Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

332 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)59%💥 ExploitSolarwinds Backup ProfilerSolarwinds Storage ManagerSolarwinds Storage Profiler20/12/201716/6/2026
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.
ModificadaMedia (6.1)1.2%—Cozmoslabs Profile Builder6/10/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter.
ModificadaMedia (6.1)0.89%—Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+4722/5/201717/6/2026
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,…
ModificadaMedia (5.3)1.6%—Miniprofiler Rack-mini-profiler2/5/201717/6/2026
The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks.
ModificadaMedia (4.3)1.1%—UC Profile Project UC Profile17/11/201517/6/2026
The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstances, which might allow remote attackers to obtain sensitive information from the anonymous user profile via unspecified vectors.
ModificadaMedia (4.3)1.7%—HP Smart Profile Server Data Analytics Layer18/10/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in HP Smart Profile Server Data Analytics Layer (SPS DAL) 2.3 before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (3.5)0.95%—Profile2 Privacy Project Profile2 Privacy15/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Profile2 Privacy module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with the "Administer Profile2 Privacy Levels" permission to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4)1.1%—SAP Profile Maintenance30/4/201417/6/2026
SAP Profile Maintenance does not properly restrict access, which allows remote authenticated users to obtain sensitive information via an unspecified RFC function, related to SAP Solution Manager 7.1.
ModificadaAlta (7.8)1.9%—Cisco Telepresence TC SoftwareCisco IP Video Phone E20Cisco Telepresence Codec C40Cisco Telepresence Codec C60+1021/6/201316/6/2026
Cisco TelePresence TC Software before 5.1.7 and TE Software before 4.1.3 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCue01743.
ModificadaMedia (6.3)0.40%—Maynard Johnson Oprofile9/6/201116/6/2026
The do_dump_data function in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to create or overwrite arbitrary files via a crafted --session-dir argument in conjunction with a symlink attack on the opd_pipe file, a different vulnerability than CVE-2011-1760.
ModificadaMedia (6.3)0.54%—Maynard Johnson Oprofile9/6/201116/6/2026
Directory traversal vulnerability in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to overwrite arbitrary files via a .. (dot dot) in the --save argument, related to the --session-dir argument, a different vulnerability than CVE-2011-1760.
ModificadaAlta (7.2)0.48%—Maynard Johnson Oprofile9/6/201116/6/2026
utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to gain privileges via shell metacharacters in the (1) --vmlinux, (2) --session-dir, or (3) --xen argument, related to the daemonrc file and the do_save_setup and do_load_setup functions, a different vulnerability than CVE-2011-1760.
ModificadaAlta (7.2)1.4%💥 ExploitMaynard Johnson Oprofile9/6/201116/6/2026
utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to conduct eval injection attacks and gain privileges via shell metacharacters in the -e argument.
ModificadaAlta (7.5)1.0%💥 ExploitInterlogy Profile Manager28/7/200916/6/2026
Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action.
ModificadaAlta (7.5)1.00%💥 ExploitV3chat V3 Chat Profiles Dating Script31/12/200816/6/2026
SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.
ModificadaCrítica (9.8)7.1%💥 ExploitV3chat V3 Chat Profiles Dating Script31/12/200816/6/2026
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.
ModificadaAlta (7.5)1.0%💥 ExploitE107 Alternate Profiles Plugin29/10/200816/6/2026
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)0.97%💥 ExploitJoomla COM ComprofilerJoomlapolis Community BuilderMambo COM Comprofiler6/5/200816/6/2026
SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action to index.php.
ModificadaMedia (6.8)21%💥 ExploitPhpprofiles27/2/200816/6/2026
PHP remote file inclusion vulnerability in include/body_comm.inc.php in phpProfiles 4.5.2 BETA allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.
ModificadaAlta (7.5)1.0%💥 ExploitJoomla COM ProfileMambo COM Profile20/2/200816/6/2026
SQL injection vulnerability in index.php in the com_profile component for Joomla! allows remote attackers to execute arbitrary SQL commands via the oid parameter.
ModificadaAlta (7.5)1.2%💥 ExploitProfilecms20/11/200716/6/2026
Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) codes action in the profile-codes module, (2) videos action in the video-codes module, or (3) games action in the arcade-games module.
ModificadaMedia (6.8)2.0%💥 ExploitProfilecms30/10/200716/6/2026
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile.
ModificadaMedia (6.8)1.2%—Phpmyprofiler26/9/200716/6/2026
PHP remote file inclusion vulnerability in include/plugin/block.t.php in Peter Schmidt phpmyProfiler 0.9.6b allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter. NOTE: this issue is disputed by CVE because the applicable require_once is in a function that is not called on a…
ModificadaMedia (4.6)0.32%—Phpprofiles26/12/200616/6/2026
phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php.
ModificadaAlta (7.5)9.5%💥 ExploitPhpprofiles26/12/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the menu parameter to (1) include/body.inc.php or (2) include/body_admin.inc.php; or a URL in the incpath parameter to (3) index.inc.php, (4) account.inc.php, (5)…