Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

596 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.6%—MediawikiDebian Linux31/10/201916/6/2026
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
ModificadaMedia (5.3)0.93%—Mediawiki Abusefilter29/10/201917/6/2026
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged users, thus disclosing potentially sensitive information.
ModificadaMedia (6.5)0.93%—Mediawiki Checkuser29/10/201917/6/2026
An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within oversighted edit summaries made available via the MediaWiki API was potentially visible to users with various levels of access to this extension. Said users should not have been able to view these…
ModificadaAlta (7.5)1.4%—Mediawiki29/10/201916/6/2026
mediawiki allows deleted text to be exposed
AnalizadaMedia (5.3)1.8%—MediawikiFedoraproject FedoraDebian Linux26/9/201917/6/2026
In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
ModificadaMedia (6.1)0.70%—Mediawiki Mobilefrontend9/8/201917/6/2026
In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.php.
ModificadaMedia (6.5)1.4%—MediawikiDebian Linux10/7/201917/6/2026
Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ModificadaMedia (6.5)1.4%—MediawikiDebian Linux10/7/201917/6/2026
MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ModificadaAlta (7.5)2.0%—MediawikiDebian Linux10/7/201917/6/2026
Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ModificadaAlta (7.5)2.3%—MediawikiDebian Linux10/7/201917/6/2026
Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ModificadaAlta (7.5)1.3%—Mediawiki10/7/201917/6/2026
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ModificadaMedia (6.1)1.3%—MediawikiDebian Linux10/7/201917/6/2026
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ModificadaAlta (8.8)0.84%—MediawikiDebian Linux10/7/201917/6/2026
Wikimedia MediaWiki through 1.32.1 allows CSRF.
ModificadaCrítica (9.8)3.3%—MediawikiDebian Linux10/7/201917/6/2026
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.
ModificadaMedia (5.3)1.3%—MediawikiDebian Linux10/7/201917/6/2026
MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
ModificadaMedia (5.3)2.3%—Mediawiki4/10/201817/6/2026
Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.
ModificadaMedia (6.5)2.0%—MediawikiDebian Linux4/10/201817/6/2026
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
ModificadaMedia (6.5)2.9%—MediawikiDebian Linux4/10/201817/6/2026
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
ModificadaMedia (4.3)1.6%—MediawikiDebian Linux4/10/201817/6/2026
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.
ModificadaMedia (5.3)2.0%—Mediawiki16/4/201817/6/2026
MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.
ModificadaCrítica (9.8)11%💥 ExploitMediawikiDebian Linux13/4/201817/6/2026
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
ModificadaMedia (5.3)1.4%—MediawikiDebian Linux13/4/201817/6/2026
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.
ModificadaMedia (6.5)1.2%—MediawikiDebian Linux13/4/201817/6/2026
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.
ModificadaMedia (5.3)1.5%—MediawikiDebian Linux13/4/201817/6/2026
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.
ModificadaAlta (8.8)1.8%—MediawikiDebian Linux13/4/201817/6/2026
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.