Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

423 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.3%—Devolutions Remote Desktop Manager27/6/202217/6/2026
Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access credentials of other users. This issue affects: Devolutions Remote Desktop Manager versions prior to 2022.1.8.
ModificadaAlta (7.5)2.0%—Devolutions Remote Desktop Manager21/6/202217/6/2026
A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location.
ModificadaMedia (4.6)0.38%—Devolutions Remote Desktop Manager15/6/202217/6/2026
A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching issue can cause sensitive fields to sometimes stay revealed when closing and reopening a panel, which could lead to involuntarily disclosing sensitive information. This issue…
ModificadaMedia (6.6)0.25%—Devolutions Password HUB3/3/202217/6/2026
The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application because of authentication bypass. An attacker must rapidly make failed biometric authentication attempts.
ModificadaAlta (7.2)9.3%—Modx Revolution26/2/202217/6/2026
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
ModificadaCrítica (9.8)1.9%—B2evolution CMS6/12/202117/6/2026
b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.
ModificadaAlta (8.8)0.55%—B2evolution CMS6/12/202117/6/2026
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.
ModificadaCrítica (9.1)2.4%—Modx Revolution31/10/202117/6/2026
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
ModificadaAlta (8.8)1.8%—Devolutions Remote Desktop Manager18/10/202117/6/2026
An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell.
ModificadaMedia (5.9)0.56%—Gnome Evolution-rss22/8/202117/6/2026
In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
ModificadaMedia (5.4)0.50%—Evolution CMS26/7/202117/6/2026
Cross Site Scripting (XSS) vulnerability in Evolution CMS 2.0.2 via the Document Manager feature.
ModificadaBaja (3.7)0.65%—Devolutions Server12/7/202117/6/2026
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
ModificadaAlta (7.8)1.6%—Gnome EvolutionYtnef Project Ytnef26/5/202116/6/2026
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding…
ModificadaAlta (8.8)5.0%—B2evolution15/4/202117/6/2026
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.
ModificadaAlta (7.2)0.84%—Devolutions Server14/4/202117/6/2026
An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.
ModificadaMedia (6.5)0.57%—Devolutions Server14/4/202117/6/2026
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaMedia (6.1)0.59%—Devolutions Server1/4/202117/6/2026
An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entries of type Document.
ModificadaAlta (7.5)1.00%—Devolutions Server1/4/202117/6/2026
An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.
ModificadaAlta (8.1)0.76%—Devolutions Server1/4/202117/6/2026
An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.
ModificadaMedia (5.4)1.4%—Devolutions Remote Desktop Manager1/4/202117/6/2026
An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vulnerability in webviews.
ModificadaCrítica (9.1)1.00%—Devolutions Server1/4/202117/6/2026
An issue was discovered in Devolutions Server before 2020.3. There is broken access control on Password List entry elements.
ModificadaMedia (5.4)1.2%—Devolutions Remote Desktop Manager1/4/202117/6/2026
Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields.
ModificadaMedia (6.1)4.5%—B2evolution CMS9/2/202117/6/2026
Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.
ModificadaMedia (4.8)3.5%—B2evolution9/2/202117/6/2026
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.
ModificadaMedia (6.1)14%—B2evolution9/2/202117/6/2026
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.