Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
505 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.4) | 4.3% | — | HP 3par Storeserv Management Console | 9/8/2019 | 17/6/2026 | A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. | |
| Modificada | Alta (7.2) | 2.8% | — | Siteserver CMS | 22/4/2019 | 17/6/2026 | A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted. | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Alta (7.5) | 1.4% | — | Siemens Cp1604 FirmwareSiemens Cp1616 FirmwareSiemens Simatic Rf185c FirmwareSiemens Simatic Cp343-1 Advanced Firmware+49 | 17/4/2019 | 17/6/2026 | The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the… | |
| Modificada | Media (6.1) | 1.5% | 💥 Exploit | Reservo Image Hosting | 24/1/2018 | 17/6/2026 | Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed. | |
| Modificada | Crítica (9.8) | 1.3% | — | Ark-web A-reserve | 1/12/2017 | 17/6/2026 | SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.1) | 0.91% | — | Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+75 | 11/5/2017 | 17/6/2026 | Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected. | |
| Modificada | Alta (7.1) | 1.1% | — | Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+89 | 11/5/2017 | 17/6/2026 | Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected. | |
| Modificada | Media (6.1) | 4.0% | 💥 Exploit | Simpel-reserveren Project Simpel-reserveren | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin simpel-reserveren v3.5.2 | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | CP Reservation Calender Project CP Reservation Calender | 17/9/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a dex_reservations_calendar_load2 action or (2) dex_item parameter in a dex_reservations_check_posted_data… | |
| Modificada | Baja (3.5) | 0.95% | — | Room Reservations Project Room Reservations | 21/4/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Room Reservations module before 7.x-1.1 for Drupal allow remote authenticated users with the "Administer the room reservations system" permission to inject arbitrary web script or HTML via the (1) node title of a "Room Reservations Category" or (2) body of a… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Iscripts Reservelogic | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter. | |
| Modificada | Media (6.8) | 2.3% | — | Scoofficeserver | 16/3/2011 | 16/6/2026 | The STARTTLS implementation in SCO SCOoffice Server does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar… | |
| Modificada | Alta (10) | 8.4% | 💥 Exploit | Analogx Simpleserver WWW | 12/2/2010 | 16/6/2026 | Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vulnerability than CVE-2000-0664. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Indianpulses COM Gameserver | 28/1/2010 | 16/6/2026 | SQL injection vulnerability in the indianpulse Game Server (com_gameserver) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the grp parameter in a gameserver action to index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Jforjoomla COM Jreservation | 23/9/2009 | 16/6/2026 | SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php. | |
| Modificada | Alta (10) | 9.9% | 💥 Exploit | Gameservers GSC | 8/9/2009 | 16/6/2026 | GSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to execute arbitrary administrator commands via a crafted packet. | |
| Modificada | Media (4.3) | 0.93% | — | Webformatique Reservation Manager | 3/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Reservation Manager allows remote attackers to inject arbitrary web script or HTML via the resman_startdate parameter. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Indianpulses COM Gameserver | 3/9/2009 | 16/6/2026 | SQL injection vulnerability in the Game Server (com_gameserver) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php. | |
| Modificada | Media (6.8) | 3.4% | 💥 Exploit | Marcelo Costa Fileserver | 20/7/2009 | 16/6/2026 | Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files via a .. (dot dot) in a pathname. | |
| Modificada | Media (5) | 2.2% | 💥 Exploit | Funscripts RED Reservations | 2/4/2009 | 16/6/2026 | The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct request to (1) makered.mdb and (2) makered97.mdb. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Enthrallweb Ereservations | 22/1/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomlahbs COM LowcosthotelsJoomlahbs Hotel Booking Reservation System | 8/1/2009 | 16/6/2026 | SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomlahbs COM 5starhotelsJoomlahbs COM AllhotelsJoomlahbs Hotel Booking Reservation System | 8/1/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2) com_5starhotels module. NOTE: some of these details are obtained… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joomlahbs Hotel Booking Reservation System | 6/1/2009 | 16/6/2026 | SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the r_type parameter in a showhoteldetails action to index.php. |