Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.22% | — | Mosswebworks MWW Disclaimer ButtonsAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jennifer Moss MWW Disclaimer Buttons mww-disclaimer-buttons allows Stored XSS.This issue affects MWW Disclaimer Buttons: from n/a through <= 3.41. | |
| Aplazada | Media (5.1) | 0.52% | — | WebworkAI | 8/9/2025 | 30/9/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code through the 'q' and 'engine' request parameters in /search. | |
| Modificada | Media (4.8) | 0.34% | — | Mosswebworks MWW Disclaimer Buttons | 15/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moss Web Works MWW Disclaimer Buttons allows Stored XSS.This issue affects MWW Disclaimer Buttons: from n/a through 3.0.2. | |
| Modificada | Media (5) | 6.1% | — | Apache StrutsOpensymphony XworkOpensymphony Webwork | 13/5/2011 | 16/6/2026 | XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3. | |
| Modificada | Baja (2.6) | 33% | — | Apache StrutsOpensymphony WebworkOpensymphony Xwork | 13/5/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method… | |
| Modificada | Media (4.3) | 2.8% | — | Webworks EpublisherWebworks HelpWebworks PublisherVmware Vcenter+6 | 16/12/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x… | |
| Modificada | Alta (7.5) | 1.2% | — | Webwork Program Generation Language | 18/12/2006 | 16/6/2026 | lib/WeBWorK/PG/Translator.pm in WeBWorK Program Generation (PG) Language before 2.3.1 uses an insufficiently restrictive regular expression to determine valid macro filenames, which allows attackers to load arbitrary macro files whose names contain the strings (1) dangerousMacros.pl, (2) PG.pl, or (3) IO.pl. | |
| Modificada | Alta (7.5) | 1.5% | — | JL Webworks Quickblogger | 29/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in acc.php in QuickBlogger (QB) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Alta (7.5) | 9.9% | — | Aewebworks Aedating | 19/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in AEDating 4.1, and possibly earlier versions, allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) inc/design.inc.php or (2) inc/admin_design.inc.php. | |
| Modificada | Media (4.3) | 1.3% | — | Aewebworks Aedating | 28/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in aeDating 4.1 allows remote attackers to inject arbitrary web script or HTML via the (1) Sex parameter in index.php, (2) ProfileType parameter in join_form.php, and (3) Email parameter in forgot.php. | |
| Modificada | Media (6.4) | 1.8% | — | Webwork | 6/6/2006 | 16/6/2026 | Directory traversal vulnerability in PG Problem Editor module (PGProblemEditor.pm) in WeBWorK Online Homework Delivery System 2.2.0 and earlier allows remote attackers to read and write files outside of the templates directory. | |
| Modificada | Alta (7.5) | 1.7% | — | JL Webworks Quickblogger | 14/4/2006 | 16/6/2026 | Directory traversal vulnerability in acc.php in QuickBlogger 1.4 allows remote attackers to read or include arbitrary local files via the request parameter. NOTE: this issue can also produce resultant XSS when the associated include statement fails. | |
| Modificada | Media (6.5) | 3.2% | — | Webwork | 27/1/2006 | 16/6/2026 | Unspecified vulnerability in WeBWorK 2.1.3 and 2.2-pre1 allows remote privileged attackers to execute arbitrary commands as the web server via unknown attack vectors. | |
| Modificada | Media (4.3) | 1.4% | — | JL Webworks Quickblogger | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in QuickBlogger 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) author ("your name") and (2) "comment" section. | |
| Modificada | Alta (7.5) | 1.2% | — | Aewebworks Aedating | 20/9/2005 | 16/6/2026 | SQL injection vulnerability in search_result.php in AEwebworks aeDating Script 4.0 and earlier allows remote attackers to execute arbitrary SQL statements via the Country parameter. | |
| Modificada | Media (5) | 1.1% | — | Aewebworks Aedating | 2/5/2005 | 16/6/2026 | index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Aewebworks Aedating | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter. | |
| Modificada | Media (4.3) | 0.95% | — | Aewebworks AedatingAI | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML. |