Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.37% | — | Ibexa Richtext Field TypeAI | 16/8/2024 | 17/6/2026 | Ibexa RichText Field Type is a Field Type for supporting rich formatted text stored in a structured XML format. In versions on the 4.6 branch prior to 4.6.10, the validator for the RichText fieldtype blocklists `javascript:` and `vbscript:` in links to prevent XSS. This can leave other options open, and the check can… | |
| Analizada | Media (6.3) | 0.58% | — | Opentext Directory Services | 12/8/2024 | 3/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1. | |
| Aplazada | Media (5.3) | 0.48% | — | Linkify TextAI | 12/8/2024 | 17/6/2026 | The Linkify Text plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application,… | |
| Analizada | Crítica (9.8) | 0.27% | — | Opentext Arcsight Intelligence | 6/8/2024 | 17/6/2026 | Privilege escalation vulnerability identified in OpenText ArcSight Intelligence. | |
| Analizada | Alta (8.8) | 0.28% | — | Opentext Arcsight Intelligence | 6/8/2024 | 17/6/2026 | Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence. | |
| Analizada | Alta (8.8) | 0.28% | — | Opentext Arcsight Intelligence | 6/8/2024 | 17/6/2026 | Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence. | |
| Analizada | Alta (7.3) | 0.24% | — | Opentext ALM Octane | 5/8/2024 | 17/6/2026 | Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all version prior to version 23.4. The vulnerability could cause remote code execution attack. | |
| Analizada | Baja (2.1) | 0.24% | — | Opentext Filr | 31/7/2024 | 17/6/2026 | Stored XSS vulnerability has been discovered in OpenText™ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when clicking links to external sites. | |
| Aplazada | Alta (7.1) | 0.15% | — | Opentext Documentum ServerAI | 30/7/2024 | 17/6/2026 | Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through 23.4. | |
| Aplazada | Alta (8.3) | 0.57% | — | Opentext Directory ServicesAI | 26/7/2024 | 17/6/2026 | Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular scenarios.This issue affects OpenText Directory Services: 24.2. | |
| Modificada | Media (5.3) | 0.37% | — | Wpchill Optimize Images ALT Text (alt Tag) & Names FOR SEO Using AI | 24/7/2024 | 17/6/2026 | The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.1.1. This is due the plugin utilizing cocur and not preventing direct access to the generate-default.php file. This makes it possible for unauthenticated… | |
| Modificada | Alta (8.8) | 1.9% | — | Sonicwall Netextender | 18/7/2024 | 17/6/2026 | Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC Client update. | |
| Aplazada | Media (6.3) | 0.28% | — | Opentext Netiq Directory AND Resource AdministratorAI | 16/7/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Administrator. This issue affects NetIQ Directory and Resource Administrator versions prior to 10.0.2 and prior to 9.2.1 Patch 10. | |
| Analizada | Media (5.4) | 0.31% | — | Mark8barnes Bible Text | 11/7/2024 | 17/6/2026 | The Bible Text WordPress plugin through 0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.63% | — | Kontextwork Drupal Wiki | 5/7/2024 | 17/6/2026 | drupal-wiki.com Drupal Wiki before 8.31.1 allows XSS via comments, captions, and image titles of a Wiki page. | |
| Modificada | Media (5.4) | 0.30% | — | Wpdeveloper Typing Text | 21/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Typing Text allows Stored XSS.This issue affects Typing Text: from n/a through 1.2.5. | |
| Aplazada | Alta (8.4) | 0.35% | — | Opentext Arcsight LoggerAI | 11/6/2024 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities could be remotely exploited. | |
| Modificada | Media (4.8) | 0.28% | — | Overclokk Stellissimo Text BOX | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Enea Overclokk Stellissimo Text Box allows Stored XSS.This issue affects Stellissimo Text Box: from n/a through 1.1.4. | |
| Aplazada | Media (4.4) | 0.32% | — | Huggingface Text-generation-inferenceAI | 30/5/2024 | 17/6/2026 | A code injection vulnerability exists in the huggingface/text-generation-inference repository, specifically within the `autodocs.yml` workflow file. The vulnerability arises from the insecure handling of the `github.head_ref` user input, which is used to dynamically construct a command for installing a software… | |
| Aplazada | Alta (7.7) | 0.36% | — | Opentext Dimensions RMAI | 23/5/2024 | 17/6/2026 | Arbitrary File Read in OpenText Dimensions RM allows authenticated users to read files stored on the server via webservices | |
| Aplazada | Alta (8.8) | 0.37% | — | Opentext Dimensions RMAI | 23/5/2024 | 17/6/2026 | Privilege Escalation in OpenText Dimensions RM allows an authenticated user to escalate there privilege to the privilege of another user via HTTP Request | |
| Aplazada | Alta (8.7) | 0.35% | — | Opentext Arcsight Enterprise Security ManagerAIOpentext Arcsight PlatformAI | 20/5/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited. | |
| Aplazada | Alta (8.7) | 0.35% | — | Opentext Arcsight Enterprise Security ManagerAIOpentext Arcsight PlatformAI | 20/5/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited. | |
| Aplazada | Alta (7.2) | 0.43% | — | Opentext Operations Bridge ReporterAI | 17/5/2024 | 17/6/2026 | A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL queries. An attack requires to be an authenticated administrator of OBR with network access to the OBR web application. | |
| Aplazada | Alta (8.8) | 0.61% | — | Alttext ALT Text AIAI | 15/5/2024 | 17/6/2026 | The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to generic SQL Injection via the ‘last_post_id’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… |