Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.70%—Surveyking14/5/202417/6/2026
An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.
AnalizadaCrítica (9.1)0.73%—Surveyking14/5/202417/6/2026
SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.
AnalizadaMedia (4.3)0.42%—Surveyking14/5/202417/6/2026
An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.
ModificadaMedia (6.5)1.3%—Surveyking25/3/20229/7/2026
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.
ModificadaCrítica (9.8)1.9%—Surveyking Project Surveyking24/3/202217/6/2026
Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.