Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 1.3% | — | Johnsoncontrols Metasys Application AND Data ServerJohnsoncontrols Metasys Extended Application AND Data ServerJohnsoncontrols Metasys Lonworks Control ServerJohnsoncontrols Metasys Open Application Server+9 | 10/3/2020 | 17/6/2026 | XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Server (ADS, ADS-Lite) versions 10.1 and prior; Metasys Extended Application and Data Server (ADX)… | |
| Modificada | Media (4.3) | 0.69% | — | Jenkins Dynamic Extended Choice Parameter | 12/2/2020 | 17/6/2026 | Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Alta (7.2) | 1.9% | — | Fortiguard Fortiextender Firmware | 31/10/2019 | 17/6/2026 | An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted "execute date" commands. | |
| Modificada | Media (4.3) | 0.90% | — | Admin Management Xtended Project Admin Management Xtended | 20/9/2019 | 17/6/2026 | The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled. | |
| Modificada | Media (4.3) | 0.70% | — | SAP Hana Extended Application Services | 10/9/2019 | 17/6/2026 | Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to enumerate open ports. | |
| Modificada | Alta (7.1) | 0.90% | — | SAP Hana Extended Application Services | 10/9/2019 | 17/6/2026 | Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to overload the server or retrieve information about internal network ports. | |
| Modificada | Media (5.7) | 0.53% | — | Mijnpress Admin-renamer-extended | 8/8/2019 | 17/6/2026 | The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF. | |
| Modificada | Media (4.3) | 0.88% | — | SAP Hana Extended Application Services | 12/6/2019 | 17/6/2026 | SAP HANA Extended Application Services (advanced model), version 1, allows authenticated low privileged XS Advanced Platform users such as SpaceAuditors to execute requests to obtain a complete list of SAP HANA user IDs and names. | |
| Modificada | Alta (8.1) | 0.65% | — | Eclipse XtendEclipse Xtext | 6/5/2019 | 17/6/2026 | All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised. | |
| Modificada | Media (6.5) | 2.1% | — | SAP Hana Extended Application Services | 12/3/2019 | 17/6/2026 | SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability). | |
| Modificada | Alta (7.5) | 1.8% | — | SAP Hana Extended Application Services | 15/2/2019 | 17/6/2026 | Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though this trace file is protected from unauthorized access, the risk of leaking information is increased. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 PoC | Extend Project Extend | 1/2/2019 | 17/6/2026 | A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype. | |
| Modificada | Crítica (9.8) | 1.7% | — | Dreamerslab Node.extend | 1/2/2019 | 17/6/2026 | A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype. | |
| Modificada | Crítica (9.8) | 1.8% | — | Just-extend Project Just-extend | 1/2/2019 | 17/6/2026 | A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions. | |
| Modificada | Media (6.6) | 1.2% | — | SAP Hana Extended Application Services | 14/8/2018 | 17/6/2026 | XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, a platform user could access controller resources via active CLI session even after corresponding authorizations have been… | |
| Modificada | Crítica (9.8) | 2.1% | — | Deep Extend Project Deep Extend | 3/7/2018 | 17/6/2026 | The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects. | |
| Modificada | Media (6.1) | 1.9% | — | Nextendweb Nextend Twitter Connect | 12/4/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the new_Twitter_sign_button function in nextend-Twitter-connect.php in the Nextend Twitter Connect plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter. NOTE: this may overlap CVE-2015-4413. | |
| Modificada | Media (6.1) | 0.65% | — | Kubik-rubik Simple Image Gallery Extended | 5/3/2018 | 17/6/2026 | The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1. | |
| Modificada | Alta (7.1) | 1.6% | — | IBM Financial Transaction ManagerIBM Transformation Extender AdvancedIBM Control Center | 21/2/2018 | 17/6/2026 | IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker… | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Kubik-rubik Simple Image Gallery Extended | 20/2/2018 | 17/6/2026 | Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter. | |
| Modificada | Media (6.5) | 0.89% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint. | |
| Modificada | Media (6.5) | 0.85% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumption. | |
| Modificada | Media (6.5) | 0.85% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users. | |
| Modificada | Alta (8.1) | 0.92% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space. | |
| Modificada | Alta (8.1) | 0.92% | — | SAP Hana Extended Application Services | 14/2/2018 | 17/6/2026 | In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space. |