Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Expressionengine Quiz AND Survey MasterAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.
AplazadaAlta (7.1)0.25%—Expressionengine Quiz AND Survey MasterAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions.
AplazadaMedia (4.9)0.60%—Expressionengine Quiz AND Survey MasterAI6/6/202623/7/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AnalizadaAlta (7.2)0.30%—Expressionengine26/1/202617/6/2026
SQL Injection vulnerability in the Structure for Admin authenticated user
ModificadaMedia (6.1)0.30%—Expressionengine16/6/202417/6/2026
ExpressionEngine before 7.4.11 allows XSS.
ModificadaAlta (8.8)1.4%—Expressionengine9/2/202317/6/2026
In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user.
ModificadaAlta (7.2)0.93%—Expressionengine18/2/202217/6/2026
Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel access to execute the attack.
ModificadaCrítica (9.8)1.4%—Expressionengine12/8/202117/6/2026
In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file names of icon.png and icon.svg.
ModificadaAlta (8.8)2.8%—Expressionengine15/3/202117/6/2026
ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under the system/user/language directory.
ModificadaAlta (8.8)4.1%—Expressionengine24/6/202017/6/2026
ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Save As Draft actions. A user with low privileges (member) is able to upload this. It is possible to bypass the MIME type check and file-extension check while uploading new…
ModificadaMedia (6.1)0.65%—Expressionengine1/10/201817/6/2026
ExpressionEngine before 4.3.5 has reflected XSS.
ModificadaMedia (5.4)0.51%—Expressionengine17/11/201717/6/2026
EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection
ModificadaAlta (7.5)4.0%—Expressionengine22/6/201717/6/2026
ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.
ModificadaMedia (6.5)1.6%—Ellislab ExpressionengineExpressionengine4/11/201417/6/2026
Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) column_filter or (2) category[] parameter to system/index.php or the (3) tbl_sort[0][] parameter in the comment module to system/index.php.
ModificadaMedia (4.3)1.7%—Expressionengine26/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter.
ModificadaMedia (4.3)1.3%—Expressionengine10/1/200816/6/2026
Cross-site scripting (XSS) vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameter.
ModificadaMedia (4.3)1.2%—Expressionengine10/1/200816/6/2026
CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter.
ModificadaMedia (4.3)2.1%—Pmachine Expressionengine27/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer).