Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

344 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.54%—Javik Randomize8/1/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Javik Randomize.This issue affects Randomize: from n/a through 1.4.3.
ModificadaMedia (5.4)0.42%—Grandslambert Better RSS Widget22/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grandslambert Better RSS Widget plugin <= 2.8.1 versions.
ModificadaMedia (4.8)0.39%—Grandplugins WOO Quick View AND BUY NOW14/11/202317/6/2026
Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in GrandPlugins Direct Checkout – Quick View – Buy Now For WooCommerce plugin <= 1.5.8 versions.
ModificadaAlta (8.8)0.31%—Brandbrilliance Post State Tags13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in BRANDbrilliance Post State Tags plugin <= 2.0.6 versions.
ModificadaAlta (8.8)0.21%—Featherplugins Custom Login Page | Temporary Users | Rebrand Login | Login Captcha6/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3 versions.
ModificadaMedia (6.5)0.48%—Grandingteco Utime Master13/10/202317/6/2026
An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to access sensitive information via a crafted cookie.
ModificadaMedia (4.8)0.35%—Grandingteco Utime Master13/10/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in the Create A New Employee function of Granding UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter.
ModificadaAlta (8.8)0.25%—Randyhoyt Category Meta12/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in josecoelho, Randy Hoyt, steveclarkcouk, Vitaliy Kukin, Eric Le Bail, Tom Ransom Category Meta plugin plugin <= 1.2.8 versions.
ModificadaCrítica (9.8)0.64%—Themevolty Theme Volty CMS Brandlist3/10/202317/6/2026
Improper neutralization of SQL parameter in Theme Volty CMS BrandList module for PrestaShop In the module “Theme Volty CMS BrandList” (tvcmsbrandlist) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.
ModificadaMedia (5.4)0.38%—Woocommerce Brands30/8/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.45 versions.
ModificadaMedia (4.8)0.37%—Brandid Social Proof (testimonial) Slider10/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in brandiD Social Proof (Testimonial) Slider plugin <= 2.2.3 versions.
ModificadaAlta (8.8)0.26%—Woocommerce Brands17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.49 versions.
ModificadaMedia (6.1)0.66%—Woocommerce Wooframework Branding5/6/202317/6/2026
A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_screen_logic of the file wooframework-branding.php. The manipulation of the argument url leads to open redirect. It is possible to launch the attack remotely. Upgrading to…
ModificadaMedia (5.4)0.36%—Berocket Brands FOR Woocommerce18/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in BeRocket Brands for WooCommerce plugin <= 3.7.0.6 versions.
ModificadaMedia (4.8)0.39%—White Label Branding FOR Elementor Page Builder Project White Label Branding FOR Elementor Page Builder15/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ozan Canakli White Label Branding for Elementor Page Builder plugin <= 1.0.2 versions.
ModificadaMedia (4.8)0.37%—WSB Brands Project WSB Brands8/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Branko Borilovic WSB Brands plugin <= 1.1.8 versions.
ModificadaAlta (8.8)0.89%—Random Text Project Random Text24/4/202317/6/2026
The Random Text WordPress plugin through 0.3.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers.
ModificadaCrítica (9.8)1.2%—Brandsdistribution Bdroppy24/4/202317/6/2026
SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component.
ModificadaMedia (6.1)0.44%—Intranda Goobi Viewer Core6/4/202317/6/2026
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when using nicknames. An attacker could create a user account and enter malicious scripts into their profile's…
ModificadaMedia (6.1)0.44%—Intranda Goobi Viewer Core6/4/202317/6/2026
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of…
ModificadaMedia (6.1)0.44%—Intranda Goobi Viewer Core6/4/202317/6/2026
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted…
ModificadaAlta (7.3)1.5%💥 PoCRockstargames Grand Theft Auto V22/1/202317/6/2026
Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023.
ModificadaCrítica (9.8)5.7%💥 ExploitGrandstream Gds3710 Firmware23/9/202217/6/2026
In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, an attacker could create a socket and connect with a remote IP:port by opening a shell and getting full access to the system. The exploit…
ModificadaCrítica (9.8)5.3%💥 ExploitGrandstream Gds3710 Firmware23/9/202217/6/2026
an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.
ModificadaAlta (8.8)0.80%—Malighting Grandma2 Light Firmware21/8/202217/6/2026
MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated networks. Also, the successor product, grandMA3, is not affected by this vulnerability.
Orbitaley — Vulnerabilidades