Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | Classapps Selectsurvey.net | 28/1/2022 | 17/6/2026 | SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection. | |
| Modificada | Alta (7.5) | 2.0% | — | Classapps Selectsurvey.net | 28/1/2022 | 17/6/2026 | A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve survey user submitted data by modifying the value of the ID parameter in sequential order beginning from 1. | |
| Modificada | Media (5.4) | 0.97% | — | Expresstech Quiz AND Survey Master | 17/1/2022 | 17/6/2026 | Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master. | |
| Modificada | Media (6.1) | 1.3% | — | Expresstech Quiz AND Survey Master | 17/1/2022 | 17/6/2026 | Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.65% | — | Expresstech Quiz AND Survey Master | 17/1/2022 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page. | |
| Modificada | Media (6.1) | 0.84% | — | Limesurvey | 14/12/2021 | 9/7/2026 | Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/templatesavechanges URI. | |
| Modificada | Media (4.8) | 0.62% | — | Reputeinfosystems Contact Form, Survey & Popup Form Plugin FOR Wordpress - Arforms Form Builder | 6/12/2021 | 17/6/2026 | The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.3) | 0.45% | — | WP Survey Plus Project WP Survey Plus | 8/11/2021 | 17/6/2026 | The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to Stored Cross-Site Scripting issues | |
| Modificada | Media (4.8) | 0.62% | — | Expresstech Quiz AND Survey Master | 11/10/2021 | 17/6/2026 | The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (6.1) | 1.5% | — | Limesurvey | 8/10/2021 | 17/6/2026 | The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js. | |
| Modificada | Media (5.3) | 0.88% | — | Mysurvey Survey Solutions | 4/10/2021 | 17/6/2026 | Survey Solutions is a survey management and data collection system. In affected versions the Headquarters application publishes /metrics endpoint available to any user. None of the survey answers are ever exposed, only the aggregate counters, including count of interviews, or count of assignments. Starting from… | |
| Modificada | Media (6.1) | 3.4% | 💥 Exploit | Expresstech Quiz AND Survey Master | 18/8/2021 | 17/6/2026 | Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.4% | — | Ays-pro Survey Maker | 2/8/2021 | 17/6/2026 | The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard | |
| Modificada | Crítica (9.8) | 46% | 💥 Exploit | Wpdevart Poll, Survey, Questionnaire AND Voting System | 12/7/2021 | 17/6/2026 | The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks | |
| Modificada | Media (6.1) | 0.69% | — | Limesurvey | 28/6/2021 | 17/6/2026 | Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in application/controllers/admin/PermissiontemplatesController.php. | |
| Modificada | Media (5.4) | 0.55% | — | Limesurvey | 28/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature. | |
| Modificada | Media (6.1) | 0.83% | — | Expresstech Quiz AND Survey Master | 20/6/2021 | 17/6/2026 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to… | |
| Analizada | Crítica (9.8) | 30% | ⚠ Explotación activa | Checkbox Survey | 27/5/2021 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7. | |
| Modificada | Alta (8.8) | 1.9% | — | Expresstech Quiz AND Survey Master | 12/4/2021 | 17/6/2026 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection. The lowest role allowed to use this… | |
| Modificada | Crítica (9.8) | 1.3% | — | Limesurvey | 14/2/2021 | 17/6/2026 | LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model. | |
| Modificada | Media (4.8) | 0.66% | — | Otrs Survey | 8/2/2021 | 17/6/2026 | Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. another agent who wants to make changes in the survey). This issue affects: OTRS AG Survey 6.0.x version 6.0.20 and prior versions; 7.0.x version 7.0.19 and prior versions. | |
| Modificada | Media (5.4) | 0.69% | — | Oracle Application Express Survey Builder | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Application Express Survey Builder component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application… | |
| Modificada | Crítica (9.9) | 76% | 💥 Exploit | Expresstech Quiz AND Survey Master | 1/1/2021 | 17/6/2026 | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via… | |
| Modificada | Crítica (9.8) | 5.1% | — | Expresstech Quiz AND Survey Master | 1/1/2021 | 17/6/2026 | An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload,… | |
| Modificada | Media (5.4) | 0.70% | — | Limesurvey | 31/12/2020 | 17/6/2026 | LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser. |