Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
351 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 1.1% | — | CraftbeerpiAI | 2/5/2024 | 17/6/2026 | URL GET parameter "logtime" utilized within the "downloadlog" function from "cbpi/http_endpoints/http_system.py" is subsequently passed to the "os.system" function in "cbpi/controller/system_controller.py" without prior validation allowing to execute arbitrary code.This issue affects CraftBeerPi 4: from 4.0.0.58… | |
| Aplazada | Media (6.1) | 0.23% | — | Webcraftplugins Image MAP PROAI | 28/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro allows Stored XSS.This issue affects Image Map Pro: from n/a before 5.6.9. | |
| Modificada | Alta (7.5) | 0.81% | — | Craftycontrol Crafty Controller | 3/2/2024 | 17/6/2026 | A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header | |
| Modificada | Alta (7.5) | 1.1% | — | Craftcms Craft CMS | 30/1/2024 | 17/6/2026 | An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings to Feed-Me Name and Feed-Me URL fields, due to saving a feed using an Asset element type with no volume selected. NOTE: this is not a report about code provided by the… | |
| Modificada | Media (5.4) | 0.38% | — | Craftcms Craft CMS | 30/1/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation. | |
| Modificada | Media (6.5) | 0.55% | — | Palantir Gotham Blackbird-witchcraftPalantir Gotham Static-assets-servlet | 29/1/2024 | 17/6/2026 | Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system. | |
| Modificada | Alta (7.5) | 1.4% | — | Codecrafters Ability FTP Server | 15/1/2024 | 17/6/2026 | A vulnerability has been found in Ability FTP Server 2.34 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component APPE Command Handler. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (8.8) | 0.59% | — | Craftcms Craft CMS | 3/1/2024 | 17/6/2026 | Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has been fixed in Craft 4.4.16 and Craft 3.9.6. Users should ensure they are running at… | |
| Modificada | Alta (7.8) | 0.73% | 💥 PoC | Plain Craft Launcher 2 Project Plain Craft Launcher 2 | 7/10/2023 | 17/6/2026 | Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary code and gain sensitive information. | |
| Modificada | Crítica (9.8) | 94% | 💥 Exploit | Craftcms Craft CMS | 13/9/2023 | 17/6/2026 | Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15. | |
| Modificada | Media (4.8) | 0.47% | — | Formcrafts Formcraft | 30/8/2023 | 17/6/2026 | The FormCraft WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Alta (7.2) | 2.3% | — | Craftcms Craft CMS | 23/8/2023 | 17/6/2026 | Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code execution. This vulnerability can lead to malicious control of vulnerable systems and data exfiltrations. Although the vulnerability is exploitable only in the… | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Craftercms | 3/8/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27. | |
| Modificada | Crítica (9.8) | 0.89% | — | Code4craft Webmagic | 28/7/2023 | 17/6/2026 | webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.PhantomJSDownloader. | |
| Modificada | Alta (7.2) | 0.85% | — | Ncrafts Formcraft | 27/6/2023 | 17/6/2026 | The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | |
| Modificada | Media (5.4) | 0.35% | — | Webcraftplugins Image MAP PRO | 27/6/2023 | 17/6/2026 | The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0. This is due to a missing capability check on the ajax_store_save() function. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.3) | 0.25% | — | Webcraftplugins Image MAP PRO | 27/6/2023 | 17/6/2026 | The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.0. This is due to missing nonce validation on the ajax_store_save() function. This makes it possible for unauthenticated attackers to modify… | |
| Modificada | Media (6.1) | 0.50% | — | Craftcms Craft CMS | 20/6/2023 | 17/6/2026 | Craft CMS through 4.4.9 is vulnerable to HTML Injection. | |
| Modificada | Alta (7.2) | 2.2% | — | Craftcms Craft CMS | 13/6/2023 | 17/6/2026 | CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: the vendor disputes this because only Administrators can add this Twig… | |
| Modificada | Alta (8.8) | 0.87% | — | Minecraft | 30/5/2023 | 17/6/2026 | Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world data that contains a symlink. | |
| Modificada | Media (6.1) | 0.65% | — | Craftcms Craft CMS | 27/5/2023 | 17/6/2026 | Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version 4.4.6. | |
| Modificada | Media (5.4) | 0.65% | — | Craftcms Craft CMS | 26/5/2023 | 17/6/2026 | Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7. | |
| Modificada | Media (4.8) | 0.62% | — | Craftcms Craft CMSCraftercms | 26/5/2023 | 17/6/2026 | Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6. | |
| Modificada | Media (5.4) | 0.68% | — | Craftcms Craft CMS | 26/5/2023 | 17/6/2026 | Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6. | |
| Modificada | Media (5.4) | 0.44% | — | Craftcms Craft CMS | 26/5/2023 | 17/6/2026 | A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively. |