Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
866 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.7) | 1.3% | — | Joomla! | 22/5/2018 | 17/6/2026 | An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS vulnerability. | |
| Modificada | Media (4.3) | 1.4% | — | Joomla! | 22/5/2018 | 17/6/2026 | An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were either unpublished or published with restricted view permission. | |
| Modificada | Media (4.8) | 1.0% | — | Joomla! | 22/5/2018 | 17/6/2026 | An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack. | |
| Modificada | Crítica (9.8) | 3.2% | — | Joomla! | 22/5/2018 | 17/6/2026 | An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen. | |
| Modificada | Media (5.9) | 1.3% | — | Joomla! | 22/5/2018 | 17/6/2026 | An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was expected to be destroyed would be recreated. | |
| Modificada | Alta (8.8) | 2.7% | — | Joomla! | 22/5/2018 | 17/6/2026 | An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissions. | |
| Modificada | Alta (7.5) | 1.7% | — | Joomla! | 22/5/2018 | 17/6/2026 | An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver. | |
| Modificada | Media (6.5) | 1.9% | — | Joomla! | 22/5/2018 | 17/6/2026 | An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. | |
| Modificada | Alta (8.8) | 28% | 💥 PoC | Joomla! | 15/3/2018 | 17/6/2026 | In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view. | |
| Modificada | Alta (7.5) | 2.3% | — | Joomlaworks K2 | 28/2/2018 | 17/6/2026 | The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cmd=file&target=l1_../configuration.php&download=1 request. The specific pathname ../configuration.php should be base64 encoded for… | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Cwjoomla CW Tags | 22/2/2018 | 17/6/2026 | SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Techjoomla Jticketing | 17/2/2018 | 17/6/2026 | SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or filter_events_cat parameter. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Techjoomla Invitex | 17/2/2018 | 17/6/2026 | SQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Neojoomla Neorecruit | 17/2/2018 | 17/6/2026 | SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Techjoomla Jgive | 17/2/2018 | 17/6/2026 | SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries parameter. | |
| Modificada | Media (6.1) | 1.7% | — | Joomla! | 30/1/2018 | 17/6/2026 | In Joomla! before 3.8.4, lack of escaping in the module chromes leads to XSS vulnerabilities in the module system. | |
| Modificada | Media (6.1) | 1.7% | — | Joomla! | 30/1/2018 | 17/6/2026 | In Joomla! before 3.8.4, inadequate input filtering in the Uri class (formerly JUri) leads to an XSS vulnerability. | |
| Modificada | Media (6.1) | 57% | — | Joomla! | 30/1/2018 | 17/6/2026 | In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox | |
| Modificada | Crítica (9.8) | 4.1% | 💥 PoC | Joomla! | 30/1/2018 | 17/6/2026 | In Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor postinstall message. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Joomlacalendars Event Calendar | 30/1/2018 | 17/6/2026 | SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Joomlacalendars Picture Calendar | 30/1/2018 | 17/6/2026 | Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Joomlacalendars Visual Calendar | 30/1/2018 | 17/6/2026 | SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action. | |
| Modificada | Alta (7.5) | 37% | 💥 Exploit | Joomlatag Jtag Members Directory | 29/1/2018 | 17/6/2026 | Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter. | |
| Modificada | Crítica (9.8) | 1.5% | — | Ijoomla AD Agency | 14/1/2018 | 17/6/2026 | The iJoomla com_adagency plugin 6.0.9 for Joomla! allows SQL injection via the `advertiser_status` and `status_select` parameters to index.php. | |
| Modificada | Crítica (9.8) | 4.4% | — | Joomla! | 10/11/2017 | 17/6/2026 | In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method. |