Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

392 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.0%—Dotcms14/11/201617/6/2026
SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
ModificadaAlta (8.8)2.0%—Dotcms14/11/201617/6/2026
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
ModificadaAlta (8.8)2.0%—Dotcms14/11/201617/6/2026
SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
ModificadaAlta (8.8)2.0%—Dotcms14/11/201617/6/2026
SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter.
ModificadaAlta (8.8)1.9%—Dotcms14/11/201617/6/2026
SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
ModificadaAlta (8.8)1.9%—Dotcms14/11/201617/6/2026
SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
ModificadaCrítica (9.8)2.8%—Dotcms14/11/201617/6/2026
SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter.
ModificadaAlta (7.2)5.0%—Dotclear10/11/201617/6/2026
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.
ModificadaAlta (7.5)1.8%—Dotcms28/10/201617/6/2026
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
ModificadaMedia (5.4)0.66%—Dnnsoftware Dotnetnuke31/8/201617/6/2026
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.
ModificadaAlta (7.5)2.2%—Dotcms30/6/201617/6/2026
CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headers via CRLF sequences in the subject.
ModificadaAlta (7.2)1.3%—Dotcms19/4/201617/6/2026
SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via the orderby parameter.
ModificadaMedia (6.5)1.6%—Dotcms19/4/201617/6/2026
SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr.
ModificadaBaja (2.7)1.5%—Dotcms18/4/201617/6/2026
Directory traversal vulnerability in the dotTailLogServlet in dotCMS before 3.5.1 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the fileName parameter.
ModificadaMedia (4.8)0.66%—Dotcms18/4/201617/6/2026
Cross-site scripting (XSS) vulnerability in lucene_search.jsp in dotCMS before 3.5.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter to c/portal/layout.
ModificadaMedia (4.3)1.2%—Dotclear3/10/201517/6/2026
Cross-site scripting (XSS) vulnerability in Dotclear before 2.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (3.5)2.4%💥 ExploitMedhabidotcom MDC Private Message2/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the message field in a private message.
ModificadaMedia (4.3)1.8%—Dnnsoftware Dotnetnuke9/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)2.1%💥 ExploitDotproject21/10/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to index.php. NOTE: the…
ModificadaMedia (6.8)0.68%💥 ExploitDotproject20/10/201416/6/2026
Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search_string or (2) where parameter in a contacts action, (3) dept_id parameter in a departments action, (4) project_id[] parameter in a project action, or (5)…
ModificadaMedia (5.4)0.27%—Buydot Funny & Interesting Things20/10/201417/6/2026
The Funny & Interesting Things (aka com.wFunnyandInterestingThings) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.2%—Dotclear22/9/201417/6/2026
Cross-site scripting (XSS) vulnerability in Dotclear before 2.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted page.
ModificadaMedia (5.4)0.28%—Sensysnetworks TrafficdotSensysnetworks Vsn240-fSensysnetworks Vsn240-tSensysnetworks VDS5/9/201417/6/2026
Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, which allows remote attackers to interfere with traffic control by replaying transmissions on a wireless network.
ModificadaAlta (7.6)0.90%—Sensysnetworks TrafficdotSensysnetworks Vsn240-fSensysnetworks Vsn240-tSensysnetworks VDS5/9/201417/6/2026
Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse update.
ModificadaMedia (6)1.2%—Dotclear11/6/201417/6/2026
Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2) .php5, (3) .phtml, or some other PHP file extension.
Orbitaley — Vulnerabilidades