Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
472 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.86% | — | Phpipam | 4/2/2019 | 17/6/2026 | phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can result in executing code in victims browser. This attack appears to be exploitable via victim visits link crafted by an attacker. This vulnerability appears to have been fixed in 1.4. | |
| Modificada | Media (5.3) | 0.96% | — | Titanhq Spamtitan | 30/1/2019 | 17/6/2026 | TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filter to send malicious emails to an entire organization by modifying the URL requests sent to the application. | |
| Modificada | Media (6.1) | 0.95% | — | Ohtanz Spam-byebye | 13/1/2019 | 17/6/2026 | Cross-site scripting vulnerability in WordPress plugin spam-byebye 2.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 0.95% | — | Phpipam | 20/12/2018 | 17/6/2026 | PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser. This attack appear to be exploitable via Attacker change theme parameter in user settings. Admin(Victim) views user in admin-panel and gets exploited.. This… | |
| Modificada | Crítica (9.8) | 1.8% | — | Phpipam | 20/12/2018 | 17/6/2026 | phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, exploiting the vulnerability to access information he/she does not have access to.. This vulnerability appears to have been fixed in 1.4. | |
| Modificada | Media (4.7) | 0.80% | — | Phpipam | 20/12/2018 | 17/6/2026 | phpipam version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in The value of the phpipamredirect cookie is copied into an HTML tag on the login page encapsulated in single quotes. Editing the value of the cookie to r5zkh'><script>alert(1)</script>quqtl exploits an XSS vulnerability. that can… | |
| Modificada | Alta (8.1) | 1.3% | — | Kernel Linux-pam | 27/11/2018 | 17/6/2026 | A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead to pam_access rules not being applied (fail open). | |
| Modificada | Alta (7.8) | 0.98% | — | Apache SpamassassinCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+3 | 17/9/2018 | 17/6/2026 | Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax. | |
| Modificada | Crítica (9.8) | 11% | — | Apache SpamassassinPdfinfo Project PdfinfoCanonical Ubuntu LinuxDebian Linux | 17/9/2018 | 17/6/2026 | A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2. | |
| Modificada | Media (5.3) | 7.9% | — | Apache SpamassassinCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+3 | 17/9/2018 | 17/6/2026 | A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan timeouts. In Apache SpamAssassin, using HTML::Parser, we setup an object and hook into the begin… | |
| Modificada | Media (6.1) | 0.81% | — | Phpipam | 24/4/2018 | 17/6/2026 | app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter. | |
| Modificada | Media (5.4) | 0.67% | — | Phpipam | 21/4/2018 | 17/6/2026 | app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter. | |
| Modificada | Alta (8.2) | 1.4% | — | Yubico PAM | 4/4/2018 | 17/6/2026 | In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors). | |
| Modificada | Media (6.1) | 0.75% | — | Promise Webpam Proe | 7/2/2018 | 17/6/2026 | Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript code in a PHPSESSID cookie. | |
| Modificada | Media (6.5) | 1.5% | — | Libpam4j Project Libpam4jDebian LinuxRedhat Enterprise Linux | 18/1/2018 | 17/6/2026 | It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information. | |
| Modificada | Baja (3.3) | 0.40% | — | Linuxmagic Magicspam | 14/1/2018 | 17/6/2026 | The LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users to discover mailbox names by reading /var/log/magicspam/mslog. | |
| Modificada | Alta (7.8) | 0.77% | — | Anti-spam Smtp Proxy Project Anti-spam Smtp Proxy | 8/11/2017 | 17/6/2026 | The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access to the assp user account to install a Trojan horse /usr/share/assp/assp.pl script. | |
| Modificada | Alta (8.8) | 2.7% | 💥 Exploit | Dasinfomedia Wpams Apartment Management System | 28/9/2017 | 17/6/2026 | Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter. | |
| Modificada | Media (5) | 0.46% | — | Mirion Technologies DMC 3000 FirmwareMirion Technologies Ipam Transmitter F/dmc 2000 FirmwareMirion Technologies Telepole II FirmwareMirion Technologies Rds-31 ITX Firmware+3 | 20/9/2017 | 17/6/2026 | A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (including Solar PWR Package), DRM and RDS Based Boundary Monitors, External Transmitters, Telepole II,… | |
| Modificada | Media (6.5) | 0.24% | — | Mirion DMC 3000 Transmitter FirmwareMirion Ipam Transmitter F/dmc 2000 FirmwareMirion Rds-31 ITX FirmwareMirion Drm-1/2 Firmware+4 | 20/9/2017 | 17/6/2026 | An Inadequate Encryption Strength issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (including Solar PWR Package), DRM and RDS Based Boundary Monitors, External Transmitters, Telepole II, and… | |
| Modificada | Media (6.1) | 0.67% | — | Rspamd Project Rspamd | 29/7/2017 | 17/6/2026 | interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page. | |
| Modificada | Media (6.1) | 0.71% | — | Phpipam | 5/3/2017 | 17/6/2026 | Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (instructions in app/admin/instructions/preview.php; subnetId in app/admin/powerDNS/refresh-ptr-records.php). An attacker could execute… | |
| Modificada | Alta (7.8) | 0.78% | — | Debian LinuxFedoraproject FedoraPerlOpensuse Leap+1 | 2/8/2016 | 17/6/2026 | (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11)… | |
| Modificada | Crítica (9.8) | 1.8% | — | Libpam-sshauth Project Libpam-sshauthDebian Linux | 6/5/2016 | 17/6/2026 | The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileges via a system user account. | |
| Modificada | Media (6.5) | 2.7% | — | Linux-pamOracle Sparc-opl Service Processor | 24/8/2015 | 17/6/2026 | The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password. |