Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 662 respecto a la semana anterior
Críticas / altas1264▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.13% | — | Mosh-proAI | 26/8/2025 | 31/8/2026 | The configuration of Mosh-Pro on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileged access to execute arbitrary code that inherits Mosh-Pro TCC (Transparency, Consent, and Control) permissions. Acquired resource access is limited to previously granted permissions by the user.… | |
| Aplazada | Media (6.5) | 0.21% | — | Moshensky CF7 SpreadsheetsAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moshensky CF7 Spreadsheets cf7-spreadsheets allows Stored XSS.This issue affects CF7 Spreadsheets: from n/a through <= 2.3.2. | |
| Aplazada | Alta (7.1) | 0.29% | — | Moshensky CF7 SpreadsheetsAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moshensky CF7 Spreadsheets cf7-spreadsheets allows Reflected XSS.This issue affects CF7 Spreadsheets: from n/a through <= 2.3.2. | |
| Aplazada | Media (5.4) | 0.26% | — | Moshensky CF7 SpreadsheetsAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in moshensky CF7 Spreadsheets cf7-spreadsheets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 Spreadsheets: from n/a through <= 2.3.2. | |
| Aplazada | Media (4.3) | 0.34% | — | Jaed Mosharraf AND Pluginbazar Team Open Close Woocommerce StoreAI | 17/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Jaed Mosharraf & Pluginbazar Team Open Close WooCommerce Store.This issue affects Open Close WooCommerce Store: from n/a through 4.9.1. | |
| Modificada | Media (4.3) | 1.5% | — | Cosmoshop | 27/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the admin-login panel (admin/index.cgi) in Cosmoshop allows remote attackers to inject arbitrary web script or HTML via the username field (u_name parameter). | |
| Modificada | Media (6.8) | 0.61% | — | Zaunz Gmbh Cosmoshop | 1/1/2015 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/setup_edit.cgi in CosmoShop ePRO 10.05.00 allows remote attackers to hijack the authentication of administrators for requests that modify settings via a setup action. | |
| Modificada | Media (4.3) | 0.97% | — | Zaunz Gmbh Cosmoshop | 1/1/2015 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in CosmoShop ePRO 10.05.00 allow remote attackers to inject arbitrary web script or HTML via (1) the rcopy parameter to cgi-bin/admin/rubrikadmin.cgi, (2) the typ parameter to cgi-bin/admin/artikeladmin.cgi, or (3) the suchbegriff parameter to… | |
| Modificada | Media (5) | 1.6% | — | Moshe Weitzman Organic Groups | 14/8/2012 | 16/6/2026 | The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access, which allows remote attackers to obtain sensitive information such as private group titles via a request through the Views module. | |
| Modificada | Media (4) | 11% | 💥 Exploit | Keith Winstein Mosh | 29/6/2012 | 16/6/2026 | The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value. | |
| Modificada | Baja (2.1) | 1.7% | — | Moshe Weitzman Organic Groups | 27/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in og.js in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with the Vertical Tabs module, allows remote authenticated users to inject arbitrary web script or HTML via vectors related the group title. | |
| Modificada | Media (6.8) | 2.6% | — | Moshe Weitzman Organic Groups | 27/6/2012 | 16/6/2026 | The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "access content" permission removed, which allows remote attackers to bypass access restrictions and possibly have other unspecified impact. | |
| Modificada | Media (6.5) | 1.3% | — | Moshe Weitzman OG Vocab | 31/12/2009 | 16/6/2026 | The Organic Groups (OG) Vocabulary module 6.x before 6.x-1.0 for Drupal allows remote authenticated group members to bypass intended access restrictions, and create, modify, or read a vocabulary, via unspecified vectors. | |
| Modificada | Media (4.3) | 1.7% | — | Moshe Weitzman OG Vocab | 26/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Organic Groups (OG) Vocabulary 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the group title. | |
| Modificada | Baja (3.5) | 1.0% | — | Moshe Weitzman Organic Groups | 9/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Organic Groups (OG) 5.x-7.x before 5.x-7.4, 5.x-8.x before 5.x-8.1, and 6.x-1.x before 6.x-1.4, a module for Drupal, allows remote authenticated users, with create or edit group nodes permissions, to inject arbitrary web script or HTML via the User-Agent HTTP header, a… | |
| Modificada | Media (4.3) | 1.1% | — | Moshe Weitzman Devel | 28/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the variable editor in the Devel module 5.x before 5.x-1.2 and 6.x before 6.x-1.18, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a variable name. | |
| Modificada | Alta (7.8) | 1.7% | — | Cosmoshop | 19/5/2006 | 16/6/2026 | Directory traversal vulnerability in (1) edit_mailtexte.cgi and (2) bestmail.cgi in Cosmoshop 8.11.106 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Cosmoshop | 19/5/2006 | 16/6/2026 | SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary SQL commands via the artnum parameter. | |
| Modificada | Media (5) | 1.2% | — | Cosmoshop | 2/9/2005 | 16/6/2026 | Directory traversal vulnerability in bestmail_edit.cgi in cosmoshop 8.10.78 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Cosmoshop | 2/9/2005 | 16/6/2026 | SQL injection vulnerability in the login function for the administration login panel in cosmoshop 8.10.78 allows remote attackers to execute arbitrary SQL commands and bypass authentication via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.33% | — | Cosmoshop | 2/9/2005 | 16/6/2026 | cosmoshop 8.10.78 and earlier stores passwords in plaintext in the database, which allows local users to obtain sensitive information. |