Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.0% | — | Dotcms | 14/11/2016 | 17/6/2026 | SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter. | |
| Modificada | Alta (8.8) | 2.0% | — | Dotcms | 14/11/2016 | 17/6/2026 | SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter. | |
| Modificada | Alta (8.8) | 2.0% | — | Dotcms | 14/11/2016 | 17/6/2026 | SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter. | |
| Modificada | Alta (8.8) | 2.0% | — | Dotcms | 14/11/2016 | 17/6/2026 | SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter. | |
| Modificada | Alta (8.8) | 1.9% | — | Dotcms | 14/11/2016 | 17/6/2026 | SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter. | |
| Modificada | Alta (8.8) | 1.9% | — | Dotcms | 14/11/2016 | 17/6/2026 | SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter. | |
| Modificada | Crítica (9.8) | 2.8% | — | Dotcms | 14/11/2016 | 17/6/2026 | SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter. | |
| Modificada | Alta (7.2) | 5.0% | — | Dotclear | 10/11/2016 | 17/6/2026 | Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.8% | — | Dotcms | 28/10/2016 | 17/6/2026 | In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later. | |
| Modificada | Media (5.4) | 0.66% | — | Dnnsoftware Dotnetnuke | 31/8/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element. | |
| Modificada | Alta (7.5) | 2.2% | — | Dotcms | 30/6/2016 | 17/6/2026 | CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headers via CRLF sequences in the subject. | |
| Modificada | Alta (7.2) | 1.3% | — | Dotcms | 19/4/2016 | 17/6/2026 | SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via the orderby parameter. | |
| Modificada | Media (6.5) | 1.6% | — | Dotcms | 19/4/2016 | 17/6/2026 | SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr. | |
| Modificada | Baja (2.7) | 1.5% | — | Dotcms | 18/4/2016 | 17/6/2026 | Directory traversal vulnerability in the dotTailLogServlet in dotCMS before 3.5.1 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the fileName parameter. | |
| Modificada | Media (4.8) | 0.66% | — | Dotcms | 18/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in lucene_search.jsp in dotCMS before 3.5.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter to c/portal/layout. | |
| Modificada | Media (4.3) | 1.2% | — | Dotclear | 3/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Dotclear before 2.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.5) | 2.4% | 💥 Exploit | Medhabidotcom MDC Private Message | 2/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the message field in a private message. | |
| Modificada | Media (4.3) | 1.8% | — | Dnnsoftware Dotnetnuke | 9/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Dotproject | 21/10/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to index.php. NOTE: the… | |
| Modificada | Media (6.8) | 0.68% | 💥 Exploit | Dotproject | 20/10/2014 | 16/6/2026 | Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search_string or (2) where parameter in a contacts action, (3) dept_id parameter in a departments action, (4) project_id[] parameter in a project action, or (5)… | |
| Modificada | Media (5.4) | 0.27% | — | Buydot Funny & Interesting Things | 20/10/2014 | 17/6/2026 | The Funny & Interesting Things (aka com.wFunnyandInterestingThings) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.2% | — | Dotclear | 22/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Dotclear before 2.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted page. | |
| Modificada | Media (5.4) | 0.28% | — | Sensysnetworks TrafficdotSensysnetworks Vsn240-fSensysnetworks Vsn240-tSensysnetworks VDS | 5/9/2014 | 17/6/2026 | Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, which allows remote attackers to interfere with traffic control by replaying transmissions on a wireless network. | |
| Modificada | Alta (7.6) | 0.90% | — | Sensysnetworks TrafficdotSensysnetworks Vsn240-fSensysnetworks Vsn240-tSensysnetworks VDS | 5/9/2014 | 17/6/2026 | Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse update. | |
| Modificada | Media (6) | 1.2% | — | Dotclear | 11/6/2014 | 17/6/2026 | Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2) .php5, (3) .phtml, or some other PHP file extension. |