBaja (1.8)0.18%—Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services16/7/202417/6/2026
An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and database folders when they are…
ModificadaMedia (6)0.30%—Rockwellautomation Factorytalk Policy Manager16/7/202417/6/2026
The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html by implementing CIP…
AnalizadaAlta (8.5)0.33%—Rockwellautomation Factorytalk View14/6/202417/6/2026
A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access Control Lists, and potentially gaining further access within the system.
AnalizadaAlta (8.2)0.50%—Rockwellautomation Factorytalk View14/6/202417/6/2026
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. Due to the lack of proper authentication, this action is allowed without proper authentication…
ModificadaAlta (8.2)0.50%—Rockwellautomation Factorytalk View14/6/202417/6/2026
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification.
ModificadaCrítica (9.8)0.40%—Wpfactory Products, Order & Customers Export FOR Woocommerce9/6/202417/6/2026
Missing Authorization vulnerability in WPFactory Products, Order & Customers Export for WooCommerce.This issue affects Products, Order & Customers Export for WooCommerce: from n/a through 2.0.8.
AnalizadaAlta (8.8)0.36%—Dfactory Responsive Lightbox & Gallery9/6/202417/6/2026
Missing Authorization vulnerability in dFactory Responsive Lightbox.This issue affects Responsive Lightbox: from n/a through 2.4.6.
ModificadaMedia (5.4)0.44%—Webfactoryltd Minimal Coming Soon & Maintenance Mode8/6/202417/6/2026
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_ajax functions in all versions up to, and including, 2.38. This makes it possible for authenticated attackers, with…
ModificadaMedia (4.3)0.28%—Webfactoryltd WP Reset8/6/202417/6/2026
The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_ajax function in all versions up to, and including, 2.02. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the value fo the 'License…
ModificadaMedia (4.3)0.35%—Webfactoryltd WP Force SSL8/6/202417/6/2026
The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_setting' function in versions up to, and including, 1.66. This makes it possible for authenticated attackers, subscriber-level permissions and above, to…
AplazadaMedia (5.3)0.35%—Webfactoryltd Captcha CodeAI4/6/202417/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in WebFactory Ltd Captcha Code allows Functionality Bypass.This issue affects Captcha Code: from n/a through 2.9.
AplazadaMedia (6.4)0.33%—Dfactory Download AttachmentsAI4/6/202417/6/2026
The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'download-attachments' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaMedia (6.5)0.67%—Wpfactory Download Plugins AND Themes From DashboardAI22/5/202417/6/2026
Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server.
AnalizadaAlta (7.2)1.1%💥 PoCWpfactory EAN FOR Woocommerce17/5/202417/6/2026
Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.
AnalizadaAlta (8.8)0.65%—Rockwellautomation Factorytalk View16/5/202417/6/2026
A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack could result in information exposure,…
AplazadaAlta (7)0.27%💥 PoCRockwellautomation Factorytalk Remote AccessAI16/5/202417/6/2026
An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a…
AplazadaMedia (6.4)0.27%—Jfrog ArtifactoryAIJfrog PlatformAI15/5/202417/6/2026
A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s user email.
AplazadaCrítica (9)0.67%—Jfrog ArtifactoryAI1/5/202417/6/2026
An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.
AplazadaAlta (8.1)0.85%—Wpfactory Customer Email Verification FOR WoocommerceAI30/4/202417/6/2026
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification, and…
AplazadaAlta (8.4)1.1%—Factory MmigroupAI22/4/202417/6/2026
An issue was discovered in a third-party com.factory.mmigroup component, shipped on devices from multiple device manufacturers. Certain software builds for various Android devices contain a vulnerable pre-installed app with a package name of com.factory.mmigroup (versionCode='3', versionName='2.1) that allows local…
AplazadaMedia (6.1)0.17%—Itel Vision 3 TurboAITranssion Autotest FactoryAI22/4/202417/6/2026
Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package name of com.transsion.autotest.factory (versionCode='7', versionName='1.8.0(220310_1027)') that allows local third-party apps to execute arbitrary shell commands in its context (system user) due to…
ModificadaMedia (4.3)0.38%—Wpfactory EAN FOR Woocommerce18/4/202417/6/2026
The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'alg_wc_ean_product_meta' shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level…
ModificadaMedia (5.4)0.32%—Wpfactory EAN FOR Woocommerce18/4/202417/6/2026
The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_product_meta' shortcode in all versions up to, and including, 4.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalizadaMedia (4.3)0.41%—Jfrog Artifactory15/4/202417/6/2026
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.