Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
431 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.3% | — | Mozilla NSSDebian LinuxRedhat Enterprise LinuxSuse Linux Enterprise Server+23 | 15/11/2019 | 17/6/2026 | A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Crítica (9.8) | 3.0% | — | Sagemathcell | 18/10/2019 | 17/6/2026 | An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating system, as demonstrated by an __import__('os').popen('whoami').read() line. NOTE:… | |
| Modificada | Alta (8.8) | 1.4% | — | Vernissage Project Vernissage | 10/10/2019 | 17/6/2026 | The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates. | |
| Modificada | Crítica (9.8) | 2.3% | — | Symantec Message Gateway | 11/7/2019 | 17/6/2026 | Symantec Messaging Gateway, prior to 10.7.1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. | |
| Modificada | Media (5.3) | 1.1% | — | Sagemcom F@st 5260 Firmware | 5/3/2019 | 17/6/2026 | Sagemcom F@st 5260 routers using firmware version 0.4.39, in WPA mode, default to using a PSK that is generated from a 2-part wordlist of known values and a nonce with insufficient entropy. The number of possible PSKs is about 1.78 billion, which is too small. | |
| Modificada | Media (5.3) | 2.5% | — | IBM APP ConnectIBM Integration BUSIBM Websphere Message Broker | 4/2/2019 | 17/6/2026 | IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and WebSphere Message Broker V8.0.0.0 through V8.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit… | |
| Modificada | Media (6.1) | 0.69% | — | Barracuda Message Archiver | 23/12/2018 | 17/6/2026 | Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module. | |
| Modificada | Media (5.5) | 0.33% | — | IBM Integration BUSIBM Websphere Message Broker | 26/11/2018 | 17/6/2026 | IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attacker could exploit this vulnerability to modify or delete these files with an unknown impact. IBM X-Force ID: 127406. | |
| Modificada | Media (5.9) | 0.67% | — | Kddi + MessageNtttocomo + MessageSoftbank + MessageNTT Tocomo + Message | 15/11/2018 | 17/6/2026 | Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and… | |
| Modificada | Alta (8.8) | 0.87% | — | Tibco Enterprise Message Service | 6/11/2018 | 17/6/2026 | The Central Administration server (emsca) component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF)… | |
| Modificada | Media (6.5) | 1.0% | — | HP Enhanced Internet Usage Manager | 27/9/2018 | 17/6/2026 | HPE has addressed a remote arbitrary file modification vulnerability in HPE enhanced Internet Usage Manager (eIUM) v9.0FP1 with the cumulative patch for v9.0FP1 - eIUM90FP01XXX.YYYYMMDD-HHMM. | |
| Analizada | Media (5.9) | 1.2% | — | Pivotal Software Spring Advanced Message Queuing ProtocolVmware Rabbitmq Java Client | 14/9/2018 | 17/6/2026 | Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit. | |
| Modificada | Alta (8.8) | 2.1% | — | Sage XRT Treasury | 24/7/2018 | 17/6/2026 | Sage XRT Treasury, version 3, fails to properly restrict database access to authorized users, which may enable any authenticated user to gain full access to privileged database functions. Sage XRT Treasury is a business finance management application. Database user access privileges are determined by the USER_CODE… | |
| Modificada | Alta (8.8) | 2.4% | — | Pybitmessage | 13/3/2018 | 17/6/2026 | Bitmessage PyBitmessage version v0.6.2 (and introduced in or after commit 8ce72d8d2d25973b7064b1cf76a6b0b3d62f0ba0) contains a Eval injection vulnerability in main program, file src/messagetypes/__init__.py function constructObject that can result in Code Execution. This attack appears to be exploitable via remote… | |
| Modificada | Media (6.1) | 0.94% | — | Sophos Puremessage | 26/1/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Sophos PureMessage for UNIX before 6.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 3.7% | 💥 Exploit | Patsatech Sagepay Server Gateway FOR Woocommerce | 9/1/2018 | 17/6/2026 | The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.php page parameter. | |
| Modificada | Crítica (9.8) | 3.6% | — | Pivotal Software Spring Advanced Message Queuing Protocol | 27/11/2017 | 17/6/2026 | In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a remote code execution attack. | |
| Modificada | Crítica (9.8) | 5.1% | — | Pidusage Project Pidusage | 17/11/2017 | 17/6/2026 | soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution | |
| Modificada | Media (5.3) | 1.2% | — | IBM Integration BUSIBM Websphere Message Broker | 4/10/2017 | 17/6/2026 | IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versions that could lead to further attacks. IBM X-Force ID: 121341. | |
| Modificada | Alta (7.8) | 0.47% | — | Fso-frameworkd Project Fso-frameworkdFso-gsmd Project Fso-gsmdFso-usaged Project Fso-usagedPhonefsod Project Phonefsod | 26/9/2017 | 17/6/2026 | The D-Bus security policy files in /etc/dbus-1/system.d/*.conf in fso-gsmd 0.12.0-3, fso-frameworkd 0.9.5.9+git20110512-4, and fso-usaged 0.12.0-2 as packaged in Debian, the upstream cornucopia.git (fsoaudiod, fsodatad, fsodeviced, fsogsmd, fsonetworkd, fsotdld, fsousaged) git master on 2015-01-19, the upstream… | |
| Modificada | Media (4.8) | 3.8% | 💥 Exploit | Wso2 API ManagerWso2 APP ManagerWso2 Application ServerWso2 Business Process Server+13 | 21/9/2017 | 17/6/2026 | WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter. | |
| Modificada | Alta (8.8) | 2.1% | 💥 Exploit | Symantec Message Gateway | 11/8/2017 | 17/6/2026 | The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the web application trusts. A CSRF… | |
| Analizada | Alta (8.8) | 36% | ⚠ Explotación activa💥 Exploit | Symantec Message Gateway | 11/8/2017 | 17/6/2026 | The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the… | |
| Modificada | Baja (2.5) | 0.28% | — | IBM Websphere Message BrokerIBM Integration BUS | 5/7/2017 | 17/6/2026 | IBM WebSphere Message Broker could allow a local user with specialized access to prevent the message broker from starting. IBM X-Force ID: 122033. |