Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.3%—Neocrome Seditio17/11/201216/6/2026
Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2) docs/upgrade/sedito_convert_to_utf8.optional.sql, or (3) system/install/install.parser.sql.
ModificadaMedia (5)1.2%—Neocrome Seditio17/11/201216/6/2026
Neocrome Seditio build 161 and earlier allows remote attackers to obtain sensitive information via direct request to (1) view.php, (2) plugins/contact/lang/contact.en.lang.php, (3) system/lang/en/main.lang.php, (4) system/lang/en/message.lang.php, or (5) system/core/view/view.inc.php, which reveals the installation…
ModificadaBaja (2.6)1.3%—Neocrome Seditio17/11/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the sed_import function in system/functions.php in Neocrome Seditio build 160 and 161 allow remote attackers to inject arbitrary web script or HTML via the (1) newmsg or (2) rtext parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.6%💥 ExploitOneorzero Action AND Information Management System1/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
ModificadaAlta (7.5)1.3%—Thomas Hunter Neoinvoice26/8/201216/6/2026
SQL injection vulnerability in application/controllers/invoice.php in NeoInvoice might allow remote attackers to execute arbitrary SQL commands via vectors involving the sort_col variable in the list_items function, a different vulnerability than CVE-2012-3477.
ModificadaAlta (7.5)1.2%—Thomas Hunter Neoinvoice26/8/201216/6/2026
SQL injection vulnerability in signup_check.php in NeoInvoice allows remote attackers to execute arbitrary SQL commands via the value parameter in a username action.
ModificadaMedia (5.8)1.3%—Neoaxis WEB Player20/1/201216/6/2026
Directory traversal vulnerability in the web player in NeoAxis NeoAxis web player 1.4 and earlier allows user-assisted remote attackers to write arbitrary files via a .. (dot dot) in a filename in the neoaxis_web_application_win32.zip ZIP archive.
ModificadaAlta (7.5)1.2%💥 ExploitNeojoomla COM Neorecruit1/11/201116/6/2026
SQL injection vulnerability in the NeoRecruit (com_neorecruit) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in an offer_view action to index.php, a different vector than CVE-2007-4506.
ModificadaAlta (7.5)1.3%—Oneorzero Aims1/11/201116/6/2026
SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the cookieName variable.
ModificadaAlta (10)3.1%—Oneorzero Aims1/11/201116/6/2026
OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges via a crafted oozimsrememberme cookie.
ModificadaMedia (4)2.3%💥 ExploitOneorzero Aims14/9/201116/6/2026
Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action.
ModificadaMedia (6.5)0.90%💥 ExploitOneorzero Aims14/9/201116/6/2026
Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types parameter in a show_item_search action in the…
ModificadaAlta (7.5)14%💥 ExploitG4j.laoneo COM Gcalendar16/3/201016/6/2026
Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)2.3%💥 ExploitG4j.laoneo COM Gcalendar29/11/200916/6/2026
SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the gcid parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.2%—Danneo CMS9/9/200916/6/2026
SQL injection vulnerability in mod/poll/comment.php in the vote module in Danneo CMS 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the comtext parameter, in conjunction with crafted comname and comtitle parameters, in a poll action to index.php, related to incorrect input sanitization…
ModificadaMedia (5.8)1.5%—Webdav NeonApple MAC OS XCanonical Ubuntu LinuxFedoraproject Fedora21/8/200916/6/2026
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification…
ModificadaMedia (4.3)8.4%💥 ExploitWebdav Neon21/8/200916/6/2026
neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
ModificadaAlta (7.5)2.3%💥 ExploitNeocrome Seditio24/4/200916/6/2026
SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the c parameter to plug.php.
ModificadaAlta (7.8)9.7%💥 ExploitTP Neostrada Livebox Adsl Router20/3/200916/6/2026
The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTTP requests for the /- URI.
ModificadaMedia (5)6.5%💥 ExploitOneorzero Helpdesk12/3/200916/6/2026
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the default_language parameter.
ModificadaMedia (4.3)2.3%—Webdav Neon27/8/200816/6/2026
neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Digest authentication, Digest domain parameter support, and the parse_domain function.
ModificadaMedia (4.3)1.5%💥 ExploitZoneo-soft Freeforum10/8/200816/6/2026
Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter to (1) the default URI or (2) index.php, or (3) the PATH_INFO to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely…
ModificadaMedia (6.8)0.85%💥 ExploitDanneo CMS25/3/200816/6/2026
SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.
ModificadaAlta (7.5)1.00%💥 ExploitJoomla COM NeogalleryMambo COM Neogallery13/2/200816/6/2026
SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show action.
ModificadaAlta (7.5)0.97%💥 ExploitJoomla COM NeoreferencesMambo COM Neoreferences12/2/200816/6/2026
SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.
Orbitaley — Vulnerabilidades