Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.2% | — | Vanguard Project Vanguard | 5/7/2020 | 17/6/2026 | An issue was discovered in the Vanguard plugin 2.1 for WordPress. XSS can occur via the mails/new title field, a product field to the p/ URI, or the Products Search box. | |
| Modificada | Crítica (9.8) | 1.4% | — | Sokkia Gnr5 Vanguard Firmware | 15/6/2020 | 17/6/2026 | SOKKIA GNR5 Vanguard WEB version 1.2 (build: 91f2b2c3a04d203d79862f87e2440cb7cefc3cd3) and hardware version 212 allows remote attackers to bypass admin authentication via a SQL injection attack that uses the User Name or Password field on the login page. | |
| Modificada | Media (6.1) | 0.63% | — | Vanguard Project Marketplace Digital Products PHP | 28/12/2017 | 17/6/2026 | Vanguard Marketplace Digital Products PHP has XSS via the phps_query parameter to /search. | |
| Modificada | Alta (8.8) | 0.46% | — | Vanguard Project Marketplace Digital Products PHP | 28/12/2017 | 17/6/2026 | Vanguard Marketplace Digital Products PHP has CSRF via /search. | |
| Modificada | Alta (8.8) | 6.0% | — | Vanguard Project Marketplace Digital Products PHP | 27/12/2017 | 17/6/2026 | Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI. | |
| Modificada | Crítica (9.8) | 2.7% | — | Vanguard Project Marketplace Digital Products PHP | 27/12/2017 | 17/6/2026 | Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI. |