Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
933 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.75% | — | Zabbix-agent2 | 18/12/2023 | 17/6/2026 | The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution. | |
| Modificada | Alta (7.2) | 0.87% | — | Zabbix Server | 18/12/2023 | 17/6/2026 | An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server. | |
| Modificada | Alta (8.1) | 0.67% | — | Zabbix-agent | 18/12/2023 | 17/6/2026 | The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server. | |
| Modificada | Alta (8.8) | 0.85% | — | Zabbix ServerZabbix Frontend | 18/12/2023 | 17/6/2026 | The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user. | |
| Modificada | Alta (8.8) | 0.26% | — | Softlabbd Integrate Google Drive | 17/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.4. | |
| Modificada | Media (6.1) | 0.39% | — | Softlabbd Integrate Google Drive | 7/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.This issue affects Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and… | |
| Modificada | Alta (8.8) | 1.2% | — | Phpjabbers Appointment Scheduler | 7/12/2023 | 17/6/2026 | Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpjabbers Appointment Scheduler | 7/12/2023 | 17/6/2026 | A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion. | |
| Modificada | Media (5.4) | 0.42% | — | Phpjabbers Appointment Scheduler | 7/12/2023 | 17/6/2026 | Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. | |
| Modificada | Media (5.4) | 0.46% | — | Phpjabbers Appointment Scheduler | 7/12/2023 | 17/6/2026 | Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code. | |
| Modificada | Media (5.4) | 0.46% | — | Phpjabbers CAR Rental Script | 7/12/2023 | 17/6/2026 | Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code. | |
| Modificada | Media (5.4) | 0.46% | — | Phpjabbers CAR Rental Script | 7/12/2023 | 17/6/2026 | Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Phpjabbers CAR Rental Script | 7/12/2023 | 17/6/2026 | Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpjabbers CAR Rental Script | 7/12/2023 | 17/6/2026 | A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion. | |
| Modificada | Alta (7.5) | 1.2% | — | Phpjabbers Availability Booking Calendar | 7/12/2023 | 17/6/2026 | A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion. | |
| Modificada | Alta (8.8) | 1.2% | — | Phpjabbers Shuttle Booking Software | 7/12/2023 | 17/6/2026 | Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export. | |
| Modificada | Media (5.4) | 0.46% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. | |
| Modificada | Media (5.4) | 0.46% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List. | |
| Modificada | Media (5.4) | 0.45% | — | Phpjabbers Availability Booking Calendar | 7/12/2023 | 17/6/2026 | Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code. | |
| Modificada | Media (6.1) | 0.50% | — | Phpjabbers Availability Booking Calendar | 7/12/2023 | 17/6/2026 | A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php. | |
| Modificada | Alta (8.8) | 1.2% | — | Phpjabbers Availability Booking Calendar | 7/12/2023 | 17/6/2026 | Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component. | |
| Modificada | Media (5.4) | 0.72% | — | Phpjabbers Shuttle Booking Software | 7/12/2023 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript via the name, description, title, or address parameter to index.php. | |
| Modificada | Media (5.2) | 0.29% | — | Abbott ID NOW Firmware | 14/11/2023 | 17/6/2026 | The startup process and device configurations of the Abbott ID NOW device, before v7.1, can be interrupted and/or modified via physical access to an internal serial port. Direct physical access is required to exploit. |