Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.24%—Infusedwoo PROAI25/8/202627/8/2026
The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users…
AplazadaAlta (7.5)0.46%—Infusedwoo PROAI14/5/202617/6/2026
The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify…
AplazadaCrítica (9.1)0.46%—Infusedwoo PROAI14/5/202617/6/2026
The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages,…
AplazadaCrítica (9.8)0.70%—Infusedwoo PROAI14/5/202617/6/2026
The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the iwar_save_recipe() AJAX handler. This makes it possible for unauthenticated attackers to create a…
AplazadaAlta (8.8)0.51%—Infusedwoo PROAI14/5/202617/6/2026
The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infusedwoo_gdpr_upddata() function missing authorization and capability checks, as well as lacking restrictions on which user meta keys can be updated. This makes it possible…
ModificadaAlta (8.8)1.3%—Libconfuse Project LibconfuseFedoraproject Fedora9/9/202217/6/2026
cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.
ModificadaAlta (8.8)1.1%—Libconfuse Project Libconfuse30/11/201817/6/2026
cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak.
ModificadaAlta (8.8)1.8%—Libconfuse Project LibconfuseDebian Linux20/7/201817/6/2026
trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read.
ModificadaAlta (7.5)0.99%—Infuseum ASP Message Board7/11/200716/6/2026
SQL injection vulnerability in boards/printer.asp in ASP Message Board 2.2.1c allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.4%—Citrix Metaframe Secure Access ManagerCitrix Nfuse3/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field.
ModificadaAlta (7.5)7.9%—Citrix Nfuse12/8/200216/6/2026
Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.
ModificadaMedia (5)3.6%—Citrix Nfuse12/8/200216/6/2026
Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.
ModificadaMedia (5)2.5%—Citrix Nfuse12/8/200216/6/2026
Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.
ModificadaMedia (5)2.0%—Citrix Nfuse31/5/200216/6/2026
Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.
ModificadaMedia (5)3.6%—Citrix Nfuse18/10/200116/6/2026
Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field.