Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

426 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.86%—Modx Revolution6/2/201917/6/2026
MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.
ModificadaMedia (5.4)0.57%—Modx Evolution CMS28/12/201817/6/2026
Evolution CMS 1.4.x allows XSS via the manager/ search parameter.
ModificadaMedia (5.4)0.57%—Modx Evolution CMS28/12/201817/6/2026
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
ModificadaAlta (8.8)1.5%—Logisim-evolution Project Logisim-evolution28/12/201817/6/2026
Logisim Evolution version 2.14.3 and earlier contains an XML External Entity (XXE) vulnerability in Circuit file loading functionality (loadXmlFrom in src/com/cburch/logisim/file/XmlReader.java) that can result in information leak, possible RCE depending on system configuration. This attack appears to be exploitable…
ModificadaMedia (5.4)0.59%—Modx Revolution26/9/201817/6/2026
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
ModificadaCrítica (9.8)2.9%—Canonical Ubuntu LinuxGnome Evolution20/7/201817/6/2026
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by…
ModificadaAlta (7.5)1.9%—Modx Revolution13/7/201817/6/2026
MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result in remove files. This attack appear to be exploitable via web request via security/login processor. This vulnerability appears to have been fixed in pull 13980.
ModificadaAlta (7.2)64%—Modx Revolution13/7/201817/6/2026
MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content. This attack appear to be exploitable via Web request. This vulnerability appears to have been fixed…
ModificadaAlta (7.8)1.2%—Loboevolution Project Loboevolution26/6/201817/6/2026
LoboEvolution version < 9b75694cedfa4825d4a2330abf2719d470c654cd contains a XML External Entity (XXE) vulnerability in XML Parsing when viewing the XML file in the browser that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via…
ModificadaCrítica (9.8)1.8%—Gnome Evolution15/6/201817/6/2026
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function. NOTE: the software maintainer disputes this because "the code had computed the required string length…
ModificadaMedia (5.4)0.66%—Modx Revolution1/6/201817/6/2026
MODX Revolution 2.6.3 has XSS.
ModificadaMedia (5.9)4.1%—9folders NineApple MailBloop AirmailEmclient+1316/5/201817/6/2026
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
ModificadaCrítica (9.8)2.4%—B2evolution2/1/201817/6/2026
b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.
ModificadaMedia (5.4)0.50%—Modx Revolution17/11/201717/6/2026
A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier. An authenticated user with permissions to edit users can save malicious JavaScript as a User Group name and potentially take control over victims' accounts. This can lead to an escalation of…
ModificadaMedia (6.1)1.2%—Modx Revolution29/8/201717/6/2026
Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.
ModificadaMedia (6.1)0.60%—Modx Revolution30/7/201717/6/2026
In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors/index.php will be triggered by every user, when they visit this module.
ModificadaAlta (8.8)1.1%—Modx Revolution17/7/201717/6/2026
MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges.
ModificadaMedia (4.7)0.65%—Modx Revolution18/5/201717/6/2026
In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning.
ModificadaMedia (5.4)0.56%—Modx Revolution18/5/201717/6/2026
In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.
ModificadaAlta (8.8)1.9%—Modx Revolution18/5/201717/6/2026
In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.
ModificadaMedia (6.1)0.69%—Modx Revolution18/5/201717/6/2026
In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.
ModificadaAlta (7)0.82%—Modx RevolutionPHP18/5/201717/6/2026
In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.
ModificadaMedia (5.3)2.7%—Modx Revolution25/4/201717/6/2026
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to obtain system directory information.
ModificadaCrítica (9.8)2.2%—Modx Revolution30/3/201717/6/2026
setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path parameter.
ModificadaAlta (8.1)2.1%—Modx Revolution30/3/201717/6/2026
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code by leveraging the lack of the HTTPS protection mechanism.