Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.65% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |
| Analizada | Media (5.4) | 0.59% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited… | |
| Analizada | Alta (7.7) | 0.80% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Analizada | Alta (7.7) | 0.80% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Analizada | Media (5.4) | 0.59% | — | Synology Surveillance Station | 28/3/2024 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited… | |
| Modificada | Media (5.4) | 0.39% | — | Ays-pro Survey Maker | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Reflected XSS.This issue affects Survey Maker: from n/a through 4.0.6. | |
| Aplazada | Crítica (9.3) | 2.0% | 💥 Exploit | Expresstechlabs Quiz AND Survey MasterAI | 26/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4. | |
| Analizada | Media (6.1) | 0.51% | — | Devsoftbaltic Survey-creator | 21/3/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute arbitrary code and obtain sensitive information via the title parameter in form. | |
| Modificada | Media (4.8) | 0.34% | — | Ays-pro Survey Maker | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS.This issue affects Survey Maker: from n/a through 4.0.5. | |
| Aplazada | Media (5.4) | 0.20% | — | Expresstechsoftware Quiz AND Survey MasterAI | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.18. | |
| Analizada | Alta (7.5) | 0.58% | — | Ecomiz Survey TMA | 23/2/2024 | 17/6/2026 | In the module "Survey TMA" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without restriction. | |
| Modificada | Alta (8.8) | 0.97% | — | Four-faith Video Surveillance Management System | 27/11/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Xiamen Four-Faith Video Surveillance Management System 2016/2017. Affected by this issue is some unknown functionality of the component Apache Struts. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has… | |
| Modificada | Media (5.4) | 0.39% | — | Quizandsurveymaster Quiz AND Survey Master | 23/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master plugin <= 8.1.13 versions. | |
| Modificada | Media (5.4) | 0.68% | — | Limesurvey | 18/11/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component. | |
| Modificada | Media (4.1) | 1.1% | — | Microsoft Send Customer Voice Survey From Dynamics 365 | 14/11/2023 | 17/6/2026 | Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability | |
| Modificada | Alta (8.8) | 0.31% | — | Expresstech Quiz AND Survey Master | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions. | |
| Modificada | Crítica (9.8) | 1.3% | — | Diaowen Dwsurvey | 1/9/2023 | 17/6/2026 | File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file. | |
| Modificada | Media (5.4) | 0.55% | — | Expresstech Quiz AND Survey Master | 7/8/2023 | 17/6/2026 | The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (7.5) | 0.86% | 💥 PoC | Ngsurvey | 2/8/2023 | 17/6/2026 | Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys. | |
| Modificada | Alta (7.5) | 1.2% | 💥 PoC | Ngsurvey | 2/8/2023 | 17/6/2026 | Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey contains a "Text Field", "Comment Field" or "Contact Details". | |
| Modificada | Media (5.4) | 0.38% | — | Otrs Survey | 24/7/2023 | 17/6/2026 | An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module… | |
| Modificada | Crítica (9.8) | 0.95% | — | Four-faith Video Surveillance Management System | 21/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Xiamen Four Letter Video Surveillance Management System up to 20230712. This issue affects some unknown processing in the library UserInfoAction.class of the component Login. The manipulation leads to improper authorization. The attack may be… | |
| Modificada | Media (6.1) | 0.56% | — | Diaowen Dwsurvey | 20/6/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.action file. | |
| Modificada | Alta (7.8) | 0.23% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 14/6/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.20% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 14/6/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. |