Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.8% | — | XSS Hunter Express Project XSS Hunter Express | 17/9/2021 | 17/6/2026 | XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths. | |
| Modificada | Alta (7.2) | 2.4% | — | Cisco ExpresswayCisco Telepresence Video Communication Server | 18/8/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as the root user. This vulnerability is due to incorrect handling of… | |
| Modificada | Alta (7.2) | 1.1% | — | Cisco ExpresswayCisco Telepresence Video Communication Server | 18/8/2021 | 17/6/2026 | A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underlying operating system. The vulnerability is due to insufficient validation of… | |
| Modificada | Media (6.1) | 3.4% | — | Expresstech Quiz AND Survey Master | 18/8/2021 | 17/6/2026 | Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 1.3% | — | CkeditorDebian LinuxFedoraproject FedoraOracle Application Express+8 | 13/8/2021 | 17/6/2026 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It… | |
| Modificada | Alta (8.8) | 0.57% | — | Express-cart Project Express-cart | 12/8/2021 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other unspecified impacts. | |
| Modificada | Crítica (9.8) | 1.4% | — | Expressionengine | 12/8/2021 | 17/6/2026 | In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->get('file') instead of the fixed file names of icon.png and icon.svg. | |
| Modificada | Media (5.4) | 1.2% | — | CkeditorFedoraproject FedoraOracle Application ExpressOracle Banking Party Management+6 | 12/8/2021 | 17/6/2026 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary… | |
| Modificada | Media (5.4) | 1.2% | — | CkeditorFedoraproject FedoraOracle Application ExpressOracle Banking Party Management+9 | 12/8/2021 | 17/6/2026 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It… | |
| Modificada | Alta (8.8) | 2.9% | — | Devexpress | 4/8/2021 | 17/6/2026 | DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization. | |
| Modificada | Media (5.4) | 0.50% | — | Oracle Application Express | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 21.1.0.00.04. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.5) | 1.4% | — | Prismjs PrismOracle Application Express | 28/6/2021 | 17/6/2026 | Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24.… | |
| Modificada | Alta (7) | 1.8% | — | Phoenixcontact Config+Phoenixcontact PC WorxPhoenixcontact PC Worx Express | 25/6/2021 | 17/6/2026 | Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could lead to a remote code execution when unallocated memory is freed because of incompletely initialized data. The attacker needs to get… | |
| Modificada | Media (6.1) | 1.6% | — | Mongo-express Project Mongo-express | 21/6/2021 | 17/6/2026 | mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: https://github.com/mongo-express/mongo-express/issues/577, when the content of a cell grows larger than supported size, clicking on a row will show full document unescaped, however this needs admin… | |
| Modificada | Media (6.1) | 0.83% | — | Expresstech Quiz AND Survey Master | 20/6/2021 | 17/6/2026 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to… | |
| Modificada | Media (6.1) | 0.81% | — | Cisco Unified Intelligence CenterCisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center Express | 16/6/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate… | |
| Modificada | Media (5.3) | 2.1% | — | Eclipse Jakarta Expression LanguageQuarkusOracle Communications Cloud Native Core PolicyOracle Weblogic Server | 26/5/2021 | 17/6/2026 | In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid. | |
| Modificada | Alta (8.6) | 16% | — | Express Handlebars Project Express Handlebars | 14/5/2021 | 17/6/2026 | Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream applications. This potential vulnerability is… | |
| Modificada | Media (6.8) | 1.3% | — | Express Handlebars Project Express Handlebars | 14/5/2021 | 17/6/2026 | express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream applications. This potential vulnerability is somewhat… | |
| Modificada | Media (4.8) | 0.53% | — | Express-cart Project Express-cart | 11/5/2021 | 17/6/2026 | The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on an admin hacking his/her own website. | |
| Modificada | Alta (7.7) | 0.92% | — | Atlassian Connect Express | 16/4/2021 | 17/6/2026 | Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Express app occurs with a server-to-server JWT or a context JWT.… | |
| Modificada | Media (5.3) | 1.3% | — | Resourcexpress | 15/4/2021 | 17/6/2026 | In QED ResourceXpress through 4.9k, a large numeric or alphanumeric value submitted in specific URL parameters causes a server error in script execution due to insufficient input validation. | |
| Modificada | Alta (7.5) | 0.88% | — | Mongo-express Project Mongo-express | 13/4/2021 | 17/6/2026 | All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled exception, leading to a crash. | |
| Modificada | Alta (8.8) | 1.9% | — | Expresstech Quiz AND Survey Master | 12/4/2021 | 17/6/2026 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection. The lowest role allowed to use this… | |
| Modificada | Media (6.1) | 0.82% | — | Cisco Unified Contact Center ExpressCisco Unified Intelligence Center | 8/4/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly… |