Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
250 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.87% | — | Wplegalpages WP Legal Pages | 26/9/2019 | 17/6/2026 | The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-domain-name, lp-business-name, lp-phone, lp-street, lp-city-state, lp-country, lp-email, lp-address, or lp-niche parameters. | |
| Modificada | Crítica (9.1) | 2.5% | — | Insert Pages Project Insert Pages | 22/8/2019 | 17/6/2026 | The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths. | |
| Modificada | Alta (8.8) | 0.65% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 14/8/2019 | 17/6/2026 | The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF. | |
| Modificada | Media (6.5) | 0.60% | — | Mijnpress Simple ADD Pages OR Posts | 14/8/2019 | 17/6/2026 | The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users. | |
| Modificada | Media (6.1) | 0.96% | — | Smackcoders Import ALL Pages, Post Types, Products, Orders, AND Users AS XML & CSV | 12/8/2019 | 17/6/2026 | The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS. | |
| Modificada | Media (6.1) | 1.6% | — | Simplenia Pages | 21/3/2019 | 17/6/2026 | The Simplenia Pages plugin 2.6.0 for Atlassian Bitbucket Server has XSS. | |
| Modificada | Media (6.1) | 0.69% | — | Html-pages Project Html-pages | 1/2/2019 | 17/6/2026 | A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering. | |
| Modificada | Media (5.5) | 0.37% | — | IBM Openpages GRC Platform | 10/9/2018 | 17/6/2026 | IBM OpenPages GRC Platform 7.2, 7.3, 7.4, and 8.0 could allow an attacker to obtain sensitive information from error log files. IBM X-Force ID: 134001. | |
| Modificada | Baja (3.3) | 0.33% | — | IBM Openpages GRC Platform | 30/8/2018 | 17/6/2026 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser. IBM X-Force ID: 110303. | |
| Modificada | Alta (7.5) | 10% | — | Microsoft Asp.net CoreMicrosoft Asp.net Model View ControllerMicrosoft Asp.net Webpages | 11/7/2018 | 17/6/2026 | A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. | |
| Modificada | Alta (8.6) | 1.6% | — | Grunt-gh-pages Project Grunt-gh-pages | 31/5/2018 | 17/6/2026 | A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this output is publicly available then the… | |
| Modificada | Media (5.4) | 0.61% | — | Multidots Mass Pages/posts Creator | 31/5/2018 | 17/6/2026 | An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom content. There is no nonce or user capability check, so anyone can launch a DoS attack against a site and create hundreds of… | |
| Modificada | Crítica (9.8) | 2.2% | — | Html-pages Project Html-pages | 29/5/2018 | 17/6/2026 | The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL. | |
| Modificada | Media (5.3) | 1.3% | — | IBM Openpages GRC Platform | 1/11/2017 | 17/6/2026 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow an unauthenticated user to obtain sensitive information about the server that could be used in future attacks against the system. IBM X-Force ID: 126241. | |
| Modificada | Alta (8.8) | 0.66% | — | IBM Openpages GRC Platform | 1/11/2017 | 17/6/2026 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 125162. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Openpages GRC Platform | 1/11/2017 | 17/6/2026 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125151. | |
| Modificada | Media (5.3) | 1.3% | — | IBM Openpages GRC Platform | 1/11/2017 | 17/6/2026 | IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain sensitive information including private APIs that could be used in further attacks against the system. IBM X-Force ID: 122201. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Openpages GRC Platform | 1/11/2017 | 17/6/2026 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 122200. | |
| Modificada | Media (5.4) | 0.73% | — | IBM Openpages GRC Platform | 1/11/2017 | 17/6/2026 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114711. | |
| Modificada | Media (5.4) | 0.87% | — | IBM Openpages GRC Platform | 24/10/2017 | 17/6/2026 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 114712. | |
| Modificada | Alta (8.8) | 2.9% | — | Inboundnow Wordpress Landing Pages | 18/10/2017 | 17/6/2026 | The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter. | |
| Modificada | Media (5.3) | 0.96% | — | Apple KeynoteApple NumbersApple Pages | 2/4/2017 | 17/6/2026 | An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue involves the "Export" component. It allows users to bypass iWork PDF password protection by leveraging… | |
| Modificada | Media (5.4) | 0.70% | — | IBM Openpages GRC Platform | 1/1/2016 | 17/6/2026 | SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.8) | 2.8% | — | Apple IworkApple Pages | 18/10/2015 | 17/6/2026 | The Apple iWork application before 2.6 for iOS and Apple Pages before 5.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Pages document. | |
| Modificada | Media (6.8) | 2.9% | — | Apple NumbersApple PagesApple KeynoteApple Iwork | 18/10/2015 | 17/6/2026 | The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document. |