Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.41% | — | Projectworlds Online Examination System | 1/11/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | |
| Modificada | Media (6.1) | 0.39% | — | Projectworlds Online Examination System | 1/11/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | |
| Modificada | Media (6.5) | 0.34% | — | Terminalfour | 16/10/2023 | 17/6/2026 | In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Crítica (9.8) | 14% | 💥 Exploit | Incsub Forminator | 30/8/2023 | 17/6/2026 | The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to upload arbitrary files on… | |
| Modificada | Media (5.4) | 0.28% | — | Minapper Rest API TO Miniprogram | 16/8/2023 | 17/6/2026 | The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments | |
| Modificada | Media (6.1) | 4.1% | — | Incsub Forminator | 31/7/2023 | 17/6/2026 | The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form fields that use pre-populated query parameters, which could lead to reflected XSS attacks. | |
| Modificada | Media (4.3) | 0.43% | — | Incsub Forminator | 12/7/2023 | 17/6/2026 | The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.13.4. This is due to missing or incorrect nonce validation on the listen_for_saving_export_schedule() function. This makes it possible for… | |
| Modificada | Media (6.5) | 0.38% | — | Online Examination System Project Online Examination System | 7/7/2023 | 17/6/2026 | The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link that, when clicked by an admin user, will delete a user account from the database without the admin's consent. The email of the user to be deleted is passed as a… | |
| Modificada | Baja (3.1) | 0.36% | — | Incsub Forminator | 4/7/2023 | 17/6/2026 | The Forminator WordPress plugin before 1.24.1 does not use an atomic operation to check whether a user has already voted, and then update that information. This leads to a Race Condition that may allow a single user to vote multiple times on a poll. | |
| Modificada | Alta (7.8) | 0.60% | — | Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue | 14/6/2023 | 17/6/2026 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI. | |
| Modificada | Crítica (9.8) | 0.62% | — | Adampos Mobilmen EL Terminali Yazilimi | 23/5/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal Software: before 3. | |
| Modificada | Alta (7.5) | 1.8% | — | Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+7 | 28/4/2023 | 17/6/2026 | Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications. | |
| Modificada | Crítica (9.8) | 0.92% | — | Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+7 | 28/4/2023 | 17/6/2026 | Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data… | |
| Modificada | Media (6.5) | 0.97% | — | Getlaminas Laminas-diactorosGuzzlephp Psr-7Fedoraproject Fedora | 24/4/2023 | 17/6/2026 | Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0, users who create HTTP requests or responses using laminas/laminas-diactoros, when providing a newline at the start or end of a header key or value, can cause an invalid… | |
| Modificada | Crítica (9.8) | 0.72% | — | Eskom EL Terminali (SU Okuma) Uygulamalarimiz | 14/4/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection. This issue affects Water Metering Software: before 23.04.06. | |
| Modificada | Media (4.9) | 0.56% | — | Terminalfour | 12/4/2023 | 17/6/2026 | The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1. | |
| Modificada | Media (6.1) | 0.41% | — | Incsub Forminator | 16/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.14.11. | |
| Modificada | Media (6.3) | 0.31% | — | Eternal Terminal Project Eternal Terminal | 16/2/2023 | 17/6/2026 | In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file. | |
| Modificada | Media (5.3) | 1.1% | — | Eternal Terminal Project Eternal Terminal | 13/1/2023 | 17/6/2026 | In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles. | |
| Modificada | Media (5.3) | 0.88% | — | Eternal Terminal Project Eternal Terminal | 13/1/2023 | 17/6/2026 | In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp. | |
| Modificada | Crítica (9.8) | 0.65% | — | Criminals Project Criminals | 11/1/2023 | 17/6/2026 | A vulnerability was found in NoxxieNl Criminals. It has been classified as critical. Affected is an unknown function of the file ingame/roulette.php. The manipulation of the argument gambleMoney leads to sql injection. The patch is identified as 0a60b31271d4cbf8babe4be993d2a3a1617f0897. It is recommended to apply a… | |
| Modificada | Crítica (9.8) | 14% | — | Gullseye Terminal Operating System | 10/1/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allows SQL Injection. This issue affects GullsEye terminal operating system: from unspecified before 5.0.13. | |
| Modificada | Alta (7.5) | 0.95% | — | Terminal-kit Project Terminal-kit | 7/1/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in cronvel terminal-kit up to 2.1.7. Affected is an unknown function. The manipulation leads to inefficient regular expression complexity. Upgrading to version 2.1.8 is able to address this issue. The name of the patch is… | |
| Modificada | Alta (7.8) | 0.16% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/12/2022 | 17/6/2026 | Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards. |