Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

31 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.56%—Thinking Software Technology EfenceAI14/9/202618/9/2026
EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
AplazadaAlta (8.7)0.79%—Thinking Software Technology EfenceAI26/8/202626/8/2026
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AplazadaAlta (8.8)0.48%—Thinking Software Technology EfenceAI26/8/202626/8/2026
Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can access file upload functionality and read database contents.
AplazadaCrítica (9.3)0.90%—Thinking Software Technology EfenceAI26/8/20263/9/2026
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AplazadaAlta (8.8)0.79%—PacketfenceAI6/8/202631/8/2026
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
AplazadaAlta (8.7)0.65%—Wordfence Anti Malware Security AND Bruteforce FirewallAI16/5/202617/6/2026
WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the file parameter. Attackers can send requests to the duplicator_download action via admin-ajax.php with path traversal…
AnalizadaMedia (6.5)0.27%—Mega-fence Project Mega-fence5/1/202617/6/2026
Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client IP without validating a trusted proxy chain. An attacker can supply an arbitrary XFF value in a remote request to spoof the client IP, which is then propagated to security-relevant state (e.g.,…
AplazadaAlta (7.1)0.33%—Harshtohit111 Fence URLAI28/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in harshtohit111 Fence URL fence-url allows Stored XSS.This issue affects Fence URL: from n/a through <= 2.0.0.
AplazadaAlta (8.8)1.4%—Redhat Fence Agents Remediation OperatorAI12/8/202417/6/2026
A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, for example, a user with developer access, can create a specially crafted…
ModificadaMedia (5.4)0.31%—Mainwp Wordfence Extension25/3/202417/6/2026
Missing Authorization vulnerability in MainWP MainWP Wordfence Extension.This issue affects MainWP Wordfence Extension: from n/a through 4.0.7.
AnalizadaAlta (7.5)100%⚠ Explotación activaSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaCrítica (9.8)1.0%—Thinkingsoftware Efence16/6/202317/6/2026
Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.
ModificadaCrítica (9.8)1.0%—Thinkingsoftware Efence31/1/202317/6/2026
Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.
ModificadaMedia (4.8)0.81%—Wordfence Security23/9/202217/6/2026
The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to…
ModificadaMedia (5.9)0.83%—Clusterlabs Fence-agents2/1/202017/6/2026
In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.
ModificadaMedia (5)2.2%—Clusterlabs Fence-agentsRedhat Enterprise LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation30/7/201917/6/2026
A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM…
ModificadaMedia (6.1)1.0%—Wordfence25/4/201917/6/2026
The Wordfence plugin 7.2.3 for WordPress allows XSS via a unique attack vector. NOTE: It has been asserted that this is not a valid vulnerability in the context of the Wordfence WordPress plugin as the firewall rules are not maintained as part of the Wordfence software but rather it is a set of rules hosted on vendor…
ModificadaMedia (6.1)1.2%—Wordfence Security28/8/201817/6/2026
Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the val parameter to whois.php.
ModificadaAlta (7.8)0.84%—F-secure Xfence13/6/201817/6/2026
An issue was discovered in F-Secure XFENCE and Little Flocker. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned…
ModificadaCrítica (9.8)1.6%—Packetfence1/2/201816/6/2026
html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentication via a crafted username.
ModificadaCrítica (9.8)1.5%—Packetfence1/2/201816/6/2026
The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authentication via an empty password.
ModificadaAlta (7.8)1.1%—Fujitsu Fence-explorer15/9/201717/6/2026
Untrusted search path vulnerability in FENCE-Explorer for Windows V8.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (4.3)2.3%—Wordfence Security Project Wordfence Security6/11/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the whoisval parameter on the WordfenceWhois page to wp-admin/admin.php.
ModificadaMedia (5.4)0.27%—Defence.pk23/9/201417/6/2026
The Defence.pk (aka com.tapatalk.defencepkforums) application 2.4.13.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.6%—Efence Project Efence2/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in callback.php in the efence plugin 1.3.2 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) message, (2) zoneid, (3) pubKey, or (4) privKey parameter.