Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1437 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.18% | — | Parisneo Lollms WEB UI | 10/6/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the clear_personality_files_list function of the parisneo/lollms-webui v9.6. The vulnerability arises from the use of a GET request to clear personality files list, which lacks proper CSRF protection. This flaw allows attackers to trick users into performing… | |
| Modificada | Crítica (9.8) | 0.41% | — | Typps Calendarista | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.5. | |
| Modificada | Media (4.3) | 0.26% | — | Comparisonslider Comparison Slider | 30/5/2024 | 17/6/2026 | The Comparison Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 1.0.5. This makes it possible for authenticated attackers, with subscriber access or above, to change plugin settings and perform… | |
| Modificada | Media (4.3) | 0.18% | — | Comparisonslider Comparison Slider | 30/5/2024 | 17/6/2026 | The Comparison Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on several functions hooked to AJAX actions. This makes it possible for unauthenticated attackers to change slider titles, delete… | |
| Modificada | Media (5.4) | 0.25% | — | Comparisonslider Comparison Slider | 30/5/2024 | 17/6/2026 | The Comparison Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the slider title parameter in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject… | |
| Aplazada | Crítica (9.8) | 0.92% | — | Parisneo LollmsAI | 16/5/2024 | 17/6/2026 | A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code execution due to insufficient sanitization of user input. The issue arises from the lack of path sanitization when handling the `name` parameter in the `unInstall_binding` function, allowing an attacker… | |
| Analizada | Alta (7.5) | 0.46% | — | Claris Filemaker Server | 14/5/2024 | 17/6/2026 | Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileMaker Server 20.3.2 by validating transactions before replying to client requests. | |
| Analizada | Media (4.9) | 0.45% | — | Claris Filemaker Server | 14/5/2024 | 17/6/2026 | Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by eliminating the send of Admin Role passwords in the Node.js socket. | |
| Analizada | Baja (2) | 0.26% | — | Oracle Solaris | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require… | |
| Modificada | Alta (7.8) | 0.17% | — | Oracle Solaris | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in… | |
| Modificada | Alta (8.2) | 0.27% | — | Oracle Solaris | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Zones). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in… | |
| Analizada | Media (6.1) | 0.31% | — | Claris Filemaker Server | 15/4/2024 | 17/6/2026 | Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login endpoint. The vulnerability was resolved in FileMaker Server 20.3.2 by escaping the HTML contents of the login error message on the… | |
| Aplazada | Media (4.3) | 0.23% | — | Typps Calendarista Basic EditionAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2. | |
| Aplazada | Alta (8.5) | 0.55% | — | Typps CalendaristaAI | 28/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Typps Calendarista.This issue affects Calendarista: from n/a through 15.5.7. | |
| Analizada | Media (4.9) | 0.45% | — | Claris PROClaris Filemaker Server | 21/3/2024 | 17/6/2026 | A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in requests. | |
| Aplazada | Alta (7.1) | 0.37% | — | Typps Calendarista-basic-editionAI | 21/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2. | |
| Modificada | Alta (7.8) | 0.18% | — | Claris PROClaris Filemaker PRO | 19/3/2024 | 17/6/2026 | Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS. | |
| Modificada | Alta (7.5) | 1.2% | 💥 PoC | Autopolis Bulgarisation FOR Woocommerce | 13/3/2024 | 17/6/2026 | The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in all versions up to, and including, 3.0.14. This makes it possible for unauthenticated and authenticated attackers, with subscriber-level access and above, to generate and… | |
| Modificada | Media (4.3) | 0.18% | — | Autopolis Bulgarisation FOR Woocommerce | 12/3/2024 | 17/6/2026 | The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.14. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to generate and delete labels via a forged… | |
| Analizada | Alta (8.8) | 8.8% | — | Arista NG Firewall | 4/3/2024 | 17/6/2026 | Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges. | |
| Analizada | Baja (3.1) | 0.34% | — | Arista Multiaccess | 4/3/2024 | 17/6/2026 | On affected 7130 Series FPGA platforms running MOS and recent versions of the MultiAccess FPGA, application of ACL’s may result in incorrect operation of the configured ACL for a port resulting in some packets that should be denied being permitted and some | |
| Modificada | Media (5.5) | 0.18% | — | Oracle Solaris | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this… | |
| Modificada | Baja (3.8) | 0.19% | — | Oracle Solaris | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in… | |
| Modificada | Media (6.5) | 0.34% | — | Arista MOS | 6/12/2023 | 17/6/2026 | On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed in local logs or remote logging servers by authenticated users, as well as appear in clear text in the device’s running config. | |
| Modificada | Media (6.1) | 0.37% | — | Evarisk Digirisk | 3/11/2023 | 17/6/2026 | The Digirisk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'current_group_id' parameter in version 6.0.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can… |