Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
413 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.60% | — | Jfrog ArtifactoryAI | 5/8/2024 | 17/6/2026 | JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning. | |
| Modificada | Baja (1.8) | 0.18% | — | Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services | 16/7/2024 | 17/6/2026 | An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and database folders when they are… | |
| Modificada | Media (6) | 0.30% | — | Rockwellautomation Factorytalk Policy Manager | 16/7/2024 | 17/6/2026 | The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html by implementing CIP… | |
| Analizada | Alta (8.5) | 0.33% | — | Rockwellautomation Factorytalk View | 14/6/2024 | 17/6/2026 | A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access Control Lists, and potentially gaining further access within the system. | |
| Analizada | Alta (8.2) | 0.50% | — | Rockwellautomation Factorytalk View | 14/6/2024 | 17/6/2026 | A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. Due to the lack of proper authentication, this action is allowed without proper authentication… | |
| Modificada | Alta (8.2) | 0.50% | — | Rockwellautomation Factorytalk View | 14/6/2024 | 17/6/2026 | A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification. | |
| Modificada | Crítica (9.8) | 0.40% | — | Wpfactory Products, Order & Customers Export FOR Woocommerce | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WPFactory Products, Order & Customers Export for WooCommerce.This issue affects Products, Order & Customers Export for WooCommerce: from n/a through 2.0.8. | |
| Analizada | Alta (8.8) | 0.36% | — | Dfactory Responsive Lightbox & Gallery | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in dFactory Responsive Lightbox.This issue affects Responsive Lightbox: from n/a through 2.4.6. | |
| Modificada | Media (5.4) | 0.44% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 8/6/2024 | 17/6/2026 | The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_ajax functions in all versions up to, and including, 2.38. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.3) | 0.28% | — | Webfactoryltd WP Reset | 8/6/2024 | 17/6/2026 | The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_ajax function in all versions up to, and including, 2.02. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the value fo the 'License… | |
| Modificada | Media (4.3) | 0.35% | — | Webfactoryltd WP Force SSL | 8/6/2024 | 17/6/2026 | The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_setting' function in versions up to, and including, 1.66. This makes it possible for authenticated attackers, subscriber-level permissions and above, to… | |
| Aplazada | Media (5.3) | 0.35% | — | Webfactoryltd Captcha CodeAI | 4/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in WebFactory Ltd Captcha Code allows Functionality Bypass.This issue affects Captcha Code: from n/a through 2.9. | |
| Aplazada | Media (6.4) | 0.33% | — | Dfactory Download AttachmentsAI | 4/6/2024 | 17/6/2026 | The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'download-attachments' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.67% | — | Wpfactory Download Plugins AND Themes From DashboardAI | 22/5/2024 | 17/6/2026 | Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server. | |
| Analizada | Alta (7.2) | 1.1% | 💥 PoC | Wpfactory EAN FOR Woocommerce | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9. | |
| Analizada | Alta (8.8) | 0.65% | — | Rockwellautomation Factorytalk View | 16/5/2024 | 17/6/2026 | A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack could result in information exposure,… | |
| Aplazada | Alta (7) | 0.27% | 💥 PoC | Rockwellautomation Factorytalk Remote AccessAI | 16/5/2024 | 17/6/2026 | An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a… | |
| Aplazada | Media (6.4) | 0.27% | — | Jfrog ArtifactoryAIJfrog PlatformAI | 15/5/2024 | 17/6/2026 | A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s user email. | |
| Aplazada | Crítica (9) | 0.67% | — | Jfrog ArtifactoryAI | 1/5/2024 | 17/6/2026 | An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled. | |
| Aplazada | Alta (8.1) | 0.85% | — | Wpfactory Customer Email Verification FOR WoocommerceAI | 30/4/2024 | 17/6/2026 | The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification, and… | |
| Aplazada | Alta (8.4) | 1.1% | — | Factory MmigroupAI | 22/4/2024 | 17/6/2026 | An issue was discovered in a third-party com.factory.mmigroup component, shipped on devices from multiple device manufacturers. Certain software builds for various Android devices contain a vulnerable pre-installed app with a package name of com.factory.mmigroup (versionCode='3', versionName='2.1) that allows local… | |
| Aplazada | Media (6.1) | 0.17% | — | Itel Vision 3 TurboAITranssion Autotest FactoryAI | 22/4/2024 | 17/6/2026 | Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package name of com.transsion.autotest.factory (versionCode='7', versionName='1.8.0(220310_1027)') that allows local third-party apps to execute arbitrary shell commands in its context (system user) due to… | |
| Modificada | Media (4.3) | 0.38% | — | Wpfactory EAN FOR Woocommerce | 18/4/2024 | 17/6/2026 | The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'alg_wc_ean_product_meta' shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level… | |
| Modificada | Media (5.4) | 0.32% | — | Wpfactory EAN FOR Woocommerce | 18/4/2024 | 17/6/2026 | The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_product_meta' shortcode in all versions up to, and including, 4.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (4.3) | 0.41% | — | Jfrog Artifactory | 15/4/2024 | 17/6/2026 | JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments. |