Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.39% | — | Webliberty Simple SpoilerAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple Spoiler simple-spoiler allows Stored XSS.This issue affects Simple Spoiler: from n/a through <= 1.4. | |
| Analizada | Alta (7.3) | 0.56% | — | Webliberty Simple Spoiler | 14/9/2024 | 17/6/2026 | The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for unauthenticated attackers to execute arbitrary… | |
| Aplazada | Media (5.9) | 0.26% | — | Webliberty Simple SpoilerAI | 3/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple Spoiler simple-spoiler.This issue affects Simple Spoiler: from n/a through <= 1.2. | |
| Modificada | Media (6.1) | 0.38% | — | Deepsoft Weblibrarian | 6/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Robert Heller WebLibrarian plugin <= 3.5.8.1 versions. | |
| Modificada | Crítica (9.1) | 37% | 💥 Exploit | Iclinks Scadaflex II FirmwareIclinks Weblib | 26/2/2022 | 17/6/2026 | On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files. | |
| Modificada | Media (6.1) | 0.92% | — | Deepsoft Weblibrarian | 21/8/2019 | 17/6/2026 | The weblibrarian plugin before 3.4.8.7 for WordPress has XSS via front-end short codes. | |
| Modificada | Media (6.1) | 0.89% | — | Deepsoft Weblibrarian | 21/8/2019 | 17/6/2026 | The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes. | |
| Modificada | Media (6.1) | 0.92% | — | Deepsoft Weblibrarian | 21/8/2019 | 17/6/2026 | The weblibrarian plugin before 3.4.8.5 for WordPress has XSS via front-end short codes. | |
| Modificada | Media (6.5) | 1.4% | — | Deepsoft Weblibrarian | 15/7/2019 | 17/6/2026 | Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection. The impact is: Exposing the entire database. The component is: Function "AllBarCodes" (defined at database_code.php line 1018) is vulnerable to a boolean-based blind sql injection. This function call can be triggered by any user logged-in… | |
| Modificada | Alta (10) | 3.6% | — | Darryl Burgdorf Weblibs | 10/1/2005 | 16/6/2026 | weblibs.pl in WebLibs 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the TextFile parameter. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Darryl Burgdorf Weblibs | 10/1/2005 | 16/6/2026 | Directory traversal vulnerability in weblibs.pl in WebLibs 1.0 allows remote attackers to read arbitrary files via .. sequences in the TextFile parameter. |