Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

194 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.98%—Agentevolution Impress Listings20/9/201917/6/2026
The wp-listings plugin before 2.0.2 for WordPress has includes/views/single-listing.php XSS.
ModificadaAlta (8.8)0.68%—Impress WP Rollback27/8/201917/6/2026
The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
ModificadaMedia (6.1)0.91%—Impress WP Rollback27/8/201917/6/2026
The wp-rollback plugin before 1.2.3 for WordPress has XSS.
ModificadaMedia (6.1)1.5%—Impresscms6/5/201917/6/2026
ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php.
ModificadaAlta (7.2)1.3%—Thimpress Learnpress9/1/201917/6/2026
SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.1)1.0%—Thimpress Learnpress9/1/201917/6/2026
Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (6.1)0.95%—Thimpress Learnpress9/1/201917/6/2026
Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.4)3.7%💥 ExploitImpresscms1/7/201517/6/2026
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_path parameter in a cancel action.
ModificadaMedia (4.3)1.0%—Impresscms11/6/201417/6/2026
Cross-site scripting (XSS) vulnerability in modules/system/admin.php in ImpressCMS 1.3.6.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a listimg action.
ModificadaMedia (6)1.5%—Impresscms6/10/201216/6/2026
Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the icmsConfigPlugins[sanitizer_plugins][] parameter.
ModificadaMedia (4.3)1.7%—Impresscms6/10/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) notifications.php, (2) modules/system/admin/images/browser.php, and (3) modules/content/admin/content.php.
ModificadaAlta (7.5)3.9%—Impresspages CMS6/10/201216/6/2026
Eval injection vulnerability in ip_cms/modules/standard/content_management/actions.php in ImpressPages CMS 1.0.12 and possibly other versons before 1.0.13 allows remote attackers to execute arbitrary code via the cm_group parameter.
ModificadaMedia (4.3)1.1%—Impresscms29/12/201016/6/2026
Cross-site scripting (XSS) vulnerability in modules/content/admin/content.php in ImpressCMS 1.2.3 Final, and possibly other versions before 1.2.4, allows remote attackers to inject arbitrary web script or HTML via the quicksearch_ContentContent parameter.
ModificadaAlta (7.5)1.1%—Impresscms17/11/201016/6/2026
SQL injection vulnerability in ImpressCMS before 1.2.3 RC2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.0%—Impresscms2/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in the userranks feature in modules/system/admin.php in ImpressCMS 1.0.2 final allows remote attackers to inject arbitrary web script or HTML via the rank_title parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)1.5%—Impresscms23/1/200916/6/2026
Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
ModificadaAlta (9.3)17%💥 ExploitBurnaware Technologies BurnawareImpressum CdburnerxpNumedia Soft Numedia DVD Burning SDK30/9/200816/6/2026
NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog…
ModificadaAlta (10)1.4%—Impresscms4/8/200816/6/2026
Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php and "a few files."
ModificadaMedia (5)2.9%—Impressions Games Lords OF THE Realm III31/12/200416/6/2026
Lords of the Realm III 1.01 and earlier, when in the lobby stage, allows remote attackers to cause a denial of service (crash from unallocated memory write) via a long user nickname.
Orbitaley — Vulnerabilidades