Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

481 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.65%—Synology Surveillance Station28/3/202417/6/2026
Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.
AnalizadaMedia (5.4)0.59%—Synology Surveillance Station28/3/202417/6/2026
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited…
AnalizadaAlta (7.7)0.80%—Synology Surveillance Station28/3/202417/6/2026
Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors.
AnalizadaAlta (7.7)0.80%—Synology Surveillance Station28/3/202417/6/2026
Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors.
AnalizadaMedia (5.4)0.59%—Synology Surveillance Station28/3/202417/6/2026
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited…
ModificadaMedia (5.4)0.39%—Ays-pro Survey Maker27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Reflected XSS.This issue affects Survey Maker: from n/a through 4.0.6.
AplazadaCrítica (9.3)2.0%💥 ExploitExpresstechlabs Quiz AND Survey MasterAI26/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.
AnalizadaMedia (6.1)0.51%—Devsoftbaltic Survey-creator21/3/202417/6/2026
Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute arbitrary code and obtain sensitive information via the title parameter in form.
ModificadaMedia (4.8)0.34%—Ays-pro Survey Maker19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS.This issue affects Survey Maker: from n/a through 4.0.5.
AplazadaMedia (5.4)0.20%—Expresstechsoftware Quiz AND Survey MasterAI16/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.18.
AnalizadaAlta (7.5)0.58%—Ecomiz Survey TMA23/2/202417/6/2026
In the module "Survey TMA" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without restriction.
ModificadaAlta (8.8)0.97%—Four-faith Video Surveillance Management System27/11/202317/6/2026
A vulnerability, which was classified as critical, has been found in Xiamen Four-Faith Video Surveillance Management System 2016/2017. Affected by this issue is some unknown functionality of the component Apache Struts. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has…
ModificadaMedia (5.4)0.39%—Quizandsurveymaster Quiz AND Survey Master23/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master plugin <= 8.1.13 versions.
ModificadaMedia (5.4)0.68%—Limesurvey18/11/202317/6/2026
Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component.
ModificadaMedia (4.1)1.1%—Microsoft Send Customer Voice Survey From Dynamics 36514/11/202317/6/2026
Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability
ModificadaAlta (8.8)0.31%—Expresstech Quiz AND Survey Master13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions.
ModificadaCrítica (9.8)1.3%—Diaowen Dwsurvey1/9/202317/6/2026
File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.
ModificadaMedia (5.4)0.55%—Expresstech Quiz AND Survey Master7/8/202317/6/2026
The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (7.5)0.86%💥 PoCNgsurvey2/8/202317/6/2026
Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys.
ModificadaAlta (7.5)1.2%💥 PoCNgsurvey2/8/202317/6/2026
Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey contains a "Text Field", "Comment Field" or "Contact Details".
ModificadaMedia (5.4)0.38%—Otrs Survey24/7/202317/6/2026
An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module…
ModificadaCrítica (9.8)0.95%—Four-faith Video Surveillance Management System21/7/202317/6/2026
A vulnerability, which was classified as critical, has been found in Xiamen Four Letter Video Surveillance Management System up to 20230712. This issue affects some unknown processing in the library UserInfoAction.class of the component Login. The manipulation leads to improper authorization. The attack may be…
ModificadaMedia (6.1)0.56%—Diaowen Dwsurvey20/6/202317/6/2026
Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.action file.
ModificadaAlta (7.8)0.23%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+32314/6/202317/6/2026
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
ModificadaAlta (7.8)0.20%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+32314/6/202317/6/2026
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
Orbitaley — Vulnerabilidades