Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.24% | — | Switchwp WP Client Reports | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SwitchWP WP Client Reports.This issue affects WP Client Reports: from n/a through 1.0.22. | |
| Modificada | Alta (8.8) | 0.24% | — | Pluginus FOX - Currency Switcher Professional FOR Woocommerce | 29/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7. | |
| Modificada | Alta (8.8) | 0.24% | — | Pluginus Wordpress Currency Switcher | 29/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1. | |
| Aplazada | Media (4.9) | 0.52% | — | Arubaos-switchAI | 26/3/2024 | 17/6/2026 | Authenticated Denial of Service Vulnerability in ArubaOS-Switch SSH Daemon | |
| Analizada | Media (4.9) | 0.64% | — | Wp-buy Login AS User OR Customer (user Switching) | 11/3/2024 | 17/6/2026 | The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site. | |
| Analizada | Alta (7.5) | 1.0% | — | OpenvswitchFedoraproject Fedora | 22/2/2024 | 17/6/2026 | A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled. | |
| Aplazada | Alta (7.5) | 0.52% | — | UI Unifi Access PointsAIUI Unifi SwitchesAIUI Unifi LTE BackupAIUI Unifi ExpressAI | 20/2/2024 | 17/6/2026 | A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery. Affected Products: UniFi Access Points UniFi Switches UniFi LTE Backup UniFi Express (Only Mesh Mode, Router mode is not affected) Mitigation: Update UniFi… | |
| Analizada | Crítica (9.8) | 62% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet FortiswitchmanagerFortinet FortiosFortinet Fortipam | 15/2/2024 | 17/6/2026 | A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions… | |
| Modificada | Media (5.4) | 0.27% | — | Pluginus Wordpress Currency Switcher | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WPCS – WordPress Currency Switcher Professional allows Stored XSS.This issue affects WPCS – WordPress Currency Switcher Professional: from n/a through 1.2.0. | |
| Modificada | Alta (7.5) | 0.57% | — | Openvswitch | 19/1/2024 | 17/6/2026 | openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c. | |
| Modificada | Alta (8.8) | 1.3% | — | Pluginus FOX - Currency Switcher Professional FOR Woocommerce | 16/1/2024 | 17/6/2026 | The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode. | |
| Modificada | Media (5.4) | 0.41% | — | Pluginus FOX - Currency Switcher Professional FOR Woocommerce | 11/1/2024 | 17/6/2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.9) | 1.5% | — | Freeswitch | 27/12/2023 | 17/6/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.11, when handling DTLS-SRTP for media setup, FreeSWITCH is susceptible to Denial of Service due to a race… | |
| Modificada | Alta (8.8) | 0.25% | — | Pluginus FOX - Currency Switcher Professional FOR Woocommerce | 17/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 FOX – Currency Switcher Professional for WooCommerce.This issue affects FOX – Currency Switcher Professional for WooCommerce: from n/a through 1.4.1.4. | |
| Modificada | Alta (7.6) | 0.79% | — | Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+4 | 14/12/2023 | 17/6/2026 | Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit f57bd745b4cbed577ea654fad4701bea4d38b44c. A malicious game streaming server could exploit a buffer overflow vulnerability to crash a moonlight client.… | |
| Modificada | Alta (8.8) | 1.7% | — | Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+3 | 14/12/2023 | 17/6/2026 | Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. A malicious game streaming server… | |
| Modificada | Alta (8.8) | 1.7% | — | Moonlight-stream Moonlight-common-cMoonlight-stream MoonlightMoonlight-stream Moonlight EmbeddedMoonlight-stream Moonlight Xbox+3 | 14/12/2023 | 17/6/2026 | Moonlight-common-c contains the core GameStream client code shared between Moonlight clients. Moonlight-common-c is vulnerable to buffer overflow starting in commit 50c0a51b10ecc5b3415ea78c21d96d679e2288f9 due to unmitigated usage of unsafe C functions and improper bounds checking. A malicious game streaming server… | |
| Modificada | Alta (8.8) | 0.49% | — | Fortinet FortiaiFortinet FortimailFortinet FortindrFortinet Fortirecorder+2 | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x,… | |
| Modificada | Media (6.5) | 0.68% | — | Switchwp WP Client Reports | 23/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SwitchWP WP Client Reports plugin <= 1.0.16 versions. | |
| Modificada | Alta (8.8) | 0.29% | — | Jamesmehorter Device Theme Switcher | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in James Mehorter Device Theme Switcher.This issue affects Device Theme Switcher: from n/a through 3.0.2. | |
| Modificada | Media (5.4) | 0.44% | — | Plugin-planet Theme Switcha | 20/10/2023 | 17/6/2026 | The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'theme_switcha_list' shortcode in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (7.5) | 0.78% | — | Tapo Mini Smart Wi-fi Plug FirmwareNanoleaf Lightstrip FirmwareGovee LED Strip FirmwareSwitchbot Hub2 Firmware+5 | 10/10/2023 | 17/6/2026 | Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a… | |
| Modificada | Media (5.5) | 0.42% | — | OpenvswitchRedhat Openshift Container PlatformRedhat VirtualizationRedhat Enterprise Linux+1 | 6/10/2023 | 17/6/2026 | A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses. | |
| Modificada | Alta (8.8) | 0.25% | — | Fugu Maintenance Switch | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fugu Maintenance Switch plugin <= 1.5.2 versions. | |
| Modificada | Media (6.5) | 0.91% | — | Freeswitch | 15/9/2023 | 17/6/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.10, FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP… |