Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

113 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.21%—Connections-pro Connections Business DirectoryAI30/9/202630/9/2026
The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including…
Pendiente de análisisBaja (3.1)0.15%—HCL ConnectionsAI31/8/20263/9/2026
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data.
AplazadaBaja (3.7)0.12%—HCL ConnectionsAI26/8/202628/8/2026
HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to information disclosure or security bypass.
AnalizadaBaja (3.5)0.27%—Hcltech Connections27/7/202620/8/2026
An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.
AnalizadaBaja (3.5)0.27%—Hcltech Connections27/7/202620/8/2026
HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.
Pendiente de análisisBaja (3.5)0.16%—HCL ConnectionsAI23/6/202630/9/2026
HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.
AplazadaMedia (4.6)0.12%—HCL ConnectionsAI18/5/202617/6/2026
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
AnalizadaMedia (5.4)0.16%—Hcltech Connections19/3/202617/6/2026
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may allow the attacker steal cookie-based authentication credentials and comprise user's…
AnalizadaBaja (3.5)0.27%—Hcltech Connections20/2/202617/6/2026
HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow a user to obtain limited information when a single piece of internal metadata is returned in the browser.
AnalizadaMedia (6.5)0.21%—Hcltech Connections18/11/202517/6/2026
HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper rendering of application data.
AnalizadaMedia (4.6)0.15%—Hcltech Connections15/8/202517/6/2026
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
AnalizadaAlta (7.5)0.22%—Hcltech Connections Docs14/8/202517/6/2026
HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.
AnalizadaBaja (3.5)0.20%—Hcltech Connections17/7/202517/6/2026
HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive information they are not entitled to, which is caused by improper handling of request data.
AnalizadaAlta (7.5)0.49%—Connections-pro Wp-syntax19/4/202517/6/2026
The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post containing a large number of tags, thereby exploiting a catastrophic backtracking issue in the regular expression processing to cause a DoS.
AnalizadaBaja (3.5)0.27%—Hcltech Connections4/4/202517/6/2026
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
AnalizadaMedia (4.4)0.15%—Hcltech Connections Docs12/2/202517/6/2026
HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.
AplazadaMedia (6.5)0.57%—Connections-pro Connections Business DirectoryAI25/1/202517/6/2026
The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a connections image directory in all versions up to, and including, 10.4.66. This makes it possible for authenticated attackers, with Administrator-level access…
AplazadaMedia (6.5)0.24%—Martythornley Photographer ConnectionsAI18/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MartyThornley Photographer Connections photographer-connections allows Stored XSS.This issue affects Photographer Connections: from n/a through <= 1.3.1.
AnalizadaMedia (4.6)0.18%—Hcltech Connections14/11/202417/6/2026
HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.
AnalizadaMedia (4.3)0.27%—Hcltech Connections28/10/202417/6/2026
HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive information they are not entitled to due to the improper handling of request data.
AnalizadaMedia (5.7)0.31%—Hcltech Connections9/10/202417/6/2026
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly handling the request data.
AnalizadaMedia (5.4)0.26%—Hcltech Connections25/6/202417/6/2026
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise user's…
AnalizadaMedia (4.3)0.33%—Hcltech Connections25/6/202417/6/2026
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
AplazadaMedia (4.4)0.25%—HCL Connections DocsAI8/6/202417/6/2026
HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional attacks.
AnalizadaMedia (6.5)0.33%—Hcltech Connections18/4/202417/6/2026
HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.