Skip to content
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Vulnerabilidades CVE
Vulnerabilidades CVE
drmunozcl
2025-06-04T18:44:58-04:00
Vulnerabilidades CVE
A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:
Severidad:
Todas
NONE
LOW
MEDIUM
HIGH
CRITICAL
UNKNOWN
CVE:
Aplicar
Borrar filtros
CVE ID
Publicado
Severidad
CVSS
Descripción
CVE-2026-63423
2026-08-13
HIGH
7.8
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to…
CVE-2026-61984
2026-08-13
HIGH
7.5
Unauthenticated Broken Access Control in WPMobile.App
CVE-2026-61980
2026-08-13
HIGH
7.5
Unauthenticated Arbitrary File Download in OMGF Pro
CVE-2026-61979
2026-08-13
HIGH
8.1
Unauthenticated Privilege Escalation in SAML SP Single Sign On
CVE-2026-61978
2026-08-13
MEDIUM
6.5
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank)
CVE-2026-61974
2026-08-13
HIGH
7.1
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP
CVE-2026-61969
2026-08-13
CRITICAL
9.3
Unauthenticated SQL Injection in Listdom
CVE-2026-61967
2026-08-13
CRITICAL
9.8
Unauthenticated Privilege Escalation in miniorange otp verification
CVE-2026-61966
2026-08-13
CRITICAL
9.3
Subscriber SQL Injection in WPJAM Basic
CVE-2026-61965
2026-08-13
HIGH
7.1
Unauthenticated Cross Site Scripting (XSS) in GeekyBot
CVE-2026-61962
2026-08-13
CRITICAL
10.0
Unauthenticated Arbitrary Code Execution in WP BASE Booking
CVE-2026-61960
2026-08-13
HIGH
7.1
Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free
CVE-2026-53802
2026-08-13
HIGH
7.1
rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration…
CVE-2026-53798
2026-08-13
MEDIUM
5.3
rsync tbefore 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing…
CVE-2026-53794
2026-08-13
MEDIUM
5.3
rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte…
CVE-2026-53790
2026-08-13
HIGH
8.1
rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment…
CVE-2026-53785
2026-08-13
HIGH
7.1
rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in…
CVE-2026-48702
2026-08-13
HIGH
7.5
Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip…
CVE-2026-28189
2026-08-13
HIGH
7.4
Unauthenticated Arbitrary File Deletion in Participants Database
CVE-2026-28188
2026-08-13
HIGH
7.3
Unauthenticated Broken Access Control in Hydra Booking
CVE-2026-28187
2026-08-13
HIGH
7.1
Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance
CVE-2026-28186
2026-08-13
HIGH
8.1
Subscriber Broken Access Control in Travelfic Toolkit
CVE-2026-28185
2026-08-13
CRITICAL
9.8
Unauthenticated Broken Authentication in Log in with Google
CVE-2026-28182
2026-08-13
MEDIUM
6.5
Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter
CVE-2026-28181
2026-08-13
MEDIUM
6.5
Subscriber Broken Access Control in AcyMailing SMTP Newsletter
CVE-2026-28176
2026-08-13
HIGH
8.8
Unauthenticated PHP Object Injection in Booking Activities
CVE-2026-28175
2026-08-13
HIGH
7.1
Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics
CVE-2026-28174
2026-08-13
MEDIUM
6.5
Customer Sensitive Data Exposure in WP Event SOlution
CVE-2026-28173
2026-08-13
HIGH
7.1
Customer Arbitrary Content Deletion in WP Event SOlution
CVE-2026-28170
2026-08-13
HIGH
7.1
Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button
CVE-2026-28168
2026-08-13
HIGH
8.5
Subscriber SQL Injection in CubeWP
CVE-2026-28161
2026-08-13
HIGH
8.8
Subscriber Privilege Escalation in Service Finder Booking
CVE-2026-28159
2026-08-13
MEDIUM
6.5
Subscriber Broken Access Control in Service Finder Booking
CVE-2026-28158
2026-08-13
HIGH
7.1
Unauthenticated Cross Site Scripting (XSS) in Do Lasso
CVE-2026-28157
2026-08-13
HIGH
7.5
Subscriber Path Traversal in Do Lasso
CVE-2026-28156
2026-08-13
HIGH
8.5
Subscriber SQL Injection in Do Lasso
CVE-2026-28155
2026-08-13
MEDIUM
6.5
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso
CVE-2026-28149
2026-08-13
CRITICAL
9.8
Unauthenticated PHP Object Injection in Headless Single Sign On
CVE-2026-28148
2026-08-13
CRITICAL
9.8
Unauthenticated Bypass Vulnerability in Headless Single Sign On
CVE-2026-28142
2026-08-13
CRITICAL
9.3
Unauthenticated SQL Injection in Web Directory Free
CVE-2026-28008
2026-08-13
CRITICAL
9.8
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client)
CVE-2026-28004
2026-08-13
HIGH
7.1
Unauthenticated Cross Site Scripting (XSS) in Business Directory
CVE-2026-28003
2026-08-13
HIGH
7.1
Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist
CVE-2026-28002
2026-08-13
HIGH
8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22.
CVE-2026-28001
2026-08-13
CRITICAL
9.3
Unauthenticated SQL Injection in WP Directory Kit
CVE-2026-27999
2026-08-13
MEDIUM
6.5
Subscriber Broken Access Control in Tourfic
CVE-2026-27544
2026-08-13
CRITICAL
10.0
Unauthenticated Remote Code Execution (RCE) in QA Analytics
CVE-2026-27543
2026-08-13
HIGH
8.1
Unauthenticated Privilege Escalation in MStore API
CVE-2026-27539
2026-08-13
HIGH
7.1
Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce
CVE-2026-27538
2026-08-13
HIGH
7.5
Unauthenticated SQL Injection in WP Directory Kit
« Anterior
Página 32 de 4837
Siguiente »
Page load link
Go to Top