Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.54% | — | Javik Randomize | 8/1/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Javik Randomize.This issue affects Randomize: from n/a through 1.4.3. | |
| Modificada | Media (5.4) | 0.42% | — | Grandslambert Better RSS Widget | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grandslambert Better RSS Widget plugin <= 2.8.1 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Grandplugins WOO Quick View AND BUY NOW | 14/11/2023 | 17/6/2026 | Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in GrandPlugins Direct Checkout – Quick View – Buy Now For WooCommerce plugin <= 1.5.8 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Brandbrilliance Post State Tags | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BRANDbrilliance Post State Tags plugin <= 2.0.6 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Featherplugins Custom Login Page | Temporary Users | Rebrand Login | Login Captcha | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3 versions. | |
| Modificada | Media (6.5) | 0.48% | — | Grandingteco Utime Master | 13/10/2023 | 17/6/2026 | An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to access sensitive information via a crafted cookie. | |
| Modificada | Media (4.8) | 0.35% | — | Grandingteco Utime Master | 13/10/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Create A New Employee function of Granding UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter. | |
| Modificada | Alta (8.8) | 0.25% | — | Randyhoyt Category Meta | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in josecoelho, Randy Hoyt, steveclarkcouk, Vitaliy Kukin, Eric Le Bail, Tom Ransom Category Meta plugin plugin <= 1.2.8 versions. | |
| Modificada | Crítica (9.8) | 0.64% | — | Themevolty Theme Volty CMS Brandlist | 3/10/2023 | 17/6/2026 | Improper neutralization of SQL parameter in Theme Volty CMS BrandList module for PrestaShop In the module “Theme Volty CMS BrandList” (tvcmsbrandlist) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions. | |
| Modificada | Media (5.4) | 0.38% | — | Woocommerce Brands | 30/8/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.45 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Brandid Social Proof (testimonial) Slider | 10/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in brandiD Social Proof (Testimonial) Slider plugin <= 2.2.3 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Woocommerce Brands | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.49 versions. | |
| Modificada | Media (6.1) | 0.66% | — | Woocommerce Wooframework Branding | 5/6/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_screen_logic of the file wooframework-branding.php. The manipulation of the argument url leads to open redirect. It is possible to launch the attack remotely. Upgrading to… | |
| Modificada | Media (5.4) | 0.36% | — | Berocket Brands FOR Woocommerce | 18/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in BeRocket Brands for WooCommerce plugin <= 3.7.0.6 versions. | |
| Modificada | Media (4.8) | 0.39% | — | White Label Branding FOR Elementor Page Builder Project White Label Branding FOR Elementor Page Builder | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ozan Canakli White Label Branding for Elementor Page Builder plugin <= 1.0.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | WSB Brands Project WSB Brands | 8/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Branko Borilovic WSB Brands plugin <= 1.1.8 versions. | |
| Modificada | Alta (8.8) | 0.89% | — | Random Text Project Random Text | 24/4/2023 | 17/6/2026 | The Random Text WordPress plugin through 0.3.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers. | |
| Modificada | Crítica (9.8) | 1.2% | — | Brandsdistribution Bdroppy | 24/4/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component. | |
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when using nicknames. An attacker could create a user account and enter malicious scripts into their profile's… | |
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of… | |
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted… | |
| Modificada | Alta (7.3) | 1.5% | 💥 PoC | Rockstargames Grand Theft Auto V | 22/1/2023 | 17/6/2026 | Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023. | |
| Modificada | Crítica (9.8) | 5.7% | 💥 Exploit | Grandstream Gds3710 Firmware | 23/9/2022 | 17/6/2026 | In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, an attacker could create a socket and connect with a remote IP:port by opening a shell and getting full access to the system. The exploit… | |
| Modificada | Crítica (9.8) | 5.3% | 💥 Exploit | Grandstream Gds3710 Firmware | 23/9/2022 | 17/6/2026 | an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access. | |
| Modificada | Alta (8.8) | 0.80% | — | Malighting Grandma2 Light Firmware | 21/8/2022 | 17/6/2026 | MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated networks. Also, the successor product, grandMA3, is not affected by this vulnerability. |