Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

351 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.98%—Codecrafters Ability Mail Server12/3/201917/6/2026
Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe.
ModificadaAlta (7.2)1.5%—Craftcms Craft CMS25/12/201817/6/2026
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be…
ModificadaMedia (4.8)3.7%💥 ExploitCraftcms Craft CMS24/12/201817/6/2026
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
ModificadaAlta (8.8)1.7%—Craftercms Crafter CMS6/12/201817/6/2026
A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library during rendering of a web page.
ModificadaMedia (6.1)0.68%—Craftedweb Project Craftedweb4/9/201817/6/2026
CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.
ModificadaMedia (6.1)0.71%—Craftedweb Project Craftedweb27/6/201817/6/2026
In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter.
ModificadaAlta (7.5)1.8%—Snapcraft Snapd2/2/201817/6/2026
In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's access restrictions.
ModificadaCrítica (9.8)2.5%—Premium Minecraft Servers List Project Premium Minecraft Servers ListMinecraft Servers List Lite Project Minecraft Servers List Lite23/1/201817/6/2026
install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does not sanitize input before saving database connection information in connect.php, which might allow remote attackers to execute arbitrary PHP code via the (1) database_server, (2) database_user, (3)…
ModificadaAlta (8.8)1.9%—Craftcms Craft CMS1/1/201817/6/2026
Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php extension.
ModificadaMedia (6.1)1.4%💥 ExploitCodecrafters Ability Mail Server20/12/201717/6/2026
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4.
ModificadaCrítica (9.8)2.3%—Formcrafts Formcraft23/8/201717/6/2026
The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.
ModificadaMedia (5.4)2.8%💥 ExploitCraftcms Craft CMS8/6/201717/6/2026
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
ModificadaMedia (5.3)0.96%—Craftcms Craft CMS1/5/201717/6/2026
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
ModificadaMedia (6.1)0.84%—Craftcms Craft CMS1/5/201717/6/2026
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
ModificadaMedia (5.3)1.2%—Craftcms Craft CMS1/5/201717/6/2026
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
ModificadaMedia (6.1)0.83%—Craftcms Craft CMS22/4/201717/6/2026
Craft CMS before 2.6.2974 allows XSS attacks.
ModificadaMedia (5.9)24%💥 ExploitJcraft Jsch19/1/201717/6/2026
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.
ModificadaMedia (4.3)1.9%—Webcrafted Project Webcrafted13/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in /signup in WEBCrafted allows remote attackers to inject arbitrary web script or HTML via the username.
ModificadaMedia (5.4)0.27%—Pocketmags Craft Stamper Magazine19/10/201417/6/2026
The Craft Stamper Magazine (aka com.triactivemedia.craftstamper) application @7F080183 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Magzter Woodcraft Magazine19/10/201417/6/2026
The Woodcraft Magazine (aka com.magzter.woodcraftmagazine) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Mobilecraft Bilgi Yarisi9/9/201417/6/2026
The Bilgi Yarisi (aka net.mobilecraft.bilgiyarisi) application 1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)2.2%💥 ExploitThedigitalcraft Atomcms10/7/201417/6/2026
SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.4%💥 ExploitCode-crafters Ability Mail Server21/12/201317/6/2026
Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email.
ModificadaAlta (7.5)4.8%💥 ExploitNcrafts Formcraft20/12/201317/6/2026
SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (10)7.7%💥 ExploitSkincrafter21/5/201216/6/2026
Buffer overflow in the InitLicenKeys function in a certain ActiveX control in SkinCrafter3_vs2005.dll in SkinCrafter 3.0 allows remote attackers to execute arbitrary code via a long string in the first argument (aka the reg_name argument).
Orbitaley — Vulnerabilidades