Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.53% | — | Artibot | 13/3/2024 | 17/6/2026 | The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Modificada | Media (5) | 0.58% | — | Artibot | 13/3/2024 | 17/6/2026 | The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the artibot_update function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Analizada | Media (6.1) | 0.47% | — | Jfrog Artifactory | 13/3/2024 | 17/6/2026 | JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism. | |
| Analizada | Alta (8.8) | 0.88% | — | Jfrog Artifactory | 7/3/2024 | 17/6/2026 | JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts. | |
| Analizada | Alta (7.5) | 0.44% | — | Jfrog Artifactory | 7/3/2024 | 17/6/2026 | JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data. | |
| Analizada | Media (6.5) | 0.47% | — | Jfrog Artifactory | 7/3/2024 | 17/6/2026 | JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration. | |
| Analizada | Media (4.3) | 0.50% | — | Jenkins Subversion Partial Release Manager | 6/3/2024 | 17/6/2026 | A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build. | |
| Analizada | Media (4.3) | 0.31% | — | Jenkins Subversion Partial Release Manager | 6/3/2024 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger a build. | |
| Analizada | Crítica (9.8) | 17% | — | Articatech Artica Proxy | 5/3/2024 | 17/6/2026 | Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on TCP port 7050. Security issues associated with exposing this… | |
| Analizada | Crítica (9.8) | 0.93% | — | Articatech Artica Proxy | 5/3/2024 | 17/6/2026 | The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user. | |
| Modificada | Crítica (9.6) | 1.5% | 💥 PoC | Martinbarker Rendertune | 29/2/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Upload Title parameter. | |
| Modificada | Baja (3.3) | 0.10% | — | AMD Alveo U50 FirmwareAMD Alveo U200 FirmwareAMD Alveo U250 FirmwareAMD Alveo U280 Firmware+43 | 13/2/2024 | 17/6/2026 | Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bitstreams. | |
| Modificada | Media (4.8) | 0.32% | — | Ays-pro Chartify | 12/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chart Builder Team Chartify – WordPress Chart Plugin allows Stored XSS.This issue affects Chartify – WordPress Chart Plugin: from n/a through 2.0.6. | |
| Modificada | Alta (7.5) | 1.1% | — | Artifex Mupdf | 5/2/2024 | 17/6/2026 | freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function. | |
| Modificada | Alta (7.5) | 1.1% | — | Artifex Mupdf | 5/2/2024 | 17/6/2026 | freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function. | |
| Modificada | Crítica (9.8) | 0.88% | — | Artifex Ghostscript | 4/2/2024 | 17/6/2026 | Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature). | |
| Modificada | Media (5.4) | 0.31% | — | Artiosmedia Product Code FOR Woocommerce | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artios Media Product Code for WooCommerce allows Stored XSS.This issue affects Product Code for WooCommerce: from n/a through 1.4.4. | |
| Modificada | Media (5.4) | 0.56% | — | Martinmbithi Internet Banking System | 22/1/2024 | 17/6/2026 | A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. Affected by this vulnerability is an unknown functionality of the file pages_client_signup.php. The manipulation of the argument Client Full Name leads to cross site scripting. The attack can be launched remotely. The exploit… | |
| Modificada | Crítica (9.8) | 0.92% | — | Artistscope Artisbrowser | 27/12/2023 | 17/6/2026 | An issue in ArtistScope ArtisBrowser v.34.1.5 and before allows an attacker to bypass intended access restrictions via interaction with the com.artis.browser.IntentReceiverActivity component. NOTE: this is disputed by the vendor, who indicates that ArtisBrowser 34 does not support CSS3. | |
| Modificada | Alta (7.5) | 0.71% | — | Artifex Mupdf | 26/12/2023 | 17/6/2026 | A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of jquant2.c. NOTE: this is disputed by the supplier because there was not reasonable evidence to determine the existence of a vulnerability or identify the affected product. | |
| Modificada | Alta (7.5) | 0.71% | — | Artifex Mupdf | 26/12/2023 | 17/6/2026 | A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of load-pnm.c when fz_colorspace_n returns zero. | |
| Modificada | Alta (7.5) | 0.91% | — | Artifex Mupdf | 26/12/2023 | 17/6/2026 | A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c. | |
| Modificada | Alta (7.5) | 0.91% | — | Artifex Mupdf | 26/12/2023 | 17/6/2026 | A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_image() of load-pnm.c when span equals zero. | |
| Modificada | Alta (7.5) | 0.91% | — | Artifex Mupdf | 26/12/2023 | 17/6/2026 | A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_pixmap_from_float_data() of pixmap.c. | |
| Modificada | Media (5.4) | 0.31% | — | Elearningfreak Insert OR Embed Articulate Content | 21/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Batt Insert or Embed Articulate Content into WordPress allows Stored XSS.This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000021. |