Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.5% | — | Najeebmedia Frontend File Manager | 3/10/2022 | 17/6/2026 | The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE | |
| Modificada | Media (5.3) | 8.3% | 💥 Exploit | Najeebmedia Frontend File Manager | 3/10/2022 | 17/6/2026 | The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the web server | |
| Modificada | Media (4.4) | 1.2% | — | Zabbix FrontendDebian LinuxFedoraproject Fedora | 9/3/2022 | 17/6/2026 | An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the… | |
| Modificada | Media (4.4) | 1.2% | — | Zabbix FrontendFedoraproject Fedora | 9/3/2022 | 17/6/2026 | An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the… | |
| Modificada | Media (4.4) | 1.2% | — | Zabbix FrontendDebian LinuxFedoraproject Fedora | 9/3/2022 | 17/6/2026 | An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as… | |
| Modificada | Media (4.4) | 1.2% | — | Zabbix FrontendDebian LinuxFedoraproject Fedora | 9/3/2022 | 17/6/2026 | An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim. This attack can be implemented… | |
| Modificada | Alta (8.8) | 17% | 💥 Exploit | Wedevs WP User Frontend | 24/1/2022 | 17/6/2026 | The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 8.5% | 💥 Exploit | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 21/12/2021 | 17/6/2026 | The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections | |
| Modificada | Alta (8.8) | 1.3% | — | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 8/11/2021 | 17/6/2026 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using… | |
| Modificada | Media (6.1) | 26% | 💥 Exploit | Frontend Uploader Project Frontend Uploader | 11/10/2021 | 17/6/2026 | The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly | |
| Modificada | Media (4.3) | 0.67% | — | Otrs ItsmconfigurationmanagementOtrscisincustomerfrontend | 22/3/2021 | 17/6/2026 | Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects: OTRSCIsInCustomerFrontend 7.0.15 and prior versions, ITSMConfigurationManagement 7.0.24 and prior versions | |
| Modificada | Media (4.3) | 0.76% | — | Otrs CIS IN Customer Frontend | 8/2/2021 | 17/6/2026 | Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions. | |
| Modificada | Media (6.5) | 0.53% | — | View Frontend Statistics Project View Frontend Statistics | 18/11/2020 | 17/6/2026 | An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext passwords if ext:felogin is installed) may be… | |
| Modificada | Media (6.1) | 0.81% | — | Mediawiki Mobilefrontend | 19/3/2020 | 17/6/2026 | In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affects REL1_31, REL1_32, and REL1_33. | |
| Modificada | Media (6.1) | 0.70% | — | Mediawiki Mobilefrontend | 9/8/2019 | 17/6/2026 | In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.php. | |
| Modificada | Media (6.1) | 1.2% | — | Open-xchange Documentconverter-apiOpen-xchange Office WEBOpen-xchange Appsuite BackendOpen-xchange Appsuite Frontend | 29/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0 before 7.8.0-rev10, and 7.8.2 before… | |
| Modificada | Alta (7.5) | 2.2% | — | Frontend User Upload Project Frontend User Upload | 16/6/2015 | 17/6/2026 | Unrestricted file upload vulnerability in the Frontend User Upload (feupload) extension 0.5.0 and earlier for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension using a frontend form, then accessing it via a direct request to the file in the fileadmin folder. | |
| Modificada | Media (4.3) | 6.5% | 💥 Exploit | Frontend Uploader Project Frontend Uploader | 2/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI. | |
| Modificada | Alta (7.5) | 2.7% | — | CWT Frontend Edit Project CWT Frontend Edit | 11/9/2014 | 17/6/2026 | Unspecified vulnerability in the CWT Frontend Edit (cwt_feedit) extension before 1.2.5 for TYPO3 allows remote authenticated users to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Steve Grundell Frontend MP3 Player | 17/6/2009 | 16/6/2026 | SQL injection vulnerability in the Frontend MP3 Player (fe_mp3player) 0.2.3 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 Frontend Users View | 22/10/2008 | 16/6/2026 | SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | Typo3 DAM Frontend Extension | 7/7/2008 | 16/6/2026 | Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 SQL Frontend Extension | 7/7/2008 | 16/6/2026 | SQL injection vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 DAM Frontend Extension | 7/7/2008 | 16/6/2026 | SQL injection vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Typo3 SQL Frontend Extension | 7/7/2008 | 16/6/2026 | Unspecified vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to cause a denial of service via unknown vectors. |