Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
191 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.1% | — | Fleetco Fleet Maintenance Management | 2/3/2020 | 17/6/2026 | Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the application/x-php Content-Type to the accidents_add.php?submit=1 URI, as demonstrated by the value_Images_1 field, which leads to remote command execution on the remote server. Any authenticated user can… | |
| Modificada | Alta (7.6) | 2.0% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 9/1/2020 | 17/6/2026 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting). | |
| Modificada | Media (5.4) | 1.1% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 9/1/2020 | 17/6/2026 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes. | |
| Modificada | Alta (8.8) | 0.92% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 9/1/2020 | 17/6/2026 | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo. | |
| Modificada | Alta (8.8) | 0.63% | — | WP Maintenance Project WP Maintenance | 26/12/2019 | 17/6/2026 | A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with resultant XSS. | |
| Modificada | Media (6.5) | 0.87% | — | Yithemes Yith Maintenance Mode | 26/9/2019 | 17/6/2026 | The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter. | |
| Modificada | Media (5.1) | 0.29% | — | HP Blade Maintenance EntityHP Integrated Maintenance EntityHP Maintenance Entity | 5/6/2019 | 17/6/2026 | The HPE Nonstop Maintenance Entity family of products are vulnerable to local disclosure of information, such as system layout and configuration. | |
| Modificada | Alta (7.2) | 1.5% | — | Designmodo WP Maintenance Mode | 14/12/2018 | 17/6/2026 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throughout a multisite network. | |
| Modificada | Media (4.3) | 0.78% | — | Designmodo WP Maintenance Mode | 14/12/2018 | 17/6/2026 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings. | |
| Modificada | Media (4.3) | 0.98% | — | Designmodo WP Maintenance Mode | 14/12/2018 | 17/6/2026 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses. | |
| Modificada | Alta (8.1) | 3.0% | — | Btrfsmaintenance Project Btrfsmaintenance | 15/8/2018 | 17/6/2026 | An issue was discovered in evaluate_auto_mountpoint in btrfsmaintenance-functions in btrfsmaintenance through 0.4.1. Code execution as root can occur via a specially crafted filesystem label if btrfs-{scrub,balance,trim} are set to auto in /etc/sysconfig/btrfsmaintenance (this is not the default, though). | |
| Modificada | Media (6.5) | 2.3% | 💥 Exploit | Dasinfomedia Annual Maintenance Contract Management System | 28/9/2017 | 17/6/2026 | Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling. | |
| Modificada | Alta (8.2) | 1.4% | — | Oracle Complex Maintenance Repair AND Overhaul | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul component in Oracle Supply Chain Products Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Dialog Box. | |
| Modificada | Media (4) | 1.1% | — | SAP Profile Maintenance | 30/4/2014 | 17/6/2026 | SAP Profile Maintenance does not properly restrict access, which allows remote authenticated users to obtain sensitive information via an unspecified RFC function, related to SAP Solution Manager 7.1. | |
| Modificada | Media (6.8) | 0.95% | — | Wordpress WP Maintenance Mode Plugin | 21/6/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings. | |
| Modificada | Alta (7.8) | 3.7% | — | Livedata Iccp ServerLivedata Maintenance ServerLivedata Protocol Server | 3/5/2007 | 16/6/2026 | Unspecified vulnerability in LiveData Server before 5.00.62 allows remote attackers to cause a denial of service (exit) via crafted Connection-Oriented Transport Protocol (COTP) packets. |