Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.44% | — | Charlestsmith Word Replacer PRO | 16/3/2024 | 17/6/2026 | The Word Replacer Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the word_replacer_ultra() function in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to update arbitrary content on the affected WordPress… | |
| Modificada | Alta (8.6) | 2.0% | — | Charlesproxy Charles | 13/11/2018 | 17/6/2026 | An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file from an attacker, an intranet network may be accessed and information may be leaked. | |
| Modificada | Alta (7) | 0.76% | — | Charlesproxy Charles | 3/8/2018 | 17/6/2026 | Race condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privileges via vectors involving the --self-repair option. | |
| Modificada | Media (6.8) | 5.4% | — | Jean Charles JBC Explorer | 10/11/2007 | 16/6/2026 | Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows remote authenticated administrators to inject arbitrary PHP code via the DEBUG parameter, which can be executed by accessing config.inc.php. NOTE: this can be exploited by unauthenticated remote… | |
| Modificada | Media (6.8) | 7.3% | — | Jean Charles JBC Explorer | 10/11/2007 | 16/6/2026 | dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.php via the suppr parameter, and (2) re-create the auth.inc.php file with contents that specify a new account name and password for JBC Explorer via the login and password… | |
| Modificada | Alta (7.8) | 2.2% | — | Charles Kerr PAN | 3/11/2003 | 16/6/2026 | Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address. | |
| Modificada | Media (5) | 6.8% | — | Charles Steinkuehler Sh-httpd | 27/10/2003 | 16/6/2026 | Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character. | |
| Modificada | Media (5) | 2.0% | — | Charles Clark Meteor Ftpd | 27/9/2001 | 16/6/2026 | Directory traversal vulnerability in Meteor FTP 1.0 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the ls/LIST command, or (2) a ... in the cd/CWD command. |