Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

318 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.79%—Expresstech Quiz AND Survey Master29/11/202217/6/2026
The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible for unauthenticated attackers to inject…
ModificadaAlta (7.5)0.71%—Expresstech Quiz AND Survey Master18/11/202217/6/2026
Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress.
ModificadaMedia (6.1)0.45%—Expresstech Quiz AND Survey Master18/11/202217/6/2026
Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
ModificadaCrítica (9.8)0.75%—Expresstech Quiz AND Survey Master18/11/202217/6/2026
Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
ModificadaMedia (5.4)0.47%—Expresstech Quiz AND Survey Master17/11/202217/6/2026
Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaAlta (7.2)0.90%—Limesurvey15/11/202217/6/2026
LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.
ModificadaAlta (8.8)0.58%—Expresstech Quiz AND Survey Master3/11/202217/6/2026
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.
ModificadaAlta (7.2)0.91%—Expresstech Quiz AND Survey Master28/10/202217/6/2026
Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaMedia (5.4)0.46%—Expresstech Quiz AND Survey Master28/10/202217/6/2026
Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaMedia (5.4)0.50%—Expresstech Quiz AND Survey Master28/10/202217/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaMedia (4.3)0.50%—Quizandsurveymaster Quiz AND Survey Master30/9/202217/6/2026
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.
ModificadaMedia (4.8)0.54%—Wpdevart Poll, Survey, Questionnaire AND Voting System6/9/202217/6/2026
Authenticated (admin+) Cross-Site Scripting (XSS) vulnerability in wpdevart Poll, Survey, Questionnaire and Voting system plugin <= 1.7.4 at WordPress.
ModificadaMedia (6.1)0.78%—Limesurvey25/5/202217/6/2026
A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.
ModificadaMedia (6.1)0.57%—Surveysparrow Enterprise Survey Software11/5/202217/6/2026
Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter.
ModificadaMedia (5.4)2.4%💥 ExploitSurveysparrow Enterprise Survey Software11/5/202217/6/2026
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.
ModificadaMedia (6.5)1.3%—Surveyking25/3/20229/7/2026
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.
ModificadaCrítica (9.8)1.9%—Surveyking Project Surveyking24/3/202217/6/2026
Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.
ModificadaCrítica (9.8)1.2%—Diaowen Dwsurvey20/3/202217/6/2026
DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java.
ModificadaCrítica (9.8)3.1%—Diaowen Dwsurvey20/3/202217/6/2026
DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java.
ModificadaAlta (8.8)14%💥 PoCLimesurvey24/2/202217/6/2026
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a…
ModificadaMedia (6.1)0.83%—Ays-pro Survey Maker21/2/202217/6/2026
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6).
ModificadaMedia (6.1)1.4%—Getperfectsurvey Perfect Survey1/2/202217/6/2026
The Perfect Survey WordPress plugin through 1.5.2 does not validate and escape the X-Forwarded-For header value before outputting it in the statistic page when the Anonymize IP setting of a survey is turned off, leading to a Stored Cross-Site Scripting issue
ModificadaMedia (6.1)0.80%—Getperfectsurvey Perfect Survey1/2/202217/6/2026
The Perfect Survey WordPress plugin before 1.5.2 does not sanitise and escape multiple parameters (id and filters[session_id] of single_statistics page, type and message of importexport page) before outputting them back in pages/attributes in the admin dashboard, leading to Reflected Cross-Site Scripting issues
ModificadaAlta (8.8)0.64%—Getperfectsurvey Perfect Survey1/2/202217/6/2026
The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing unauthenticated users to edit surveys and modify settings. Given the lack of sanitisation and escaping in the settings, this could also lead to a Stored Cross-Site…
ModificadaCrítica (9.8)87%💥 ExploitGetperfectsurvey Perfect Survey1/2/202217/6/2026
The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.
Orbitaley — Vulnerabilidades