Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.52% | — | Wpfront User Role Editor | 2/4/2024 | 17/6/2026 | The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.1.11184 via the wpfront_user_role_editor_assign_roles_user_autocomplete AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Media (6.5) | 0.36% | — | Buffercode Frontend DashboardAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vinoth06. Frontend Dashboard allows Stored XSS.This issue affects Frontend Dashboard: from n/a through 2.2.1. | |
| Aplazada | Media (5.9) | 0.34% | — | Wpfront Notification BARAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront Notification Bar allows Stored XSS.This issue affects WPFront Notification Bar: from n/a through 3.3.2. | |
| Modificada | Media (6.1) | 0.38% | — | Etoilewebdesign Front END Users | 26/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Front End Users allows Reflected XSS.This issue affects Front End Users: from n/a before 3.2.25. | |
| Analizada | Media (6.5) | 0.57% | — | Saleor React-storefront | 20/3/2024 | 17/6/2026 | Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymous users are able to access their data. The session is leaked through cache and can be accessed by anyone. Users should upgrade to a version… | |
| Modificada | Alta (7.5) | 0.45% | — | Najeebmedia Frontend File Manager | 17/3/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in N-Media Frontend File Manager.This issue affects Frontend File Manager: from n/a through 22.7. | |
| Analizada | Media (6.5) | 0.30% | — | SAP Fiori Front END Server | 12/3/2024 | 17/6/2026 | SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This could lead to creation of request with incorrect approver causing low impact on Confidentiality and Integrity with no impact on Availability of the application. | |
| Modificada | Alta (8.8) | 1.1% | — | Vegacorp Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data shortcode in all versions up to, and including, 1.2.1 due to insufficient input validation and restriction on access to that shortcode. This makes it possible… | |
| Modificada | Media (4.3) | 0.47% | — | Josevega Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.1 via the vg_display_data shortcode due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.41% | — | Vegacorp Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and postmeta in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Modificada | Alta (8.8) | 0.24% | — | Elisebosse Frontpage Manager | 31/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Elise Bosse Frontpage Manager.This issue affects Frontpage Manager: from n/a through 1.3. | |
| Modificada | Media (4.8) | 0.40% | — | Wpfront Notification BAR | 25/1/2024 | 17/6/2026 | The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notification-bar-options[custom_class]’ parameter in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Modificada | Alta (7.5) | 0.39% | — | Uniswapfrontrunbot Project Uniswapfrontrunbot | 19/1/2024 | 17/6/2026 | A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.00% | — | Millionclues Admin CSS MUDeano AMP ToolboxUnihost Confirm DataAgence-press CSS Adder+11 | 19/1/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long… | |
| Modificada | Media (6.1) | 75% | 💥 Exploit | Cloud Citrix Storefront | 17/1/2024 | 17/6/2026 | Cross-site scripting (XSS) | |
| Modificada | Crítica (9.8) | 0.62% | — | Dynamiapps Frontend Admin | 29/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Shabti Kaplan Frontend Admin by DynamiApps.This issue affects Frontend Admin by DynamiApps: from n/a through 3.18.3. | |
| Modificada | Alta (8.8) | 0.85% | — | Zabbix ServerZabbix Frontend | 18/12/2023 | 17/6/2026 | The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user. | |
| Modificada | Media (6.5) | 1.0% | — | Najeebmedia Frontend File Manager Plugin | 4/12/2023 | 17/6/2026 | The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php` | |
| Modificada | Alta (8.8) | 0.25% | — | Wpfrontier Frontier Post | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in finnj Frontier Post allows Cross Site Request Forgery.This issue affects Frontier Post: from n/a through 6.1. | |
| Modificada | Media (6.5) | 0.41% | — | Shamimsplugins Front END PM | 6/11/2023 | 17/6/2026 | The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled. | |
| Modificada | Alta (7.5) | 0.89% | — | Parity Frontier | 13/10/2023 | 17/6/2026 | Frontier is Substrate's Ethereum compatibility layer. Prior to commit aea528198b3b226e0d20cce878551fd4c0e3d5d0, at the end of a contract execution, when opcode SUICIDE marks a contract to be deleted, the software uses `storage::remove_prefix` (now renamed to `storage::clear_prefix`) to remove all storages associated… | |
| Modificada | Alta (8.8) | 0.27% | — | Checkfront Online Booking System | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Checkfront Inc. Checkfront Online Booking System plugin <= 3.6 versions. | |
| Modificada | Media (4.8) | 0.44% | — | Aleksanaharonyan Front Editor | 30/8/2023 | 17/6/2026 | The Front Editor WordPress plugin through 4.0.4 does not sanitize and escape some of its form settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.38% | — | Wpazure Upfrontwp | 10/8/2023 | 17/6/2026 | Auth. (subscriber+) Reflected Cross-site Scripting (XSS) vulnerability in Wpazure Themes Upfrontwp theme <= 1.1 versions. | |
| Modificada | Media (6.1) | 0.40% | — | Zabbix Frontend | 3/8/2023 | 17/6/2026 | A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.225.0. |