Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.28% | — | Coolbeans1212 Mateishomepage WebsiteAI | 29/9/2026 | 29/9/2026 | A flaw has been found in coolbeans1212 MateisHomePage-Website up to ea2a4226deeca27ab1fb9df0552ec76444547811. Affected by this issue is some unknown functionality of the file users.php. This manipulation of the argument Search causes cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Alta (8.6) | 1.3% | — | 4homepages 4images | 13/1/2026 | 17/6/2026 | 4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted… | |
| Aplazada | Alta (7.1) | 0.13% | — | Jatinder PAL Singh BP Profile AS HomepageAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage bp-profile-as-homepage allows Stored XSS.This issue affects BP Profile as Homepage: from n/a through <= 1.1. | |
| Aplazada | Crítica (10) | 1.1% | — | Masterhomepage Automatic TranslationAI | 29/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translation allows Upload a Web Shell to a Web Server.This issue affects Automatic Translation: from n/a through <= 1.0.4. | |
| Analizada | Media (6.5) | 0.26% | — | Gethomepage Homepage | 23/8/2024 | 17/6/2026 | Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is setup without certificate and authentication by default, leaving it to vulnerable to DNS rebinding. In this attack, an attacker will ask a user to visit… | |
| Modificada | Media (6.1) | 0.33% | — | Geekcodelab ALL 404 Pages Redirect TO Homepage | 12/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Geek Code Lab All 404 Pages Redirect to Homepage allows Stored XSS.This issue affects All 404 Pages Redirect to Homepage: from n/a through 1.9. | |
| Modificada | Alta (7.2) | 0.73% | — | Wpvibes Redirect 404 Error Page TO Homepage OR Custom Page With Logs | 18/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPVibes Redirect 404 Error Page to Homepage or Custom Page with Logs allows SQL Injection.This issue affects Redirect 404 Error Page to Homepage or Custom Page with Logs: from n/a through 1.8.7. | |
| Modificada | Alta (7.5) | 0.50% | — | HP System Management Homepage | 17/12/2023 | 17/6/2026 | A potential security vulnerability has been identified with HP-UX System Management Homepage (SMH). This vulnerability could be exploited locally or remotely to disclose information. | |
| Modificada | Media (4.8) | 0.39% | — | Magneticlab Homepage Pop-up | 16/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Magneticlab Homepage Pop-up | 2/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions. | |
| Modificada | Crítica (9.8) | 0.85% | — | Justsystems Atok Medical 2Justsystems Atok Medical 3Justsystems Atok PRO 3Justsystems Atok PRO 4+56 | 16/8/2022 | 17/6/2026 | An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of… | |
| Modificada | Alta (8.8) | 0.93% | — | Homepage Product Organizer FOR Woocommerce Project Homepage Product Organizer FOR Woocommerce | 22/7/2022 | 17/6/2026 | Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress. | |
| Modificada | Crítica (9.3) | 1.3% | — | Homepage Project Homepage | 11/7/2022 | 17/6/2026 | The nrlakin/homepage repository through 2017-03-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (6.5) | 0.55% | — | Wpvibes Redirect 404 Error Page TO Homepage OR Custom Page With Logs | 8/11/2021 | 17/6/2026 | The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attack | |
| Modificada | Media (5.4) | 0.62% | — | Clogica ALL 404 Redirect TO Homepage | 17/5/2021 | 17/6/2026 | The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute. | |
| Modificada | Media (6.5) | 0.56% | — | Clogica ALL 404 Redirect TO Homepage | 17/5/2021 | 17/6/2026 | The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to make a logged in user change the plugin's settings. Due to the lack of sanitisation and escaping in some fields, it could also lead to Stored Cross-Site Scripting issues | |
| Modificada | Media (4.8) | 2.0% | — | 4homepages 4images | 22/3/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter. | |
| Modificada | Media (4.8) | 0.59% | — | 4homepages 4images | 26/1/2021 | 17/6/2026 | 4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result in an attacker to inject the XSS payload into the IMAGE URL. Each time a user visits that URL, the XSS triggers and the attacker can be able to steal the cookie according to the… | |
| Modificada | Media (5.6) | 0.31% | — | HP System Management Homepage | 15/2/2018 | 17/6/2026 | A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. | |
| Modificada | Media (5.6) | 0.41% | — | HP System Management Homepage | 15/2/2018 | 17/6/2026 | A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. | |
| Modificada | Media (5.6) | 0.45% | — | HP System Management Homepage | 15/2/2018 | 17/6/2026 | A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. | |
| Modificada | Media (5.6) | 0.31% | — | HP System Management Homepage | 15/2/2018 | 17/6/2026 | A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. | |
| Modificada | Media (5.6) | 0.31% | — | HP System Management Homepage | 15/2/2018 | 17/6/2026 | A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. | |
| Modificada | Media (5.6) | 0.41% | — | HP System Management Homepage | 15/2/2018 | 17/6/2026 | A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. | |
| Modificada | Media (5.6) | 0.41% | — | HP System Management Homepage | 15/2/2018 | 17/6/2026 | A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found. |