Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.38% | — | Opentext Appbuilder | 29/1/2024 | 17/6/2026 | Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder configuration files are viewable by unauthenticated users. This issue affects AppBuilder: from 21.2 before 23.2. | |
| Modificada | Alta (7.1) | 0.37% | — | Opentext Appbuilder | 29/1/2024 | 17/6/2026 | Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenticated AppBuilder user with the ability to create or manage existing databases can leverage them to exploit the AppBuilder server - including access to its local file system. This issue affects… | |
| Modificada | Alta (8.8) | 1.0% | — | Opentext Appbuilder | 29/1/2024 | 17/6/2026 | Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBuilder's Scheduler functionality that facilitates creation of scheduled tasks is vulnerable to command injection. This allows authenticated users to inject arbitrary operating system commands into the… | |
| Modificada | Alta (7.5) | 0.47% | — | Opentext Appbuilder | 29/1/2024 | 17/6/2026 | Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An unauthenticated or authenticated user can abuse a page of AppBuilder to read arbitrary files on the server on which it is hosted. This issue affects… | |
| Modificada | Media (5.5) | 0.21% | — | Sonicwall Capture ClientSonicwall Netextender | 18/1/2024 | 17/6/2026 | SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability. | |
| Modificada | Alta (8.8) | 0.61% | — | Jorisvm JVM Gutenberg Rich Text Icons | 29/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Joris van Montfort JVM Gutenberg Rich Text Icons.This issue affects JVM Gutenberg Rich Text Icons: from n/a through 1.2.3. | |
| Modificada | Alta (8.8) | 0.81% | — | Textpattern | 28/12/2023 | 17/6/2026 | There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions. | |
| Modificada | Alta (8.8) | 0.29% | — | Codeastrology ADD TO Cart Text Changer AND Customize Button, ADD Custom Icon | 18/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saiful Islam Add to Cart Text Changer and Customize Button, Add Custom Icon.This issue affects Add to Cart Text Changer and Customize Button, Add Custom Icon: from n/a through 2.0. | |
| Modificada | Media (6.5) | 0.94% | — | Itextpdf Itext | 26/11/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Apryse iText 8.0.1. This issue affects some unknown processing of the file PdfDocument.java of the component Reference Table Handler. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.5) | 1.1% | — | Itextpdf Itext | 26/11/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Apryse iText 8.0.2. This vulnerability affects the function main of the file PdfDocument.java. The manipulation leads to improper validation of array index. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Alta (8.8) | 0.21% | — | Zixn Original Texts Yandex Webmaster | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Djo Original texts Yandex WebMaster plugin <= 1.18 versions. | |
| Modificada | Media (6.5) | 0.79% | — | Gopiplus WP Photo Text Slider 50 | 31/10/2023 | 17/6/2026 | The Wp photo text slider 50 plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers… | |
| Modificada | Media (6.5) | 0.79% | — | Gopiplus WP Fade IN Text News | 31/10/2023 | 17/6/2026 | The WP fade in text news plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers… | |
| Modificada | Media (5.4) | 0.52% | — | Eralion Neon Text | 27/10/2023 | 17/6/2026 | The Neon text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's neontext_box shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes (color). This makes it possible for authenticated attackers with… | |
| Modificada | Alta (7.3) | 0.29% | — | Sonicwall Netextender | 27/10/2023 | 17/6/2026 | SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-up DLL component. Successful exploitation via a local attacker could result in command execution in the target system. | |
| Modificada | Media (5.4) | 0.43% | — | Halgatewood Reusable Text Blocks | 25/10/2023 | 17/6/2026 | The Reusable Text Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text-blocks' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with author-level and… | |
| Modificada | Alta (7.8) | 0.21% | — | Sonicwall Netextender | 3/10/2023 | 17/6/2026 | A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability. | |
| Modificada | Alta (7.8) | 0.19% | — | Sonicwall Netextender | 3/10/2023 | 17/6/2026 | A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileged user to gain system privileges through running repair functionality. | |
| Modificada | Alta (7.5) | 2.7% | — | Redhat UndertowRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM LinuxoneRedhat Openshift Container Platform FOR Power+3 | 27/9/2023 | 17/6/2026 | A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by… | |
| Modificada | Alta (8.1) | 1.4% | — | QuarkusRedhat Build OF OptaplannerRedhat Build OF QuarkusRedhat Decision Manager+8 | 20/9/2023 | 4/8/2026 | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and… | |
| Modificada | Media (5.4) | 0.61% | — | Summernote Rich Text Editor | 18/9/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote attacker to execute arbitrary code via a crafted script to the insert link function in the editor component. | |
| Modificada | Alta (8.8) | 1.0% | — | Redhat Decision ManagerRedhat DroolsRedhat Jboss Middleware Text-only AdvisoriesRedhat Process Automation | 11/9/2023 | 17/6/2026 | A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server. | |
| Modificada | Media (4.3) | 0.25% | — | Kreci Subscribers Text Counter | 30/8/2023 | 17/6/2026 | The Subscribers Text Counter WordPress plugin before 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping | |
| Modificada | Crítica (9.6) | 0.54% | — | Marktext | 19/8/2023 | 17/6/2026 | DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in MarkText 0.17.1 and before on Windows, Linux and macOS allows arbitrary JavaScript code to run in the context of MarkText main window. This vulnerability can be exploited if a user copies text from a malicious webpage and paste it into MarkText. | |
| Modificada | Alta (7.5) | 0.91% | — | Fasterxml Jackson-dataformats-text | 8/8/2023 | 17/6/2026 | Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack. |