Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 4.5% | — | B2evolution CMS | 9/2/2021 | 17/6/2026 | Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter. | |
| Modificada | Media (4.8) | 3.5% | — | B2evolution | 9/2/2021 | 17/6/2026 | Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module. | |
| Modificada | Media (6.1) | 14% | — | B2evolution | 9/2/2021 | 17/6/2026 | Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php. | |
| Modificada | Baja (3.3) | 0.35% | — | Gnome Evolution | 1/2/2021 | 17/6/2026 | GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this… | |
| Modificada | Alta (7) | 0.34% | — | Devolutions Gfwx | 26/1/2021 | 17/6/2026 | An issue was discovered in the gfwx crate before 0.3.0 for Rust. Because ImageChunkMut does not have bounds on its Send trait or Sync trait, a data race and memory corruption can occur. | |
| Modificada | Crítica (9.8) | 1.5% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Alta (7.5) | 1.3% | — | Evolutionscript Helpdeskz | 12/10/2020 | 17/6/2026 | An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone to SQL injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Modificada | Crítica (9.6) | 1.2% | — | Freebox Revolution FirmwareFreebox Mini FirmwareFreebox ONE FirmwareFreebox Delta Firmware+1 | 16/9/2020 | 17/6/2026 | A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3. | |
| Modificada | Crítica (9.6) | 1.00% | — | Freebox Revolution FirmwareFreebox Mini FirmwareFreebox ONE FirmwareFreebox Delta Firmware+1 | 16/9/2020 | 17/6/2026 | A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3. | |
| Modificada | Alta (8.8) | 0.53% | — | Freebox Revolution FirmwareFreebox Mini FirmwareFreebox ONE FirmwareFreebox Delta Firmware+1 | 16/9/2020 | 17/6/2026 | A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3. | |
| Modificada | Media (5.9) | 2.1% | — | Gnome Evolution-data-serverDebian Linux | 29/7/2020 | 17/6/2026 | In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and imapx_connect_to_server. | |
| Modificada | Media (5.9) | 2.8% | — | Gnome Evolution-data-serverDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 17/7/2020 | 17/6/2026 | evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection." | |
| Modificada | Media (6.5) | 2.8% | — | Gnome Evolution | 17/4/2020 | 17/6/2026 | An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an… | |
| Modificada | Alta (7.5) | 1.9% | — | Gnome EvolutionGnome Evolution Data ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 6/2/2020 | 16/6/2026 | The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain… | |
| Modificada | Alta (7.3) | 0.78% | — | Gnome Evolution-data-server3 | 25/11/2019 | 16/6/2026 | evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials of the victim. | |
| Modificada | Media (6.1) | 0.98% | — | Agentevolution Impress Listings | 20/9/2019 | 17/6/2026 | The wp-listings plugin before 2.0.2 for WordPress has includes/views/single-listing.php XSS. | |
| Modificada | Media (5.4) | 1.2% | — | Modx Evolution CMS | 15/8/2019 | 17/6/2026 | Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel. | |
| Modificada | Alta (8.1) | 0.99% | — | Gnome Evolution-ewsRedhat Enterprise Linux | 1/8/2019 | 17/6/2026 | It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server without the user noticing the difference. | |
| Modificada | Alta (7.5) | 1.2% | — | Modx Revolution | 23/7/2019 | 17/6/2026 | MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and content. The component is: Filtering user parameters before passing them into phpthumb class. The attack vector is: web request via… | |
| Modificada | Crítica (9.8) | 2.4% | — | B2evolution | 23/5/2019 | 17/6/2026 | b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php. | |
| Modificada | Media (6.5) | 2.4% | — | Gnome EvolutionDebian Linux | 11/2/2019 | 17/6/2026 | GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment. | |
| Modificada | Media (5.4) | 0.61% | — | Modx Revolution | 6/2/2019 | 17/6/2026 | MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description. | |
| Modificada | Media (6.1) | 0.86% | — | Modx Revolution | 6/2/2019 | 17/6/2026 | MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name. | |
| Modificada | Media (6.1) | 0.86% | — | Modx Revolution | 6/2/2019 | 17/6/2026 | MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs. |