Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

480 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.27%—Limesurvey Community EditionAI2/10/20262/10/2026
An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript…
AplazadaAlta (7.1)0.15%—Quizandsurveymaster Quiz AND Survey MasterAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
AplazadaAlta (7.1)0.24%—Limesurvey Community EditionAI29/9/202630/9/2026
An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request…
AplazadaMedia (6)0.35%—Tduck Survey FormAI25/9/202629/9/2026
TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form submissions. Attackers can read orphaned submission data including personal information by providing a known dataId to…
AplazadaAlta (7.4)0.39%—Limesurvey Community EditionAI23/9/202623/9/2026
LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page.
AplazadaAlta (7.4)0.38%—LimesurveyAI23/9/20262/10/2026
LimeSurvey Community Edition 7.0.14 fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.
AplazadaAlta (7.1)0.40%—Tduck Survey FormAI16/9/202624/9/2026
TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other users' forms and exfiltrate submissions to arbitrary external or internal addresses.
AplazadaAlta (7.1)0.42%—Tduck Survey FormAI16/9/202624/9/2026
TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submission identifiers allocated in narrow ranges and modify arbitrary form responses…
AplazadaAlta (7.5)1.7%—C-mor Video SurveillanceAI15/9/202622/9/2026
The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.
AplazadaMedia (6.1)0.91%—C-mor Video SurveillanceAI15/9/202622/9/2026
Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component
AplazadaMedia (5.3)0.31%—Quizandsurveymaster Quiz AND Survey MasterAI11/9/202611/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.
AplazadaBaja (2.7)0.30%—Quizandsurveymaster Quiz AND Survey MasterAI28/8/202628/8/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users.
AplazadaMedia (5.1)0.40%—Limesurvey Community EditionAI27/8/202628/8/2026
LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu entry creation endpoint. An authenticated user with only the global settings:read permission can directly invoke POST /index.php/admin/menuentries/sa/create and create new survey menu entries without…
AplazadaMedia (4.8)0.41%—Limesurvey Community EditionAI26/8/202628/8/2026
LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5.
AplazadaAlta (7.4)0.46%—Limesurvey Community EditionAI26/8/202628/8/2026
LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML attribute encoding. This issue affects…
AplazadaAlta (7.2)0.24%—Limesurvey Community EditionAI26/8/202628/8/2026
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message. This issue affects LimeSurvey: 7.0.5.
AplazadaAlta (8.4)0.26%—Limesurvey Community EditionAI26/8/202628/8/2026
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission can create a survey menu entry containing attacker-controlled data. The value is stored in the surveymenu_entries.data…
AplazadaCrítica (9.8)0.64%—Diaowen DwsurveyAI26/8/20269/9/2026
DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.
Pendiente de análisisMedia (5.7)0.19%—Drupal Powerful SurveysAI25/8/202628/8/2026
Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.
AplazadaBaja (2.7)0.30%—Expressivequiz Quiz AND Survey MasterAI19/8/202626/8/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient…
AplazadaBaja (2.7)0.28%—Quizandsurveymaster Quiz AND Survey MasterAI19/8/202626/8/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users.
AplazadaMedia (4.3)0.27%—Modal SurveyAI18/8/202620/8/2026
Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.
AplazadaMedia (6.5)0.45%—Quizandsurveymaster Quiz AND Survey MasterAI16/8/202620/8/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option in all versions up to, and including, 11.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaMedia (6.4)0.42%—Expresstech Quiz Survey MasterAI16/8/202620/8/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaMedia (6)0.38%—Limesurvey Community EditionAI14/8/202628/8/2026
LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list.