Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2610▼ 308 respecto a la semana anterior
Críticas / altas1345▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.64%—Diaowen DwsurveyAI26/8/20269/9/2026
DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.
AplazadaBaja (2.1)0.35%—Diaowen DwsurveyAI4/8/202612/8/2026
A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey Status Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been…
AplazadaBaja (2.1)0.36%—Diaowen DwsurveyAI4/8/202612/8/2026
A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. The manipulation results in authorization bypass. The attack can be launched remotely. The exploit…
AnalizadaAlta (7.5)0.29%—Diaowen Dwsurvey5/11/202517/6/2026
DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID with the ID of another questionnaire can enable the deletion of other questionnaires.
ModificadaCrítica (9.8)1.3%—Diaowen Dwsurvey1/9/202317/6/2026
File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.
ModificadaMedia (6.1)0.56%—Diaowen Dwsurvey20/6/202317/6/2026
Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.action file.
ModificadaCrítica (9.8)1.2%—Diaowen Dwsurvey20/3/202217/6/2026
DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java.
ModificadaCrítica (9.8)3.1%—Diaowen Dwsurvey20/3/202217/6/2026
DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java.
ModificadaMedia (6.1)0.87%—Diaowen Dwsurvey16/8/201917/6/2026
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
ModificadaMedia (6.1)0.79%—Diaowen Dwsurvey7/8/201917/6/2026
DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.