Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2546▼ 402 respecto a la semana anterior
Críticas / altas1312▲ 29 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 26% | — | Mitre CalderaAI | 24/2/2025 | 17/6/2026 | In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server that Caldera is running on via a crafted web request to the Caldera… | |
| Aplazada | Media (4.3) | 0.36% | — | Davidcramer Caldera Smtp MailerAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in David Cramer Caldera SMTP Mailer caldera-smtp-mailer.This issue affects Caldera SMTP Mailer: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.23% | — | Wpwebsitecreator WP Website CreatorAIWpformsAIFormidableAINinjaAI+2 | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpwebsitecreator Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera wp-website-creator allows Stored XSS.This issue affects Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera:… | |
| Modificada | Alta (8.8) | 0.39% | — | Gsheetconnector Caldera Forms Google Sheets Connector | 17/7/2023 | 17/6/2026 | The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Modificada | Media (6.1) | 0.46% | — | Mitre Caldera | 17/10/2022 | 17/6/2026 | MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40605. | |
| Modificada | Media (5.4) | 0.57% | — | Mitre Caldera | 17/10/2022 | 17/6/2026 | MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on agents. | |
| Modificada | Media (6.1) | 0.46% | — | Mitre Caldera | 17/10/2022 | 17/6/2026 | MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40606. | |
| Modificada | Media (6.1) | 1.2% | — | Calderaforms Caldera Forms | 18/4/2022 | 17/6/2026 | The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.51% | — | Claderaform Calderawp License Manager | 12/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability leading to Reflected Cross-Site Scripting (XSS) in CalderaWP License Manager (WordPress plugin) <= 1.2.11. | |
| Modificada | Alta (8.8) | 2.0% | — | Mitre Caldera | 12/1/2022 | 17/6/2026 | An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted. | |
| Modificada | Media (6.1) | 1.1% | — | Mitre Caldera | 12/1/2022 | 17/6/2026 | An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated and unauthenticated attackers. | |
| Modificada | Alta (8.1) | 1.2% | — | Mitre Caldera | 12/1/2022 | 17/6/2026 | An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other components that should only be accessible by admin users. | |
| Modificada | Alta (8.8) | 20% | — | Mitre Caldera | 12/1/2022 | 17/6/2026 | An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in order to escape the current command and execute arbitrary shell… | |
| Modificada | Alta (8.8) | 2.1% | — | Mitre Caldera | 12/1/2022 | 17/6/2026 | An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attacks (e.g., File Exfiltration, Server Side Request Forgery, Out of Band Exfiltration, etc.). | |
| Modificada | Media (4.8) | 0.60% | — | Calderaforms Caldera Forms | 13/12/2021 | 17/6/2026 | The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8.8) | 3.0% | — | Mitre Caldera | 12/7/2021 | 17/6/2026 | A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service. | |
| Modificada | Media (5.4) | 0.63% | — | Mitre Caldera | 19/6/2020 | 17/6/2026 | CALDERA 2.7.0 allows XSS via the Operation Name box. | |
| Modificada | Media (5.3) | 1.4% | — | Mitre Caldera | 22/3/2020 | 17/6/2026 | auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header. | |
| Modificada | Media (4.8) | 4.4% | — | Calderalabs Caldera Forms | 20/4/2018 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a greeting message, (2) the email transaction log, or (3) an imported form. | |
| Modificada | Alta (7.5) | 1.6% | — | Caldera | 8/5/2014 | 17/6/2026 | The directory manager in Caldera 9.20 allows remote attackers to conduct variable-injection attacks in the global scope via (1) the maindir_hotfolder parameter to dirmng/index.php, or an unspecified parameter to (2) PPD/index.php, (3) dirmng/docmd.php, or (4) dirmng/param.php. | |
| Modificada | Alta (10) | 4.4% | — | Caldera | 8/5/2014 | 17/6/2026 | costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute arbitrary commands via shell metacharacters in a methodCall element in a PHP XMLRPC request. | |
| Modificada | Alta (7.5) | 1.5% | — | Caldera | 8/5/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the tr parameter to (1) costview2/jobs.php or (2) costview2/printers.php. | |
| Modificada | Media (5) | 3.0% | — | Caldera | 8/5/2014 | 17/6/2026 | Directory traversal vulnerability in dirmng/index.php in Caldera 9.20 allows remote attackers to access arbitrary directories via a crafted pathname. | |
| Modificada | Alta (7.5) | 1.3% | — | Umberto Caldera Easymoblog | 6/2/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php. | |
| Modificada | Media (5) | 2.1% | — | Caldera Openlinux ServerCaldera Openlinux WorkstationCaldera OpenserverSCO Unixware | 20/10/2003 | 16/6/2026 | Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules. |