Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
431 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.84% | — | Meowapps Media Usage | 16/8/2021 | 17/6/2026 | The Media Usage WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/mmu_admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.4. | |
| Modificada | Media (6.1) | 0.41% | — | Light Messages Project Light Messages | 16/8/2021 | 17/6/2026 | The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them (even with the unfiltered_html disallowed). As a result, an attacker could make a logged in admin update the settings to arbitrary values, and set a Cross-Site Scripting… | |
| Modificada | Alta (8.8) | 1.6% | — | Coderstimes OUT OF Stock Message FOR Woocommerce | 9/8/2021 | 17/6/2026 | The Stock in & out WordPress plugin through 1.0.4 lacks proper sanitization before passing variables to an SQL request, making it vulnerable to SQL Injection attacks. Users with a role of contributor or higher can exploit this vulnerability. | |
| Modificada | Media (5.4) | 0.60% | — | Sage Syracuse | 22/7/2021 | 17/6/2026 | Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web application component. Updates are available for on-premises versions of Version 12 (components shipped with Syracuse 12.10.0 and later) of… | |
| Modificada | Alta (7.2) | 2.1% | — | Sage Syracuse | 22/7/2021 | 17/6/2026 | Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production. | |
| Modificada | Crítica (9.8) | 69% | 💥 Exploit | Sage Adxadmin | 22/7/2021 | 17/6/2026 | Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential validation. While exploiting this does require knowledge of the installation path, that information can be learned by exploiting CVE-2020-7387.… | |
| Modificada | Media (5.3) | 34% | 💥 Exploit | Sage Adxadmin | 22/7/2021 | 17/6/2026 | Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe component that reveals the installation directory of the product. Note that this vulnerability can be combined with CVE-2020-7388 to achieve full RCE. This issue was fixed in AdxAdmin 93.2.53, which ships… | |
| Modificada | Media (6.5) | 0.61% | — | KDE Messagelib | 2/6/2021 | 17/6/2026 | KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. With a crafted message, a user could be… | |
| Modificada | Alta (7.3) | 1.2% | — | Roar-pidusage Project Roar-pidusage | 18/4/2021 | 17/6/2026 | This affects all versions of package roar-pidusage. If attacker-controlled user input is given to the stat function of this package on certain operating systems, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. | |
| Modificada | Media (4.9) | 1.9% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Delete video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files. | |
| Modificada | Media (4.9) | 1.9% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files. | |
| Modificada | Media (4.9) | 1.9% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files. | |
| Modificada | Media (4.9) | 1.9% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path traversal to access system files. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The Service configuration-2 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The Service configuration-1 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The Firmware protocol configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.2% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Generate SSL certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Remote image configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Remote video storage function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Media (4.9) | 1.8% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The Firmware update function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. |