Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
196 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.93% | — | Goldplugins Easy Testimonials | 26/11/2018 | 17/6/2026 | Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting. | |
| Modificada | Alta (8.8) | 1.2% | — | Slidervilla Testimonial Slider | 12/1/2018 | 17/6/2026 | The Testimonial Slider plugin through 1.2.4 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter). | |
| Modificada | Media (6.1) | 0.78% | — | Goldplugins Easy Testimonials | 1/8/2017 | 17/6/2026 | The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the Default Testimonials Width, View More Testimonials Link, and Testimonial Excerpt Options screens. | |
| Modificada | Alta (8.8) | 2.4% | 💥 Exploit | Goldplugins Testimonials Plugin Easy Testimonials | 12/6/2017 | 17/6/2026 | SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands via the testid parameter to wp-admin/admin.php. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Media (6.8) | 2.8% | 💥 Exploit | Hitmyserver HMS Testimonials | 2/4/2014 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add new testimonials via the hms-testimonials-addnew page, (2) add new groups via the… | |
| Modificada | Alta (7.5) | 6.5% | 💥 Exploit | Indianic Testimonial Plugin | 10/9/2013 | 16/6/2026 | SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the custom_query parameter in a testimonial_add action to wp-admin/admin-ajax.php. | |
| Modificada | Media (6.8) | 3.2% | 💥 Exploit | Indianic Testimonial Plugin | 10/9/2013 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the IndiaNIC Testimonial plugin 2.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add a testimonial via an iNIC_testimonial_save action; (2) add a listing template via an… | |
| Modificada | Alta (7.5) | 1.6% | 💥 Exploit | Autartica COM Autartimonial | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the limit parameter in an autartimonial action to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 6.6% | 💥 Exploit | Timo Gaik Webby Webserver | 27/5/2010 | 16/6/2026 | Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Oscommerce Customer TestimonialsOscommerce | 12/2/2008 | 16/6/2026 | SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrary SQL commands via the testimonial_id parameter. | |
| Modificada | Media (5) | 2.7% | — | Timo Sirainen Dovecot | 20/11/2006 | 16/6/2026 | Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file. | |
| Modificada | Media (4.3) | 1.3% | — | Timothy Claason Knowledgebank | 25/10/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Timothy Claason KnowledgeBank 1.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) index.php, (2) addknowledge.php, and (3) addscreenshot.php. | |
| Modificada | Media (5) | 2.4% | — | Timo Sirainen Dovecot | 16/5/2006 | 16/6/2026 | Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Timobraun Dynamic Galerie | 10/5/2006 | 16/6/2026 | Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter to (1) index.php and (2) galerie.php. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Timobraun Dynamic Galerie | 10/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows remote attackers to inject arbitrary web script or HTML via the pfad parameter in (1) index.php and (2) galerie.php. NOTE: this issue might be resultant from directory traversal. | |
| Modificada | Media (5) | 1.7% | — | Timo Sirainen Dovecot | 16/2/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be… | |
| Modificada | Media (5.1) | 7.4% | 💥 Exploit | Timo Rossi Picasm | 20/5/2005 | 16/6/2026 | Stack-based buffer overflow in the error directive in picasm 1.12b and earlier allows attackers to execute arbitrary code via a long error message. | |
| Modificada | Alta (7.5) | 2.4% | — | Baltimore Technologies Websweeper | 5/9/2001 | 16/6/2026 | Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file is in the parentdir, (3) a /./, or (4)… | |
| Modificada | Alta (7.5) | 2.4% | — | Baltimore Technologies Websweeper | 12/8/2001 | 16/6/2026 | Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using Unicode. | |
| Modificada | Media (5) | 5.3% | 💥 Exploit | Baltimore Technologies Websweeper | 27/6/2001 | 16/6/2026 | Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header. |