Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

823 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.38%—Monospace Directus15/8/202417/6/2026
Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible because the application injects an attacker-controlled parameter that will be stored in the server and used by the client into an unsanitized DOM element. When chained with CVE-2024-6534, it…
AnalizadaCrítica (9.1)0.43%—IBM Planning Analytics WorkspaceIBM Planning Analytics Local4/8/202417/6/2026
IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 292420.
ModificadaMedia (6.4)0.21%—Wpthemespace Magical Addons FOR Elementor22/7/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor.This issue affects Magical Addons For Elementor: from n/a through 1.1.41.
AplazadaMedia (5.9)0.27%—Bracketspace Simple Post NotesAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BracketSpace Simple Post Notes allows Stored XSS.This issue affects Simple Post Notes: from n/a through 1.7.7.
AnalizadaMedia (5.4)0.32%—Wpthemespace Magical Addons FOR Elementor20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.1.41.
ModificadaCrítica (9.8)0.68%—Space Management System Project Space Management System15/7/202417/6/2026
AguardNet's Space Management System does not properly validate user input, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
ModificadaMedia (5.4)0.29%—Space Management System Project Space Management System15/7/202417/6/2026
AguardNet Technology's Space Management System does not properly filter user input, allowing remote attackers with regular privileges to inject JavaScript and perform Reflected Cross-site scripting attacks.
AnalizadaAlta (8.5)0.39%—Citrix Workspace10/7/202417/6/2026
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
AnalizadaMedia (4.8)0.22%—Citrix Workspace10/7/202417/6/2026
Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
ModificadaMedia (5.3)0.40%—Citrix Workspace10/7/202417/6/2026
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
AnalizadaMedia (5.3)0.51%—Monospace Directus8/7/202417/6/2026
Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combination with local authentication it can be possible to enumerate existing SSO users in the instance. This is possible because if an email address exists in Directus and belongs to a known SSO provider…
AnalizadaMedia (6.5)0.80%—Monospace Directus8/7/202417/6/2026
Directus is a real-time API and App dashboard for managing SQL database content. A denial of service (DoS) attack by field duplication in GraphQL is a type of attack where an attacker exploits the flexibility of GraphQL to overwhelm a server by requesting the same field multiple times in a single query. This can cause…
AnalizadaAlta (7.7)0.42%—Monospace Directus8/7/202417/6/2026
Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly handles _in, _nin operators. It evaluates empty arrays as valid so expressions like {"role": {"_in": $CURRENT_USER.some_field}} would evaluate to true allowing the request to pass. This results in…
ModificadaMedia (5)0.43%—Monospace Directus8/7/202417/6/2026
Directus is a real-time API and App dashboard for managing SQL database content. There was already a reported SSRF vulnerability via file import. It was fixed by resolving all DNS names and checking if the requested IP is an internal IP address. However it is possible to bypass this security measure and execute a SSRF…
ModificadaAlta (7.8)0.30%—KDE Plasma-workspace5/7/202417/6/2026
KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local connections are accepted. This allows another user on the same machine to gain access to the session manager, e.g., use the session-restore feature to…
AplazadaMedia (6.8)0.36%—Vmware Workspace ONE UEMAI27/6/202417/6/2026
VMware Workspace One UEM update addresses an information exposure vulnerability. A malicious actor with network access to the Workspace One UEM may be able to perform an attack resulting in an information exposure.
AplazadaBaja (2.6)0.39%—DspaceAI26/6/202417/6/2026
DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institutions worldwide to provide durable access to digital resources. In DSpace 7.0 through 7.6.1, when an HTML, XML or JavaScript Bitstream is downloaded, the user's browser may execute any embedded…
ModificadaMedia (6.4)0.11%—Schneider-electric Spacelogic As-b FirmwareSchneider-electric Spacelogic As-p Firmware12/6/202417/6/2026
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account.
ModificadaMedia (4.5)0.23%—Schneider-electric Spacelogic As-b FirmwareSchneider-electric Spacelogic As-p Firmware12/6/202417/6/2026
CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller logs.
ModificadaMedia (5.4)0.31%—Wpthemespace Magical Addons FOR Elementor6/6/202417/6/2026
The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, 1.1.39 due to insufficient input sanitization and output escaping. This makes…
AnalizadaAlta (7.5)0.62%—Monospace Directus3/6/202417/6/2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.2, providing a non-numeric length value to the random string generation utility will create a memory issue breaking the capability to generate random strings platform wide. This creates a denial of service situation where…
AnalizadaMedia (5.4)0.45%—Monospace Directus14/5/202417/6/2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens function like the other JWT tokens where they are not actually invalidated when logging out. The `directus_session` gets destroyed and the cookie gets deleted but if the cookie value is captured, it will…
AnalizadaMedia (4.9)0.76%—Monospace Directus14/5/202417/6/2026
Directus is a real-time API and App dashboard for managing SQL database content. A user with permission to view any collection using redacted hashed fields can get access the raw stored version using the `alias` functionality on the API. Normally, these redacted fields will return `**********` however if we change the…
AplazadaAlta (8.2)0.73%—Go-spacemeshAISpacemesh APIAI14/5/202417/6/2026
go-spacemesh is a Go implementation of the Spacemesh protocol full node. Nodes can publish activations transactions (ATXs) which reference the incorrect previous ATX of the Smesher that created the ATX. ATXs are expected to form a single chain from the newest to the first ATX ever published by an identity. Allowing…
ModificadaMedia (5.4)0.27%—Wpthemespace Magical Addons FOR Elementor14/5/202417/6/2026
The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including, 1.1.37 due to insufficient input sanitization and output escaping…