Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.23%—Newpath WildapricotpressAI21/8/202626/8/2026
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.
AplazadaAlta (8.2)0.34%—Dapr SentryAI2/7/202614/7/2026
Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document from the request Host, honoring an attacker-controlled X-Forwarded-Host header without validation when no allowed-hosts list is configured (the default), and serves the document with a one-hour…
AnalizadaAlta (8.1)0.49%—Linuxfoundation Dapr8/5/202617/6/2026
Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3.0 to before 1.15.14, 1.16.0-rc.1 to before 1.16.14, and 1.17.0-rc.1 to before 1.17.5, a vulnerability has been found in Dapr that allows bypassing access control policies for service invocation…
AplazadaMedia (6.5)0.37%—AgendapressAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Black and White AgendaPress – Easily Publish Meeting Agendas and Programs on WordPress agendapress allows Stored XSS.This issue affects AgendaPress – Easily Publish Meeting Agendas and Programs on WordPress: from n/a…
AplazadaMedia (5.3)0.44%—Linuxfoundation DaprAI23/5/202417/6/2026
Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. Dapr sends the app token of the invoker app instead of the app token of the invoked app. This causes of a leak of the application token of the invoker app to the invoked app when using Dapr as a gRPC proxy for remote…
AnalizadaMedia (6.8)0.18%—Measuresoft Scadapro Server30/4/202417/6/2026
The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, including unprivileged users, to write or overwrite files.
ModificadaAlta (7.5)1.4%—Linuxfoundation Dapr21/7/202317/6/2026
Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. A vulnerability has been found in Dapr that allows bypassing API token authentication, which is used by the Dapr sidecar to authenticate calls coming from the application, with a well-crafted HTTP request. Users who…
ModificadaAlta (7.5)3.9%—Linuxfoundation Dapr Dashboard3/10/202217/6/2026
Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.
ModificadaAlta (7.8)0.26%—Measuresoft Scadapro Server23/9/202217/6/2026
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.
ModificadaMedia (5.5)0.23%—Measuresoft Scadapro ClientMeasuresoft Scadapro Server31/8/202217/6/2026
Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow a denial-of-service condition.
ModificadaAlta (7.8)0.30%—Measuresoft Scadapro ClientMeasuresoft Scadapro Server31/8/202217/6/2026
Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation..
ModificadaAlta (7.8)0.32%—Measuresoft Scadapro Server31/8/202217/6/2026
Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file.
ModificadaAlta (7.8)0.31%—Measuresoft Scadapro Server31/8/202217/6/2026
Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based buffer overflow instances while processing a specific project file.
ModificadaAlta (7.8)0.30%—Measuresoft Scadapro Server31/8/202217/6/2026
Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. The controls may allow seven untrusted pointer deference instances while processing a specific project file.
ModificadaAlta (7.8)0.31%—Measuresoft Scadapro Server31/8/202217/6/2026
Measuresoft ScadaPro Server (Versions prior to 6.8.0.1) uses an unmaintained ActiveX control, which may allow an out-of-bounds write condition while processing a specific project file.
ModificadaAlta (7.2)0.48%—Measuresoft Scadapro ClientMeasuresoft Scadapro Server25/5/201216/6/2026
Untrusted search path vulnerability in Measuresoft ScadaPro Client before 4.0.0 and ScadaPro Server before 4.0.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
ModificadaAlta (10)57%—Measuresoft Scadapro16/9/201116/6/2026
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.
ModificadaAlta (10)14%—Measuresoft Scadapro16/9/201116/6/2026
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (2) OF, or (3) EF command.
ModificadaAlta (10)10%—Measuresoft Scadapro16/9/201116/6/2026
Multiple directory traversal vulnerabilities in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to read, modify, or delete arbitrary files via the (1) RF, (2) wF, (3) UF, or (4) NF command.
ModificadaAlta (10)36%—Measuresoft Scadapro16/9/201116/6/2026
Multiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long command to port 11234, as demonstrated with the TF command.