Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 212 respecto a la semana anterior
Críticas / altas1386▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.18% | — | Raiserweb Competition Form | 15/5/2025 | 17/6/2026 | The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Alta (7.1) | 0.58% | — | Raiserweb Competition Form | 29/1/2025 | 17/6/2026 | The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Alta (8.1) | 0.64% | — | Browserweb INC Whizz | 24/4/2017 | 17/6/2026 | There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request. | |
| Modificada | Media (6.1) | 3.4% | — | Browserweb Whizz | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin whizz v1.0.7 | |
| Modificada | Media (5) | 6.5% | — | Iptel Serweb | 10/12/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in js/get_js.php in SERWeb 2.0.0 dev1 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) mod and (2) js parameters. | |
| Modificada | Media (6.8) | 2.0% | — | Iptel Serweb | 10/12/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in SerWeb 2.0.0 dev1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SERWEB[configdir] parameter to load_lang.php, (2) _SERWEB[functionsdir] parameter to main_prepend.php, and the (3) _PHPLIB[libdir] parameter to load_phplib.php,… | |
| Modificada | Media (6.8) | 68% | — | Iptel Serweb | 22/6/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter. | |
| Modificada | Media (6.8) | 1.3% | — | Iptel Serweb | 22/6/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in SerWeb 0.9.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter to (1) html/load_apu.php or (2) html/mail_prepend.php. NOTE: the provenance of this information is unknown; the details are obtained solely… |