Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
351 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.98% | — | Codecrafters Ability Mail Server | 12/3/2019 | 17/6/2026 | Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe. | |
| Modificada | Alta (7.2) | 1.5% | — | Craftcms Craft CMS | 25/12/2018 | 17/6/2026 | Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be… | |
| Modificada | Media (4.8) | 3.7% | 💥 Exploit | Craftcms Craft CMS | 24/12/2018 | 17/6/2026 | index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab. | |
| Modificada | Alta (8.8) | 1.7% | — | Craftercms Crafter CMS | 6/12/2018 | 17/6/2026 | A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library during rendering of a web page. | |
| Modificada | Media (6.1) | 0.68% | — | Craftedweb Project Craftedweb | 4/9/2018 | 17/6/2026 | CraftedWeb through 2013-09-24 has reflected XSS via the p parameter. | |
| Modificada | Media (6.1) | 0.71% | — | Craftedweb Project Craftedweb | 27/6/2018 | 17/6/2026 | In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Snapcraft Snapd | 2/2/2018 | 17/6/2026 | In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's access restrictions. | |
| Modificada | Crítica (9.8) | 2.5% | — | Premium Minecraft Servers List Project Premium Minecraft Servers ListMinecraft Servers List Lite Project Minecraft Servers List Lite | 23/1/2018 | 17/6/2026 | install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does not sanitize input before saving database connection information in connect.php, which might allow remote attackers to execute arbitrary PHP code via the (1) database_server, (2) database_user, (3)… | |
| Modificada | Alta (8.8) | 1.9% | — | Craftcms Craft CMS | 1/1/2018 | 17/6/2026 | Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php extension. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Codecrafters Ability Mail Server | 20/12/2017 | 17/6/2026 | Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4. | |
| Modificada | Crítica (9.8) | 2.3% | — | Formcrafts Formcraft | 23/8/2017 | 17/6/2026 | The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php. | |
| Modificada | Media (5.4) | 2.8% | 💥 Exploit | Craftcms Craft CMS | 8/6/2017 | 17/6/2026 | Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file. | |
| Modificada | Media (5.3) | 0.96% | — | Craftcms Craft CMS | 1/5/2017 | 17/6/2026 | Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message. | |
| Modificada | Media (6.1) | 0.84% | — | Craftcms Craft CMS | 1/5/2017 | 17/6/2026 | Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052. | |
| Modificada | Media (5.3) | 1.2% | — | Craftcms Craft CMS | 1/5/2017 | 17/6/2026 | Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder. | |
| Modificada | Media (6.1) | 0.83% | — | Craftcms Craft CMS | 22/4/2017 | 17/6/2026 | Craft CMS before 2.6.2974 allows XSS attacks. | |
| Modificada | Media (5.9) | 24% | 💥 Exploit | Jcraft Jsch | 19/1/2017 | 17/6/2026 | Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command. | |
| Modificada | Media (4.3) | 1.9% | — | Webcrafted Project Webcrafted | 13/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in /signup in WEBCrafted allows remote attackers to inject arbitrary web script or HTML via the username. | |
| Modificada | Media (5.4) | 0.27% | — | Pocketmags Craft Stamper Magazine | 19/10/2014 | 17/6/2026 | The Craft Stamper Magazine (aka com.triactivemedia.craftstamper) application @7F080183 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Magzter Woodcraft Magazine | 19/10/2014 | 17/6/2026 | The Woodcraft Magazine (aka com.magzter.woodcraftmagazine) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Mobilecraft Bilgi Yarisi | 9/9/2014 | 17/6/2026 | The Bilgi Yarisi (aka net.mobilecraft.bilgiyarisi) application 1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Thedigitalcraft Atomcms | 10/7/2014 | 17/6/2026 | SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Code-crafters Ability Mail Server | 21/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email. | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | Ncrafts Formcraft | 20/12/2013 | 17/6/2026 | SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (10) | 7.7% | 💥 Exploit | Skincrafter | 21/5/2012 | 16/6/2026 | Buffer overflow in the InitLicenKeys function in a certain ActiveX control in SkinCrafter3_vs2005.dll in SkinCrafter 3.0 allows remote attackers to execute arbitrary code via a long string in the first argument (aka the reg_name argument). |