Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

431 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.50%—Docomo + MessageKddi + MessageSoftbank + Message21/12/202217/6/2026
KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character's specifications.…
ModificadaAlta (8.8)0.59%—Wordplus Better Messages19/11/202217/6/2026
Auth. (subscriber+) Server-Side Request Forgery (SSRF) vulnerability in Better Messages plugin 1.9.10.68 on WordPress.
ModificadaMedia (6.5)0.49%—Wordplus Better Messages18/11/202217/6/2026
Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress.
ModificadaAlta (7.5)1.1%—Messagepack Project Messagepack10/11/202217/6/2026
Unmarshal can panic on some inputs, possibly allowing for denial of service attacks.
ModificadaAlta (8.8)0.38%—Wordplus Better Messages23/8/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress.
ModificadaMedia (6.5)1.1%—Wordplus Better Messages23/8/202217/6/2026
Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress.
ModificadaMedia (4.3)0.29%—Wordplus Better Messages20/7/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated.
ModificadaAlta (7.8)0.21%—YRL Passage DriveYRL Passage Drive FOR BOX20/7/202217/6/2026
Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for Box version v1.0.0 contain an insufficient data verification vulnerability for interprocess communication. By running a malicious program, an arbitrary OS command may be executed with LocalSystem privilege of the Windows system where the product is…
ModificadaAlta (7.8)0.30%—Sage 30014/7/202217/6/2026
In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in the system-wide PATH environment variable. However, this directory is writable by unprivileged users because the Sage installer fails to set explicit permissions and therefore…
ModificadaCrítica (9.8)1.2%—KB Messages PHP Script Project KB Messages PHP Script13/7/202217/6/2026
A vulnerability has been found in KB Messages PHP Script 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to…
ModificadaMedia (5.4)0.55%—Private Messages Project Private Messages15/6/202217/6/2026
Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress <= 2.1.10 at WordPress.
ModificadaMedia (4.3)0.40%—Private Messages Project Private Messages15/6/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Private Messages For WordPress plugin <= 2.1.10 at WordPress allows attackers to send messages.
ModificadaCrítica (9.8)1.5%—Contact-form-with-messages-entry-management Project Contact-form-with-messages-entry-management2/6/202217/6/2026
EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.
ModificadaMedia (6.5)1.0%—Nokia Broadcast Message Center25/5/202217/6/2026
Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and…
ModificadaMedia (6.5)1.3%—Apple Imessage23/3/202217/6/2026
iMessage (Messages app) iOS 12.4 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.
ModificadaCrítica (9.8)1.2%—Messagepack-rs Project Messagepack-rs27/12/202117/6/2026
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string_primitive may read from uninitialized memory locations.
ModificadaCrítica (9.8)1.4%—Messagepack-rs Project Messagepack-rs27/12/202117/6/2026
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_extension_others may read from uninitialized memory locations.
ModificadaCrítica (9.8)1.2%—Messagepack-rs Project Messagepack-rs27/12/202117/6/2026
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string may read from uninitialized memory locations.
ModificadaCrítica (9.8)1.2%—Messagepack-rs Project Messagepack-rs27/12/202117/6/2026
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_binary may read from uninitialized memory locations.
ModificadaMedia (6.5)1.9%—Discourse Message BUS17/12/202117/6/2026
message_bus is a messaging bus for Ruby processes and web clients. In versions prior to 3.3.7 users who deployed message bus with diagnostics features enabled (default off) are vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain…
ModificadaMedia (6.5)1.1%—Vmware Spring Advanced Message Queuing Protocol30/11/202117/6/2026
In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message
ModificadaAlta (8.8)0.73%—Wordplus Better Messages1/11/202117/6/2026
The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread,…
ModificadaMedia (6.1)0.94%—Wordplus Better Messages1/11/202117/6/2026
The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (6.5)1.1%—Vmware Spring Advanced Message Queuing Protocol28/10/202117/6/2026
In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util.Dictionary object that can cause 100% CPU usage in the…
ModificadaMedia (5.5)0.65%—ZTE Axon 30 PRO Message Service25/9/202117/6/2026
There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter settings, attackers could use this vulnerability to obtain some sensitive information of users by accessing specific pages.
Orbitaley — Vulnerabilidades