Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

296 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)1.3%—Johnsoncontrols Metasys Application AND Data ServerJohnsoncontrols Metasys Extended Application AND Data ServerJohnsoncontrols Metasys Lonworks Control ServerJohnsoncontrols Metasys Open Application Server+910/3/202017/6/2026
XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Server (ADS, ADS-Lite) versions 10.1 and prior; Metasys Extended Application and Data Server (ADX)…
ModificadaMedia (4.3)0.69%—Jenkins Dynamic Extended Choice Parameter12/2/202017/6/2026
Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
ModificadaAlta (7.2)1.9%—Fortiguard Fortiextender Firmware31/10/201917/6/2026
An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted "execute date" commands.
ModificadaMedia (4.3)0.90%—Admin Management Xtended Project Admin Management Xtended20/9/201917/6/2026
The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.
ModificadaMedia (4.3)0.70%—SAP Hana Extended Application Services10/9/201917/6/2026
Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to enumerate open ports.
ModificadaAlta (7.1)0.90%—SAP Hana Extended Application Services10/9/201917/6/2026
Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to overload the server or retrieve information about internal network ports.
ModificadaMedia (5.7)0.53%—Mijnpress Admin-renamer-extended8/8/201917/6/2026
The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF.
ModificadaMedia (4.3)0.88%—SAP Hana Extended Application Services12/6/201917/6/2026
SAP HANA Extended Application Services (advanced model), version 1, allows authenticated low privileged XS Advanced Platform users such as SpaceAuditors to execute requests to obtain a complete list of SAP HANA user IDs and names.
ModificadaAlta (8.1)0.65%—Eclipse XtendEclipse Xtext6/5/201917/6/2026
All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.
ModificadaMedia (6.5)2.1%—SAP Hana Extended Application Services12/3/201917/6/2026
SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).
ModificadaAlta (7.5)1.8%—SAP Hana Extended Application Services15/2/201917/6/2026
Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though this trace file is protected from unauthorized access, the risk of leaking information is increased.
ModificadaCrítica (9.8)3.0%💥 PoCExtend Project Extend1/2/201917/6/2026
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.
ModificadaCrítica (9.8)1.7%—Dreamerslab Node.extend1/2/201917/6/2026
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
ModificadaCrítica (9.8)1.8%—Just-extend Project Just-extend1/2/201917/6/2026
A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions.
ModificadaMedia (6.6)1.2%—SAP Hana Extended Application Services14/8/201817/6/2026
XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, a platform user could access controller resources via active CLI session even after corresponding authorizations have been…
ModificadaCrítica (9.8)2.1%—Deep Extend Project Deep Extend3/7/201817/6/2026
The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
ModificadaMedia (6.1)1.9%—Nextendweb Nextend Twitter Connect12/4/201817/6/2026
Cross-site scripting (XSS) vulnerability in the new_Twitter_sign_button function in nextend-Twitter-connect.php in the Nextend Twitter Connect plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter. NOTE: this may overlap CVE-2015-4413.
ModificadaMedia (6.1)0.65%—Kubik-rubik Simple Image Gallery Extended5/3/201817/6/2026
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1.
ModificadaAlta (7.1)1.6%—IBM Financial Transaction ManagerIBM Transformation Extender AdvancedIBM Control Center21/2/201817/6/2026
IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker…
ModificadaMedia (6.1)2.2%💥 ExploitKubik-rubik Simple Image Gallery Extended20/2/201817/6/2026
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter.
ModificadaMedia (6.5)0.89%—SAP Hana Extended Application Services14/2/201817/6/2026
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.
ModificadaMedia (6.5)0.85%—SAP Hana Extended Application Services14/2/201817/6/2026
In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumption.
ModificadaMedia (6.5)0.85%—SAP Hana Extended Application Services14/2/201817/6/2026
In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users.
ModificadaAlta (8.1)0.92%—SAP Hana Extended Application Services14/2/201817/6/2026
In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space.
ModificadaAlta (8.1)0.92%—SAP Hana Extended Application Services14/2/201817/6/2026
In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space.