Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.56%—Niftypm NiftyAI17/6/202617/6/2026
Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.
AplazadaAlta (7.1)0.25%—Nifty BackupsAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NickDuncan Nifty Backups nifty-backups allows Reflected XSS.This issue affects Nifty Backups: from n/a through <= 1.08.
ModificadaAlta (8.8)0.45%—Wpconcern Nifty Coming Soon & Maintenance Mode Page7/6/202317/6/2026
The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This is due to confusing logic functions missing or having incorrect nonce validation. This makes it possible for unauthenticated attackers to gain and perform otherwise…
ModificadaMedia (6.1)1.3%—Niftypm Nifty-pm21/12/202017/6/2026
Nifty-PM CPE 2.3 is affected by stored HTML injection. The impact is remote arbitrary code execution.
ModificadaMedia (5.4)0.68%—Niftypm Nifty15/9/202017/6/2026
Nifty Project Management Web Application 2020-08-26 allows XSS, via Add Task, that is rendered upon a Project Home visit. Note: It has been argued that this is not reproducible. "The original issue was that the task would be created and an alert would be shown on the screen. Now the task would be created, but the…