Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

247 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.56%—Apollo13themes Rife Elementor Extensions & Templates5/5/202117/6/2026
The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method.
ModificadaMedia (5.4)0.59%—Brainstormforce Elementor - Header, Footer & Blocks Template5/5/202117/6/2026
The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
ModificadaAlta (8.8)1.6%—Cyberchimps Gutenberg & Elementor Templates Importer FOR Responsive23/4/202017/6/2026
The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests.
ModificadaAlta (7)0.26%—Redhat Template Service Broker Operator19/3/202017/6/2026
A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the openshift/template-service-broker-operator. An attacker with access to the container could use this flaw to modify…
ModificadaCrítica (9.8)1.3%—Pebbletemplates Pebble Templates19/12/201917/6/2026
Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lang.String) signature.
ModificadaAlta (7.5)3.1%—Almera Responsive Portfolio Site Template Project Almera Responsive Portfolio Site Template11/10/201917/6/2026
The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
ModificadaAlta (7.5)3.1%—Accio Responsive Onepage Parallax Site Template Project Accio Responsive Onepage Parallax Site Template11/10/201917/6/2026
The ThemeMakers Accio Responsive Parallax One Page Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
ModificadaAlta (7.5)3.1%—Invento / Architecture Building Agency Template Project Invento / Architecture Building Agency Template11/10/201917/6/2026
The ThemeMakers Invento Responsive Gallery/Architecture Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
ModificadaMedia (4.3)7.3%💥 ExploitAlkacon Opencms Apollo Template27/8/201917/6/2026
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp.
ModificadaMedia (6.1)2.9%💥 ExploitAlkacon Opencms Apollo Template27/8/201917/6/2026
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
ModificadaMedia (6.1)2.9%💥 ExploitAlkacon Opencms Apollo Template27/8/201917/6/2026
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
ModificadaAlta (8.1)0.79%—Jenkins Email Extension Template9/1/201917/6/2026
A cross-site request forgery vulnerability exists in Jenkins Email Extension Template Plugin 1.0 and earlier in ExtEmailTemplateManagement.java that allows creating or removing templates.
ModificadaMedia (5.4)1.6%💥 ExploitPHP Template Store Script Project PHP Template Store Script6/8/201817/6/2026
PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field in a profile.
ModificadaAlta (8.8)0.89%—Redhat OpenstackOpenstack Tripleo Heat Templates30/7/201817/6/2026
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.
ModificadaMedia (6.1)0.83%—Bracket-template Project Bracket-template7/6/201817/6/2026
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
ModificadaMedia (6.1)0.71%—IBM Social Rendering Templates FOR Digital Data Connector1/2/201717/6/2026
IBM Social Rendering Templates for Digital Data Connector is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaAlta (7.5)2.4%—Redhat OpenstackOpenstack Tripleo Heat Templates15/4/201617/6/2026
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private…
ModificadaAlta (7.5)1.7%—Openstack Tripleo Heat Templates11/4/201617/6/2026
The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.
ModificadaMedia (4.3)0.96%—IBM Content Template Catalog3/10/201517/6/2026
Cross-site scripting (XSS) vulnerability in IBM Content Template Catalog 4.x before 4.1.4 for WebSphere Portal 8.0.x and 4.x before 4.3.1 for WebSphere Portal 8.5.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
ModificadaMedia (6.8)0.57%—Node Template Project Node Template15/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Node Template module for Drupal allows remote attackers to hijack the authentication of users with the "access node template" permission for requests that delete node templates via unspecified vectors.
ModificadaMedia (6.8)1.3%💥 ExploitTemplate CMS Project Template CMS20/5/201516/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Template CMS 2.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator user via an add action to admin/index.php or (2) conduct static PHP code injection attacks via the…
ModificadaMedia (4.3)2.0%💥 ExploitTemplate CMS Project Template CMS20/5/201516/6/2026
Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the themes_editor parameter in an add_template action to admin/index.php.
ModificadaMedia (4.3)1.6%—Igor Vlasenko Html-template-pro6/1/201216/6/2026
Cross-site scripting (XSS) vulnerability in the HTML-Template-Pro module before 0.9507 for Perl allows remote attackers to inject arbitrary web script or HTML via template parameters, related to improper handling of > (greater than) and < (less than) characters.
ModificadaMedia (4.3)1.8%—Makotemplates Mako2/7/201016/6/2026
Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.
ModificadaAlta (7.5)0.91%💥 Exploit2daybiz WEB Template Software28/6/201016/6/2026
SQL injection vulnerability in customize.php in 2daybiz Web Template Software allows remote attackers to execute arbitrary SQL commands via the tid parameter.
Orbitaley — Vulnerabilidades