Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
413 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | Thephpfactory Social Factory | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter. | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Thephpfactory Swap Factory | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | Thephpfactory Collection Factory | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | Thephpfactory Jobs Factory | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter. | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Thephpfactory Article Factory Manager | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter. | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Thephpfactory Raffle Factory | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter. | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Thephpfactory Penny Auction Factory | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | Thephpfactory Reverse Auction Factory | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter. | |
| Modificada | Alta (8.8) | 0.76% | — | Jfrog Artifactory | 13/7/2018 | 17/6/2026 | JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF attack allowing an attacker to perform actions as logged in user. This attack appear to be exploitable via The victim must run maliciously crafted flash component. This… | |
| Modificada | Alta (7.2) | 2.8% | — | Jfrog Artifactory | 9/7/2018 | 17/6/2026 | JFrog JFrog Artifactory version Prior to version 6.0.3, since version 4.0.0 contains a Directory Traversal vulnerability in The "Import Repository from Zip" feature, available through the Admin menu -> Import & Export -> Repositories, triggers a vulnerable UI REST endpoint (/ui/artifactimport/upload) that can result… | |
| Modificada | Alta (7.5) | 1.1% | — | Cardfactory Project Cardfactory | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for CardFactory, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.8) | 2.8% | 💥 Exploit | Rockwellautomation Rslinx ClassicRockwellautomation Factorytalk Linx Gateway | 7/6/2018 | 17/6/2026 | An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.90.00 and prior may allow an authorized, but non-privileged local user to execute arbitrary code and allow a threat actor to escalate user privileges on the affected workstation. | |
| Modificada | Alta (7.8) | 0.70% | — | Rockwellautomation Factorytalk Activation | 11/5/2018 | 17/6/2026 | Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may allow an attacker to link to or run a malicious executable. This may allow an authorized, but not privileged local user to execute arbitrary code with elevated privileges… | |
| Modificada | Crítica (9.8) | 26% | 💥 Exploit | Jfrog Artifactory | 1/5/2018 | 17/6/2026 | Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file. | |
| Modificada | Alta (7.5) | 4.2% | — | Rockwellautomation Factorytalk Alarms AND Events | 23/12/2017 | 17/6/2026 | An Improper Input Validation issue was discovered in Rockwell Automation FactoryTalk Alarms and Events, Version 2.90 and earlier. An unauthenticated attacker with remote access to a network with FactoryTalk Alarms and Events can send a specially crafted set of packets packet to Port 403/TCP (the history archiver… | |
| Modificada | Media (5.3) | 0.34% | — | Azeotech Daqfactory | 9/9/2017 | 17/6/2026 | An Uncontrolled Search Path Element issue was discovered in AzeoTech DAQFactory versions prior to 17.1. An uncontrolled search path element vulnerability has been identified, which may execute malicious DLL files that have been placed within the search path. | |
| Modificada | Alta (7.1) | 0.32% | — | Azeotech Daqfactory | 9/9/2017 | 17/6/2026 | An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. Local, non-administrative users may be able to replace or modify original application files with malicious ones. | |
| Modificada | Crítica (9.8) | 1.6% | — | Pcfreetime Format Factory | 3/8/2017 | 17/6/2026 | Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwmapi.dll. | |
| Modificada | Media (6.1) | 1.5% | — | Dfactory Responsive Lightbox | 7/7/2017 | 17/6/2026 | Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 3.9% | — | Jfrog Artifactory | 9/12/2016 | 17/6/2026 | JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning. | |
| Modificada | Alta (7.3) | 8.2% | — | Rockwellautomation Factorytalk Energrymetrix | 28/7/2016 | 17/6/2026 | Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation. | |
| Modificada | Crítica (9.8) | 6.3% | — | Rockwellautomation Factorytalk Energrymetrix | 28/7/2016 | 17/6/2026 | SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.8) | 3.1% | — | Mindbite Sitefactory CMS | 11/9/2015 | 17/6/2026 | Absolute path traversal vulnerability in SiteFactory CMS 5.5.9 allows remote attackers to read arbitrary files via a full pathname in the file parameter to assets/download.aspx. | |
| Modificada | Media (6.9) | 0.69% | — | Rockwellautomation Factorytalk Services PlatformRockwellautomation Factorytalk View Studio | 31/3/2015 | 17/6/2026 | Untrusted search path vulnerability in the Clean Utility application in Rockwell Automation FactoryTalk Services Platform before 2.71.00 and FactoryTalk View Studio 8.00.00 and earlier allows local users to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (10) | 4.2% | — | Schneider-electric Etg3000 Factorycast HMI Gateway FirmwareSchneider-electric Tsxetg3000Schneider-electric Tsxetg3010Schneider-electric Tsxetg3021+1 | 27/1/2015 | 17/6/2026 | The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session. |