Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.64% | — | Chartered Accountant \ Auditor Website Project | 6/6/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field. | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Crítica (9.8) | 9.5% | — | Apache PdfboxApache JamesFedoraproject FedoraOracle Banking Corporate Lending Process Management+10 | 17/4/2019 | 17/6/2026 | Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF. | |
| Modificada | Media (6.5) | 1.4% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory. | |
| Modificada | Media (6.5) | 1.6% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank profile) via crafted JavaScript code in the First Name and Last Name field. | |
| Modificada | Media (5.4) | 0.65% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field. | |
| Modificada | Crítica (9.8) | 1.5% | — | Frontaccounting | 8/1/2019 | 17/6/2026 | includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow the attacker to grab the entire database of the application via the void_transaction.php filterType parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Frontaccounting | 28/12/2018 | 17/6/2026 | FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application. | |
| Modificada | Alta (7.8) | 19% | 💥 Exploit | Zahiraccounting Zahir Enterprise Plus | 3/10/2018 | 17/6/2026 | Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute arbitrary code via a crafted CSV file that is accessed through the Import CSV File menu. | |
| Modificada | Alta (8.8) | 0.51% | — | Chartered Accountant \ Auditor Website Project | 10/8/2018 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php. | |
| Modificada | Media (6.5) | 3.0% | — | Freedesktop Accountsservice | 13/7/2018 | 17/6/2026 | Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c. | |
| Modificada | Media (6.1) | 1.0% | — | Chartered Accountant \ Auditor Website Project | 9/7/2018 | 17/6/2026 | PHP Scripts Mall Auditor Website 2.0.1 has XSS via the lastname or firstname parameter. | |
| Modificada | Alta (8.8) | 1.3% | — | Debian LinuxLdap-account-manager Ldap Account Manager | 27/3/2018 | 17/6/2026 | Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging. | |
| Modificada | Media (6.1) | 1.5% | — | Debian LinuxLdap-account-manager Ldap Account Manager | 27/3/2018 | 17/6/2026 | Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI. | |
| Modificada | Crítica (9.8) | 1.4% | — | Netiq Privileged Account Manager | 6/3/2018 | 17/6/2026 | PAM exposure enabling unauthenticated access to remote host | |
| Modificada | Media (6.1) | 0.75% | — | Netiq Privileged Account Manager | 5/3/2018 | 17/6/2026 | NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests. | |
| Modificada | Media (6.1) | 0.61% | — | Netiq Privileged Account Manager | 2/3/2018 | 17/6/2026 | NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modification using the supplied cookie parameter. | |
| Modificada | Alta (8.8) | 2.3% | 💥 Exploit | Frontaccounting | 16/2/2018 | 17/6/2026 | FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page). | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Chartered Accountant Booking Script Project Chartered Accountant Booking Script | 13/12/2017 | 17/6/2026 | Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Cloudfoundry Cf-releaseCloudfoundry User Account AND AuthenticationCloudfoundry Uaa-releasePivotal Elastic Runtime | 7/9/2017 | 17/6/2026 | The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations… | |
| Modificada | Alta (8) | 0.81% | — | Samsung Galaxy APPSamsung Account APP | 27/3/2017 | 17/6/2026 | Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code. | |
| Modificada | Alta (8) | 0.68% | — | Samsung Galaxy APPSamsung Account APP | 27/3/2017 | 17/6/2026 | GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.3% | — | SAP Contract Accounting | 6/11/2014 | 17/6/2026 | SQL injection vulnerability in SAP Contract Accounting allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5.4) | 0.27% | — | MY Ngemc Account | 19/10/2014 | 17/6/2026 | The My NGEMC Account (aka com.ngemc.smartapps) application 1.153.0034 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Hkbn MY Account | 16/10/2014 | 17/6/2026 | The HKBN My Account (aka com.hkbn.myaccount) application @7F070015 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |