Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.40% | — | Speakout Email PetitionsAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Anton Voytenko PetitionerAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Anton Voytenko Petitioner petitioner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Petitioner: from n/a through <= 0.7.3. | |
| Analizada | Media (4.3) | 0.18% | — | Raiserweb Competition Form | 15/5/2025 | 17/6/2026 | The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Alta (7.1) | 0.58% | 💥 Exploit | Raiserweb Competition Form | 29/1/2025 | 17/6/2026 | The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (6.5) | 0.29% | — | Ropeswinghld Speakout Email PetitionsAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RopeSwingHld SpeakOut! Email Petitions speakout allows DOM-Based XSS.This issue affects SpeakOut! Email Petitions: from n/a through <= 4.4.2. | |
| Modificada | Alta (7.5) | 0.56% | — | Finexmedia Competition Management System | 23/5/2023 | 17/6/2026 | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users. This issue affects Competition Management System: before 23.07. | |
| Modificada | Alta (8.8) | 0.68% | — | Finexmedia Competition Management System | 23/5/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Finex Media Competition Management System allows Authentication Abuse, Authentication Bypass. This issue affects Competition Management System: before 23.07. | |
| Modificada | Crítica (9.8) | 1.0% | — | Codeboxr CBX Petition FOR Wordpress | 23/1/2023 | 17/6/2026 | The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Modificada | Crítica (9.8) | 8.8% | 💥 Exploit | Speakout! Email Petitions Project Speakout! Email Petitions | 28/3/2022 | 17/6/2026 | The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users | |
| Modificada | Baja (2.1) | 0.93% | — | Petition Project Petition | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Petition module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users with the "create petition" permission to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Appsgeyser Competition Information | 19/10/2014 | 17/6/2026 | The COMPETITION INFORMATION (aka com.ear.bilgiyarismasi) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (3.5) | 0.89% | — | Drupal Petition Node Module | 28/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Petition Node module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to signing a petition. | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Phpcompet.free PHP Competition System | 21/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Competition System BETA 0.84 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) day parameter to show_matchs.php and (2) pageno parameter to persons.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Webbdomain Petition | 6/4/2009 | 16/6/2026 | SQL injection vulnerability in getin.php in WEBBDOMAIN Petition 1.02, 2.0, and 3.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Joomla COM Beamospetition | 2/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Joomla COM Beamospetition | 2/2/2009 | 16/6/2026 | SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mpid parameter in a sign action to index.php, a different vector than CVE-2008-3132. | |
| Modificada | Alta (7.5) | 36% | 💥 Exploit | Recly Competitions | 31/12/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) add.php and (b) competitions.php in includes/competitions/, and the (2)… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomla COM Beamospetition | 10/7/2008 | 16/6/2026 | SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pet parameter to index.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 Codeon Petition Extension | 7/7/2008 | 16/6/2026 | SQL injection vulnerability in the Codeon Petition (cd_petition) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Fascript Fapersian Petition | 17/1/2008 | 16/6/2026 | SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 3.3% | 💥 Exploit | JAX Scripts JAX Petition Book | 18/1/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php. |