Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
596 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.6% | — | MediawikiDebian Linux | 31/10/2019 | 16/6/2026 | A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names. | |
| Modificada | Media (5.3) | 0.93% | — | Mediawiki Abusefilter | 29/10/2019 | 17/6/2026 | An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged users, thus disclosing potentially sensitive information. | |
| Modificada | Media (6.5) | 0.93% | — | Mediawiki Checkuser | 29/10/2019 | 17/6/2026 | An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within oversighted edit summaries made available via the MediaWiki API was potentially visible to users with various levels of access to this extension. Said users should not have been able to view these… | |
| Modificada | Alta (7.5) | 1.4% | — | Mediawiki | 29/10/2019 | 16/6/2026 | mediawiki allows deleted text to be exposed | |
| Analizada | Media (5.3) | 1.8% | — | MediawikiFedoraproject FedoraDebian Linux | 26/9/2019 | 17/6/2026 | In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup. | |
| Modificada | Media (6.1) | 0.70% | — | Mediawiki Mobilefrontend | 9/8/2019 | 17/6/2026 | In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.php. | |
| Modificada | Media (6.5) | 1.4% | — | MediawikiDebian Linux | 10/7/2019 | 17/6/2026 | Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. | |
| Modificada | Media (6.5) | 1.4% | — | MediawikiDebian Linux | 10/7/2019 | 17/6/2026 | MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. | |
| Modificada | Alta (7.5) | 2.0% | — | MediawikiDebian Linux | 10/7/2019 | 17/6/2026 | Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. | |
| Modificada | Alta (7.5) | 2.3% | — | MediawikiDebian Linux | 10/7/2019 | 17/6/2026 | Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. | |
| Modificada | Alta (7.5) | 1.3% | — | Mediawiki | 10/7/2019 | 17/6/2026 | An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. | |
| Modificada | Media (6.1) | 1.3% | — | MediawikiDebian Linux | 10/7/2019 | 17/6/2026 | Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. | |
| Modificada | Alta (8.8) | 0.84% | — | MediawikiDebian Linux | 10/7/2019 | 17/6/2026 | Wikimedia MediaWiki through 1.32.1 allows CSRF. | |
| Modificada | Crítica (9.8) | 3.3% | — | MediawikiDebian Linux | 10/7/2019 | 17/6/2026 | An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover. | |
| Modificada | Media (5.3) | 1.3% | — | MediawikiDebian Linux | 10/7/2019 | 17/6/2026 | MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. | |
| Modificada | Media (5.3) | 2.3% | — | Mediawiki | 4/10/2018 | 17/6/2026 | Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible. | |
| Modificada | Media (6.5) | 2.0% | — | MediawikiDebian Linux | 4/10/2018 | 17/6/2026 | Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock | |
| Modificada | Media (6.5) | 2.9% | — | MediawikiDebian Linux | 4/10/2018 | 17/6/2026 | Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid | |
| Modificada | Media (4.3) | 1.6% | — | MediawikiDebian Linux | 4/10/2018 | 17/6/2026 | Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'. | |
| Modificada | Media (5.3) | 2.0% | — | Mediawiki | 16/4/2018 | 17/6/2026 | MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation. | |
| Modificada | Crítica (9.8) | 11% | 💥 Exploit | MediawikiDebian Linux | 13/4/2018 | 17/6/2026 | Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities. | |
| Modificada | Media (5.3) | 1.4% | — | MediawikiDebian Linux | 13/4/2018 | 17/6/2026 | Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter. | |
| Modificada | Media (6.5) | 1.2% | — | MediawikiDebian Linux | 13/4/2018 | 17/6/2026 | Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it. | |
| Modificada | Media (5.3) | 1.5% | — | MediawikiDebian Linux | 13/4/2018 | 17/6/2026 | Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages. | |
| Modificada | Alta (8.8) | 1.8% | — | MediawikiDebian Linux | 13/4/2018 | 17/6/2026 | Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure. |