Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

120 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.28%—Coolbeans1212 Mateishomepage WebsiteAI29/9/202629/9/2026
A flaw has been found in coolbeans1212 MateisHomePage-Website up to ea2a4226deeca27ab1fb9df0552ec76444547811. Affected by this issue is some unknown functionality of the file users.php. This manipulation of the argument Search causes cross site scripting. The attack can be initiated remotely. The exploit has been…
ModificadaAlta (8.6)1.3%—4homepages 4images13/1/202617/6/2026
4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted…
AplazadaAlta (7.1)0.13%—Jatinder PAL Singh BP Profile AS HomepageAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage bp-profile-as-homepage allows Stored XSS.This issue affects BP Profile as Homepage: from n/a through <= 1.1.
AplazadaCrítica (10)1.1%—Masterhomepage Automatic TranslationAI29/10/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translation allows Upload a Web Shell to a Web Server.This issue affects Automatic Translation: from n/a through <= 1.0.4.
AnalizadaMedia (6.5)0.26%—Gethomepage Homepage23/8/202417/6/2026
Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is setup without certificate and authentication by default, leaving it to vulnerable to DNS rebinding. In this attack, an attacker will ask a user to visit…
ModificadaMedia (6.1)0.33%—Geekcodelab ALL 404 Pages Redirect TO Homepage12/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Geek Code Lab All 404 Pages Redirect to Homepage allows Stored XSS.This issue affects All 404 Pages Redirect to Homepage: from n/a through 1.9.
ModificadaAlta (7.2)0.73%—Wpvibes Redirect 404 Error Page TO Homepage OR Custom Page With Logs18/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPVibes Redirect 404 Error Page to Homepage or Custom Page with Logs allows SQL Injection.This issue affects Redirect 404 Error Page to Homepage or Custom Page with Logs: from n/a through 1.8.7.
ModificadaAlta (7.5)0.50%—HP System Management Homepage17/12/202317/6/2026
A potential security vulnerability has been identified with HP-UX System Management Homepage (SMH). This vulnerability could be exploited locally or remotely to disclose information.
ModificadaMedia (4.8)0.39%—Magneticlab Homepage Pop-up16/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions.
ModificadaAlta (8.8)0.26%—Magneticlab Homepage Pop-up2/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions.
ModificadaCrítica (9.8)0.85%—Justsystems Atok Medical 2Justsystems Atok Medical 3Justsystems Atok PRO 3Justsystems Atok PRO 4+5616/8/202217/6/2026
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of…
ModificadaAlta (8.8)0.93%—Homepage Product Organizer FOR Woocommerce Project Homepage Product Organizer FOR Woocommerce22/7/202217/6/2026
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.
ModificadaCrítica (9.3)1.3%—Homepage Project Homepage11/7/202217/6/2026
The nrlakin/homepage repository through 2017-03-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaMedia (6.5)0.55%—Wpvibes Redirect 404 Error Page TO Homepage OR Custom Page With Logs8/11/202117/6/2026
The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attack
ModificadaMedia (5.4)0.62%—Clogica ALL 404 Redirect TO Homepage17/5/202117/6/2026
The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.
ModificadaMedia (6.5)0.56%—Clogica ALL 404 Redirect TO Homepage17/5/202117/6/2026
The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to make a logged in user change the plugin's settings. Due to the lack of sanitisation and escaping in some fields, it could also lead to Stored Cross-Site Scripting issues
ModificadaMedia (4.8)2.0%—4homepages 4images22/3/202117/6/2026
A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.
ModificadaMedia (4.8)0.59%—4homepages 4images26/1/202117/6/2026
4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result in an attacker to inject the XSS payload into the IMAGE URL. Each time a user visits that URL, the XSS triggers and the attacker can be able to steal the cookie according to the…
ModificadaMedia (5.6)0.31%—HP System Management Homepage15/2/201817/6/2026
A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
ModificadaMedia (5.6)0.41%—HP System Management Homepage15/2/201817/6/2026
A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
ModificadaMedia (5.6)0.45%—HP System Management Homepage15/2/201817/6/2026
A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
ModificadaMedia (5.6)0.31%—HP System Management Homepage15/2/201817/6/2026
A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
ModificadaMedia (5.6)0.31%—HP System Management Homepage15/2/201817/6/2026
A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
ModificadaMedia (5.6)0.41%—HP System Management Homepage15/2/201817/6/2026
A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
ModificadaMedia (5.6)0.41%—HP System Management Homepage15/2/201817/6/2026
A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.