Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2610▼ 308 respecto a la semana anterior
Críticas / altas1345▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.64% | — | Diaowen DwsurveyAI | 26/8/2026 | 9/9/2026 | DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters. | |
| Aplazada | Baja (2.1) | 0.35% | — | Diaowen DwsurveyAI | 4/8/2026 | 12/8/2026 | A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey Status Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.36% | — | Diaowen DwsurveyAI | 4/8/2026 | 12/8/2026 | A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. The manipulation results in authorization bypass. The attack can be launched remotely. The exploit… | |
| Analizada | Alta (7.5) | 0.29% | — | Diaowen Dwsurvey | 5/11/2025 | 17/6/2026 | DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID with the ID of another questionnaire can enable the deletion of other questionnaires. | |
| Modificada | Crítica (9.8) | 1.3% | — | Diaowen Dwsurvey | 1/9/2023 | 17/6/2026 | File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file. | |
| Modificada | Media (6.1) | 0.56% | — | Diaowen Dwsurvey | 20/6/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.action file. | |
| Modificada | Crítica (9.8) | 1.2% | — | Diaowen Dwsurvey | 20/3/2022 | 17/6/2026 | DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java. | |
| Modificada | Crítica (9.8) | 3.1% | — | Diaowen Dwsurvey | 20/3/2022 | 17/6/2026 | DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java. | |
| Modificada | Media (6.1) | 0.87% | — | Diaowen Dwsurvey | 16/8/2019 | 17/6/2026 | DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter. | |
| Modificada | Media (6.1) | 0.79% | — | Diaowen Dwsurvey | 7/8/2019 | 17/6/2026 | DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter. |