Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
380 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.28% | — | Nxfilter | 23/7/2023 | 17/6/2026 | A vulnerability has been found in NxFilter 4.3.2.5 and classified as problematic. This vulnerability affects unknown code of the file user.jsp. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The identifier of this vulnerability is VDB-235192. NOTE: The vendor was contacted… | |
| Modificada | Media (6.1) | 0.36% | — | Nxfilter | 23/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in NxFilter 4.3.2.5. This affects an unknown part of the file /report,daily.jsp?stime=2023%2F07%2F12&timeOption=yesterday&. The manipulation of the argument user leads to cross site scripting. It is possible to initiate the attack remotely. The associated… | |
| Modificada | Media (5.5) | 0.33% | — | Leap Blue Light Filter | 9/6/2023 | 17/6/2026 | An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files. | |
| Modificada | Alta (7.8) | 0.40% | — | Leap Blue Light Filter | 9/6/2023 | 17/6/2026 | An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files. | |
| Modificada | Alta (8.8) | 1.3% | — | Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+12 | 7/6/2023 | 17/6/2026 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or… | |
| Modificada | Alta (8.8) | 3.7% | — | Linuxfoundation Cups-filtersFedoraproject FedoraDebian Linux | 17/5/2023 | 17/6/2026 | cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote code execution. `beh.c` contains the line… | |
| Modificada | Media (4.8) | 0.37% | — | WP Content Filter - Censor ALL Offensive Content From Your Site Project WP Content Filter - Censor ALL Offensive Content From Your Site | 9/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David Gwyer WP Content Filter plugin <= 3.0.1 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Ultimate WP Query Search Filter Project Ultimate WP Query Search Filter | 23/4/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in TC Ultimate WP Query Search Filter plugin <= 1.0.10 versions. | |
| Modificada | Media (6.1) | 0.56% | — | I13websolution Responsive Filterable Portfolio | 18/4/2023 | 17/6/2026 | The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (5.4) | 0.44% | — | Pluginus Wordpress Meta Data AND Taxonomies Filter | 22/3/2023 | 17/6/2026 | The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripting vulnerability in the 'tax_name' parameter of the mdf_get_tax_options_in_widget action, which can only be triggered by an authenticated user. | |
| Modificada | Media (5.4) | 0.46% | — | Gsplugins GS Filterable Portfolio | 21/2/2023 | 17/6/2026 | The GS Filterable Portfolio WordPress plugin before 1.6.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (7.2) | 1.3% | — | Pluginus Husky - Products Filter Professional FOR Woocommerce | 6/2/2023 | 17/6/2026 | The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present. | |
| Modificada | Media (5.4) | 0.47% | — | Codeamp Search & Filter | 23/1/2023 | 17/6/2026 | The Search & Filter WordPress plugin before 1.2.16 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (5.3) | 0.71% | — | DAJ M-filter | 17/1/2023 | 17/6/2026 | m-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series) allows a remote unauthenticated attacker to bypass authentication and send users' unintended email when email is being sent under the certain conditions. The attacks exploiting this vulnerability have been observed. | |
| Modificada | Media (4.8) | 0.47% | — | Wordpress Filter Gallery Project Wordpress Filter Gallery | 2/1/2023 | 17/6/2026 | The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg_gallery_filters ajax action before outputting them on the page, allowing a high privileged user such as an administrator to inject HTML or javascript to the plugin settings page, even when the… | |
| Modificada | Media (5.5) | 0.33% | — | Callback Cbfs Filter | 28/11/2022 | 17/6/2026 | A null pointer dereference vulnerability exists in the handle_ioctl_0x830a0_systembuffer functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. | |
| Modificada | Media (5.5) | 0.33% | — | Callback Cbfs Filter | 28/11/2022 | 17/6/2026 | A null pointer dereference vulnerability exists in the handle_ioctl_8314C functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. | |
| Modificada | Media (5.5) | 0.33% | — | Callback Cbfs Filter | 28/11/2022 | 17/6/2026 | A null pointer dereference vulnerability exists in the handle_ioctl_83150 functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. | |
| Modificada | Media (6.1) | 0.60% | — | Brinidesigner Awesome Filterable Portfolio | 23/9/2022 | 17/6/2026 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress. | |
| Modificada | Media (4.8) | 0.68% | — | ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters | 23/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability Add Shortcodes Actions And Filters plugin <= 2.0.9 at WordPress. | |
| Modificada | Media (5.3) | 0.70% | — | Brinidesigner Awesome Filterable Portfolio | 23/9/2022 | 17/6/2026 | Unauthenticated Plugin Settings Change vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress. | |
| Modificada | Crítica (9.8) | 1.6% | — | SO Filter Shop BY Project SO Filter Shop BY | 5/7/2022 | 17/6/2026 | So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_filter_shop_by/filter_data. | |
| Modificada | Media (6.1) | 0.85% | — | Themify Woocommerce Product Filter | 13/6/2022 | 17/6/2026 | Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Baja (3.7) | 0.98% | — | DAJ I-filter Browser & Cloud MultiagentDAJ I-filter | 10/3/2022 | 17/6/2026 | Improper check for certificate revocation in i-FILTER Ver.10.45R01 and earlier, i-FILTER Ver.9.50R10 and earlier, i-FILTER Browser & Cloud MultiAgent for Windows Ver.4.93R04 and earlier, and D-SPA (Ver.3 / Ver.4) using i-FILTER allows a remote unauthenticated attacker to conduct a man-in-the-middle attack and… | |
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Pluginus Woocommerce Products Filter | 1/2/2022 | 17/6/2026 | The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting |