Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
423 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.3% | — | Devolutions Remote Desktop Manager | 27/6/2022 | 17/6/2026 | Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access credentials of other users. This issue affects: Devolutions Remote Desktop Manager versions prior to 2022.1.8. | |
| Modificada | Alta (7.5) | 2.0% | — | Devolutions Remote Desktop Manager | 21/6/2022 | 17/6/2026 | A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location. | |
| Modificada | Media (4.6) | 0.38% | — | Devolutions Remote Desktop Manager | 15/6/2022 | 17/6/2026 | A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching issue can cause sensitive fields to sometimes stay revealed when closing and reopening a panel, which could lead to involuntarily disclosing sensitive information. This issue… | |
| Modificada | Media (6.6) | 0.25% | — | Devolutions Password HUB | 3/3/2022 | 17/6/2026 | The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application because of authentication bypass. An attacker must rapidly make failed biometric authentication attempts. | |
| Modificada | Alta (7.2) | 9.3% | — | Modx Revolution | 26/2/2022 | 17/6/2026 | MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator. | |
| Modificada | Crítica (9.8) | 1.9% | — | B2evolution CMS | 6/12/2021 | 17/6/2026 | b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input. | |
| Modificada | Alta (8.8) | 0.55% | — | B2evolution CMS | 6/12/2021 | 17/6/2026 | b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges. | |
| Modificada | Crítica (9.1) | 2.4% | — | Modx Revolution | 31/10/2021 | 17/6/2026 | A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS). | |
| Modificada | Alta (8.8) | 1.8% | — | Devolutions Remote Desktop Manager | 18/10/2021 | 17/6/2026 | An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell. | |
| Modificada | Media (5.9) | 0.56% | — | Gnome Evolution-rss | 22/8/2021 | 17/6/2026 | In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011. | |
| Modificada | Media (5.4) | 0.50% | — | Evolution CMS | 26/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Evolution CMS 2.0.2 via the Document Manager feature. | |
| Modificada | Baja (3.7) | 0.65% | — | Devolutions Server | 12/7/2021 | 17/6/2026 | Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext). | |
| Modificada | Alta (7.8) | 1.6% | — | Gnome EvolutionYtnef Project Ytnef | 26/5/2021 | 16/6/2026 | Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding… | |
| Modificada | Alta (8.8) | 5.0% | — | B2evolution | 15/4/2021 | 17/6/2026 | SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab. | |
| Modificada | Alta (7.2) | 0.84% | — | Devolutions Server | 14/4/2021 | 17/6/2026 | An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete. | |
| Modificada | Media (6.5) | 0.57% | — | Devolutions Server | 14/4/2021 | 17/6/2026 | An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (6.1) | 0.59% | — | Devolutions Server | 1/4/2021 | 17/6/2026 | An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entries of type Document. | |
| Modificada | Alta (7.5) | 1.00% | — | Devolutions Server | 1/4/2021 | 17/6/2026 | An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files. | |
| Modificada | Alta (8.1) | 0.76% | — | Devolutions Server | 1/4/2021 | 17/6/2026 | An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users. | |
| Modificada | Media (5.4) | 1.4% | — | Devolutions Remote Desktop Manager | 1/4/2021 | 17/6/2026 | An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vulnerability in webviews. | |
| Modificada | Crítica (9.1) | 1.00% | — | Devolutions Server | 1/4/2021 | 17/6/2026 | An issue was discovered in Devolutions Server before 2020.3. There is broken access control on Password List entry elements. | |
| Modificada | Media (5.4) | 1.2% | — | Devolutions Remote Desktop Manager | 1/4/2021 | 17/6/2026 | Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields. | |
| Modificada | Media (6.1) | 4.5% | — | B2evolution CMS | 9/2/2021 | 17/6/2026 | Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter. | |
| Modificada | Media (4.8) | 3.5% | — | B2evolution | 9/2/2021 | 17/6/2026 | Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module. | |
| Modificada | Media (6.1) | 14% | — | B2evolution | 9/2/2021 | 17/6/2026 | Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php. |