Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
431 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.50% | — | Docomo + MessageKddi + MessageSoftbank + Message | 21/12/2022 | 17/6/2026 | KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character's specifications.… | |
| Modificada | Alta (8.8) | 0.59% | — | Wordplus Better Messages | 19/11/2022 | 17/6/2026 | Auth. (subscriber+) Server-Side Request Forgery (SSRF) vulnerability in Better Messages plugin 1.9.10.68 on WordPress. | |
| Modificada | Media (6.5) | 0.49% | — | Wordplus Better Messages | 18/11/2022 | 17/6/2026 | Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress. | |
| Modificada | Alta (7.5) | 1.1% | — | Messagepack Project Messagepack | 10/11/2022 | 17/6/2026 | Unmarshal can panic on some inputs, possibly allowing for denial of service attacks. | |
| Modificada | Alta (8.8) | 0.38% | — | Wordplus Better Messages | 23/8/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress. | |
| Modificada | Media (6.5) | 1.1% | — | Wordplus Better Messages | 23/8/2022 | 17/6/2026 | Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress. | |
| Modificada | Media (4.3) | 0.29% | — | Wordplus Better Messages | 20/7/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated. | |
| Modificada | Alta (7.8) | 0.21% | — | YRL Passage DriveYRL Passage Drive FOR BOX | 20/7/2022 | 17/6/2026 | Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for Box version v1.0.0 contain an insufficient data verification vulnerability for interprocess communication. By running a malicious program, an arbitrary OS command may be executed with LocalSystem privilege of the Windows system where the product is… | |
| Modificada | Alta (7.8) | 0.30% | — | Sage 300 | 14/7/2022 | 17/6/2026 | In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in the system-wide PATH environment variable. However, this directory is writable by unprivileged users because the Sage installer fails to set explicit permissions and therefore… | |
| Modificada | Crítica (9.8) | 1.2% | — | KB Messages PHP Script Project KB Messages PHP Script | 13/7/2022 | 17/6/2026 | A vulnerability has been found in KB Messages PHP Script 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Modificada | Media (5.4) | 0.55% | — | Private Messages Project Private Messages | 15/6/2022 | 17/6/2026 | Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress <= 2.1.10 at WordPress. | |
| Modificada | Media (4.3) | 0.40% | — | Private Messages Project Private Messages | 15/6/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Private Messages For WordPress plugin <= 2.1.10 at WordPress allows attackers to send messages. | |
| Modificada | Crítica (9.8) | 1.5% | — | Contact-form-with-messages-entry-management Project Contact-form-with-messages-entry-management | 2/6/2022 | 17/6/2026 | EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database. | |
| Modificada | Media (6.5) | 1.0% | — | Nokia Broadcast Message Center | 25/5/2022 | 17/6/2026 | Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and… | |
| Modificada | Media (6.5) | 1.3% | — | Apple Imessage | 23/3/2022 | 17/6/2026 | iMessage (Messages app) iOS 12.4 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages. | |
| Modificada | Crítica (9.8) | 1.2% | — | Messagepack-rs Project Messagepack-rs | 27/12/2021 | 17/6/2026 | An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string_primitive may read from uninitialized memory locations. | |
| Modificada | Crítica (9.8) | 1.4% | — | Messagepack-rs Project Messagepack-rs | 27/12/2021 | 17/6/2026 | An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_extension_others may read from uninitialized memory locations. | |
| Modificada | Crítica (9.8) | 1.2% | — | Messagepack-rs Project Messagepack-rs | 27/12/2021 | 17/6/2026 | An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string may read from uninitialized memory locations. | |
| Modificada | Crítica (9.8) | 1.2% | — | Messagepack-rs Project Messagepack-rs | 27/12/2021 | 17/6/2026 | An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_binary may read from uninitialized memory locations. | |
| Modificada | Media (6.5) | 1.9% | — | Discourse Message BUS | 17/12/2021 | 17/6/2026 | message_bus is a messaging bus for Ruby processes and web clients. In versions prior to 3.3.7 users who deployed message bus with diagnostics features enabled (default off) are vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain… | |
| Modificada | Media (6.5) | 1.1% | — | Vmware Spring Advanced Message Queuing Protocol | 30/11/2021 | 17/6/2026 | In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message | |
| Modificada | Alta (8.8) | 0.73% | — | Wordplus Better Messages | 1/11/2021 | 17/6/2026 | The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread,… | |
| Modificada | Media (6.1) | 0.94% | — | Wordplus Better Messages | 1/11/2021 | 17/6/2026 | The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.5) | 1.1% | — | Vmware Spring Advanced Message Queuing Protocol | 28/10/2021 | 17/6/2026 | In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util.Dictionary object that can cause 100% CPU usage in the… | |
| Modificada | Media (5.5) | 0.65% | — | ZTE Axon 30 PRO Message Service | 25/9/2021 | 17/6/2026 | There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter settings, attackers could use this vulnerability to obtain some sensitive information of users by accessing specific pages. |