Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 28 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.59% | — | A-forms Project A-forms | 10/3/2023 | 16/6/2026 | A vulnerability, which was classified as problematic, was found in MMDeveloper A Forms Plugin up to 1.4.2 on WordPress. This affects an unknown part of the file a-forms.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.4.3 is able to address… | |
| Modificada | Media (6.1) | 0.95% | — | Ark-web A-form | 12/9/2022 | 17/6/2026 | Cross-site scripting vulnerability in Movable Type plugin A-Form versions prior to 4.1.1 (for Movable Type 7 Series) and versions prior to 3.9.1 (for Movable Type 6 Series) allows a remote unauthenticated attacker to inject an arbitrary script. | |
| Modificada | Media (4.3) | 1.0% | — | Ark-web A-form PCArk-web A-form PC Mobile | 3/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the A-Form PC and PC/Mobile before 3.1 plug-ins for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-2676. | |
| Modificada | Media (5.5) | 1.3% | — | Ark-web A-formArk-web A-form BambooArk-web A-form PCArk-web A-form PC Mobile | 3/11/2011 | 16/6/2026 | The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not require administrative authentication, which allows remote authenticated users to modify data via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | Phil-a-form | 31/5/2007 | 16/6/2026 | SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the form_id parameter. |