Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
413 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.20% | — | Dfactory Post Views CounterAI | 12/4/2024 | 17/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Post Views Counter <= 1.4.4 versions. | |
| Modificada | Media (5.9) | 0.70% | — | Webfactoryltd WP Reset | 9/4/2024 | 17/6/2026 | The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0 via the use of insufficiently random snapshot names. This makes it possible for unauthenticated attackers to extract sensitive data including site backups by… | |
| Aplazada | Media (4.3) | 0.20% | — | Wpfactory Slugs ManagerAI | 31/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Slugs Manager.This issue affects Slugs Manager: from n/a through 2.6.7. | |
| Analizada | Media (5.3) | 0.66% | — | Rockwellautomation Factorytalk View | 25/3/2024 | 17/6/2026 | A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. If the vulnerability is exploited, it could lead to the loss of view or control of the PanelView™ product. | |
| Analizada | Media (6.1) | 0.47% | — | Jfrog Artifactory | 13/3/2024 | 17/6/2026 | JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism. | |
| Analizada | Alta (8.8) | 0.88% | — | Jfrog Artifactory | 7/3/2024 | 17/6/2026 | JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts. | |
| Analizada | Alta (7.5) | 0.44% | — | Jfrog Artifactory | 7/3/2024 | 17/6/2026 | JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data. | |
| Analizada | Media (6.5) | 0.47% | — | Jfrog Artifactory | 7/3/2024 | 17/6/2026 | JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration. | |
| Modificada | Media (5.4) | 0.39% | — | Webfactoryltd WP Login Lockdown | 29/2/2024 | 17/6/2026 | The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the generate_export_file function in all versions up to, and including, 2.08. This makes it possible for authenticated attackers, with subscriber access and higher, to export… | |
| Modificada | Media (6.1) | 0.40% | — | Wpfactory Cost OF Goods FOR Woocommerce | 29/2/2024 | 17/6/2026 | The Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'section' parameter in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Modificada | Media (4.7) | 0.27% | — | Webfactoryltd WP Database Reset | 21/2/2024 | 17/6/2026 | The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing or incorrect nonce validation on the install_wpr() function. This makes it possible for unauthenticated attackers to install the WP Reset Plugin via a forged request… | |
| Analizada | Alta (8.8) | 0.99% | — | Rockwellautomation Factorytalk Services Platform | 16/2/2024 | 17/6/2026 | A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive… | |
| Modificada | Media (5.3) | 0.68% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 5/2/2024 | 17/6/2026 | The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenance… | |
| Modificada | Crítica (9.1) | 0.86% | — | Rockwellautomation Factorytalk Services Platform | 31/1/2024 | 17/6/2026 | A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory. If exploited, a malicious user could… | |
| Modificada | Alta (7.2) | 0.58% | — | Webfactoryltd WP Login Lockdown | 29/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebFactory Ltd Login Lockdown – Protect Login Form.This issue affects Login Lockdown – Protect Login Form: from n/a through 2.06. | |
| Modificada | Media (5.4) | 0.33% | — | Wpfactory Back Button Widget | 29/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Back Button Widget allows Stored XSS.This issue affects Back Button Widget: from n/a through 1.6.3. | |
| Modificada | Media (6.5) | 0.66% | — | Wpfrank Slider Factory PRO | 18/12/2023 | 17/6/2026 | The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any authenticated users, such as subscriber to access the content arbitrary post such as private, draft and password protected | |
| Modificada | Media (5.4) | 0.37% | — | Webfactoryltd Guest Author | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebFactory Ltd Guest Author allows Stored XSS.This issue affects Guest Author: from n/a through 2.3. | |
| Modificada | Media (5.4) | 0.38% | — | Dfactory Responsive Lightbox | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dFactory Responsive Lightbox & Gallery allows Stored XSS.This issue affects Responsive Lightbox & Gallery: from n/a through 2.4.5. | |
| Modificada | Media (6.1) | 0.41% | — | Wpfactory Products, Order & Customers Export FOR Woocommerce | 14/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommerce plugin <= 2.0.7 versions. | |
| Modificada | Alta (8.1) | 2.7% | — | Rockwellautomation Factorytalk Services Platform | 27/10/2023 | 17/6/2026 | Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user… | |
| Modificada | Alta (7.5) | 0.90% | — | Rockwellautomation Factorytalk View | 27/10/2023 | 17/6/2026 | Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition. | |
| Modificada | Media (4.3) | 0.39% | — | Wpfactory Custom Css, JS & PHP | 20/10/2023 | 17/6/2026 | The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.7. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save code snippets via a forged request granted they… | |
| Modificada | Crítica (9.1) | 9.6% | — | Rockwellautomation Factorytalk Linx | 13/10/2023 | 17/6/2026 | FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes… | |
| Modificada | Media (6.5) | 0.48% | — | Jfrog Artifactory | 3/10/2023 | 17/6/2026 | JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body. |