Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.79% | — | Expresstech Quiz AND Survey Master | 29/11/2022 | 17/6/2026 | The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Alta (7.5) | 0.71% | — | Expresstech Quiz AND Survey Master | 18/11/2022 | 17/6/2026 | Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress. | |
| Modificada | Media (6.1) | 0.45% | — | Expresstech Quiz AND Survey Master | 18/11/2022 | 17/6/2026 | Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. | |
| Modificada | Crítica (9.8) | 0.75% | — | Expresstech Quiz AND Survey Master | 18/11/2022 | 17/6/2026 | Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. | |
| Modificada | Media (5.4) | 0.47% | — | Expresstech Quiz AND Survey Master | 17/11/2022 | 17/6/2026 | Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress. | |
| Modificada | Alta (7.2) | 0.90% | — | Limesurvey | 15/11/2022 | 17/6/2026 | LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php. | |
| Modificada | Alta (8.8) | 0.58% | — | Expresstech Quiz AND Survey Master | 3/11/2022 | 17/6/2026 | Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress. | |
| Modificada | Alta (7.2) | 0.91% | — | Expresstech Quiz AND Survey Master | 28/10/2022 | 17/6/2026 | Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress. | |
| Modificada | Media (5.4) | 0.46% | — | Expresstech Quiz AND Survey Master | 28/10/2022 | 17/6/2026 | Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress. | |
| Modificada | Media (5.4) | 0.50% | — | Expresstech Quiz AND Survey Master | 28/10/2022 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress. | |
| Modificada | Media (4.3) | 0.50% | — | Quizandsurveymaster Quiz AND Survey Master | 30/9/2022 | 17/6/2026 | Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz. | |
| Modificada | Media (4.8) | 0.54% | — | Wpdevart Poll, Survey, Questionnaire AND Voting System | 6/9/2022 | 17/6/2026 | Authenticated (admin+) Cross-Site Scripting (XSS) vulnerability in wpdevart Poll, Survey, Questionnaire and Voting system plugin <= 1.7.4 at WordPress. | |
| Modificada | Media (6.1) | 0.78% | — | Limesurvey | 25/5/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin. | |
| Modificada | Media (6.1) | 0.57% | — | Surveysparrow Enterprise Survey Software | 11/5/2022 | 17/6/2026 | Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter. | |
| Modificada | Media (5.4) | 2.4% | 💥 Exploit | Surveysparrow Enterprise Survey Software | 11/5/2022 | 17/6/2026 | Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter. | |
| Modificada | Media (6.5) | 1.3% | — | Surveyking | 25/3/2022 | 9/7/2026 | SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application. | |
| Modificada | Crítica (9.8) | 1.9% | — | Surveyking Project Surveyking | 24/3/2022 | 17/6/2026 | Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack. | |
| Modificada | Crítica (9.8) | 1.2% | — | Diaowen Dwsurvey | 20/3/2022 | 17/6/2026 | DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java. | |
| Modificada | Crítica (9.8) | 3.1% | — | Diaowen Dwsurvey | 20/3/2022 | 17/6/2026 | DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java. | |
| Modificada | Alta (8.8) | 14% | 💥 PoC | Limesurvey | 24/2/2022 | 17/6/2026 | A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a… | |
| Modificada | Media (6.1) | 0.83% | — | Ays-pro Survey Maker | 21/2/2022 | 17/6/2026 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6). | |
| Modificada | Media (6.1) | 1.4% | — | Getperfectsurvey Perfect Survey | 1/2/2022 | 17/6/2026 | The Perfect Survey WordPress plugin through 1.5.2 does not validate and escape the X-Forwarded-For header value before outputting it in the statistic page when the Anonymize IP setting of a survey is turned off, leading to a Stored Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.80% | — | Getperfectsurvey Perfect Survey | 1/2/2022 | 17/6/2026 | The Perfect Survey WordPress plugin before 1.5.2 does not sanitise and escape multiple parameters (id and filters[session_id] of single_statistics page, type and message of importexport page) before outputting them back in pages/attributes in the admin dashboard, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Alta (8.8) | 0.64% | — | Getperfectsurvey Perfect Survey | 1/2/2022 | 17/6/2026 | The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing unauthenticated users to edit surveys and modify settings. Given the lack of sanitisation and escaping in the settings, this could also lead to a Stored Cross-Site… | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Getperfectsurvey Perfect Survey | 1/2/2022 | 17/6/2026 | The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection. |