Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2573▼ 368 respecto a la semana anterior
Críticas / altas1324▲ 44 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.91% | — | Count PER DAY Project Count PER DAY | 21/8/2019 | 16/6/2026 | The count-per-day plugin before 3.2.3 for WordPress has XSS via search words. | |
| Modificada | Media (6.1) | 0.98% | — | Count PER DAY Project Count PER DAY | 15/6/2019 | 17/6/2026 | The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter. | |
| Modificada | Alta (7.2) | 7.2% | — | Count PER DAY Project Count PER DAY | 23/10/2017 | 17/6/2026 | SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE: this can be leveraged using CSRF to allow remote attackers to… | |
| Modificada | Media (4.3) | 2.4% | — | TOM Braider Count PER DAY | 15/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in userperspan.php in the Count Per Day module before 3.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) datemin, or (3) datemax parameter. | |
| Modificada | Media (5) | 23% | — | Count PER DAY Project Count PER DAYTOM Braider Count PER DAY | 20/1/2012 | 16/6/2026 | Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter. | |
| Modificada | Media (4.3) | 5.3% | — | TOM Braider Count PER DAY | 20/1/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map parameter. |