Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.6% | 💥 Exploit | Evilmartians Imgproxy | 19/3/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0. | |
| Modificada | Media (4.3) | 0.23% | — | Xnau Participants Database | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.5 leads to list column update. | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Artisanworkshop Japanized FOR Woocommerce | 21/2/2023 | 17/6/2026 | The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Alta (8.8) | 2.1% | 💥 PoC | Nosh Chartingsystem Project Nosh Chartingsystem | 1/2/2023 | 17/6/2026 | NOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The client-side checks can be bypassed. This may allow attackers to steal Protected Health Information because the product is for health charting. | |
| Modificada | Media (5.4) | 0.57% | — | Nosh Chartingsystem Project Nosh Chartingsystem | 29/1/2023 | 17/6/2026 | NOSH 4a5cfdb allows stored XSS via the create user page. For example, a first name (of a physician, assistant, or billing user) can have a JavaScript payload that is executed upon visiting the /users/2/1 page. This may allow attackers to steal Protected Health Information because the product is for health charting. | |
| Modificada | Media (6.1) | 0.52% | — | 01-scripts 01-artikelsystem | 9/1/2023 | 17/6/2026 | A vulnerability was found in 01-Scripts 01-Artikelsystem. It has been classified as problematic. Affected is an unknown function of the file 01article.php. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. It is possible to launch the attack remotely. The patch is identified as… | |
| Modificada | Crítica (9.8) | 0.63% | — | Jfrog Artifactory | 8/1/2023 | 17/6/2026 | JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user. | |
| Modificada | Alta (8.8) | 2.5% | 💥 PoC | Artifex MujsDebian LinuxFedoraproject Fedora | 23/11/2022 | 17/6/2026 | A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file. | |
| Modificada | Media (5.5) | 0.24% | — | Artifex Mupdf | 26/8/2022 | 17/6/2026 | A Floating point exception (division-by-zero) flaw was found in Mupdf for zero width pages in muraster.c. It is fixed in Mupdf-1.20.0-rc1 upstream. | |
| Modificada | Media (6.1) | 1.6% | 💥 Exploit | Articatech Artica Proxy | 24/8/2022 | 17/6/2026 | An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php. | |
| Modificada | Alta (7.1) | 0.46% | — | Artifex GhostscriptDebian Linux | 19/8/2022 | 17/6/2026 | A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service. | |
| Modificada | Media (6.1) | 0.42% | — | Artica Pandora FMS | 5/8/2022 | 17/6/2026 | A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via module massive operation name field. | |
| Modificada | Media (4.9) | 0.84% | — | Jfrog Artifactory | 6/7/2022 | 17/6/2026 | JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x. | |
| Modificada | Media (6.1) | 0.57% | — | Jfrog Artifactory | 6/7/2022 | 17/6/2026 | JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before… | |
| Modificada | Alta (8.8) | 0.36% | — | Jfrog Artifactory | 6/7/2022 | 17/6/2026 | JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x. | |
| Modificada | Crítica (9) | 0.83% | — | Smartics | 27/6/2022 | 17/6/2026 | Elcomplus SmartICS v2.3.4.0 does not neutralize user-controllable input, which allows an authenticated user to inject arbitrary code into specific parameters. | |
| Modificada | Baja (2.7) | 0.65% | — | Smartics | 27/6/2022 | 17/6/2026 | Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-level users to perform path traversal attacks and specify arbitrary files. | |
| Modificada | Media (4.9) | 0.81% | — | Smartics | 27/6/2022 | 17/6/2026 | An authenticated user with admin privileges may be able to terminate any process on the system running Elcomplus SmartICS v2.3.4.0. | |
| Modificada | Media (6.5) | 0.53% | — | Pdf24 Articles TO PDF Project Pdf24 Articles TO PDF | 20/6/2022 | 17/6/2026 | The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (6.5) | 0.53% | — | Pdf24 Articles TO PDF Project Pdf24 Articles TO PDF | 20/6/2022 | 17/6/2026 | The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (5.5) | 1.4% | — | Artifex GhostscriptFedoraproject Fedora | 16/6/2022 | 17/6/2026 | A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prototype that depends upon the number of bits per pixel. For bpp > 64,… | |
| Modificada | Media (6.5) | 0.57% | — | Jfrog Artifactory | 23/5/2022 | 17/6/2026 | JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation. | |
| Modificada | Alta (7.8) | 0.42% | — | Minitool Partition Wizard | 20/5/2022 | 17/6/2026 | MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level. | |
| Modificada | Media (4.9) | 0.54% | — | Jfrog Artifactory | 19/5/2022 | 17/6/2026 | JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators. | |
| Modificada | Media (5.5) | 1.1% | — | Artifex MujsDebian LinuxFedoraproject Fedora | 18/5/2022 | 17/6/2026 | In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp. |