Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

505 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.4)4.3%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaAlta (7.2)2.8%—Siteserver CMS22/4/201917/6/2026
A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted.
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaAlta (7.5)1.4%—Siemens Cp1604 FirmwareSiemens Cp1616 FirmwareSiemens Simatic Rf185c FirmwareSiemens Simatic Cp343-1 Advanced Firmware+4917/4/201917/6/2026
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the…
ModificadaMedia (6.1)1.5%💥 ExploitReservo Image Hosting24/1/201817/6/2026
Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed.
ModificadaCrítica (9.8)1.3%—Ark-web A-reserve1/12/201717/6/2026
SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.1)0.91%—Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+7511/5/201717/6/2026
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected.
ModificadaAlta (7.1)1.1%—Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+8911/5/201717/6/2026
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.
ModificadaMedia (6.1)4.0%💥 ExploitSimpel-reserveren Project Simpel-reserveren10/10/201617/6/2026
Reflected XSS in wordpress plugin simpel-reserveren v3.5.2
ModificadaAlta (7.5)4.8%💥 ExploitCP Reservation Calender Project CP Reservation Calender17/9/201517/6/2026
Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a dex_reservations_calendar_load2 action or (2) dex_item parameter in a dex_reservations_check_posted_data…
ModificadaBaja (3.5)0.95%—Room Reservations Project Room Reservations21/4/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Room Reservations module before 7.x-1.1 for Drupal allow remote authenticated users with the "Administer the room reservations system" permission to inject arbitrary web script or HTML via the (1) node title of a "Room Reservations Category" or (2) body of a…
ModificadaAlta (7.5)2.4%💥 ExploitIscripts Reservelogic1/11/201116/6/2026
SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
ModificadaMedia (6.8)2.3%—Scoofficeserver16/3/201116/6/2026
The STARTTLS implementation in SCO SCOoffice Server does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar…
ModificadaAlta (10)8.4%💥 ExploitAnalogx Simpleserver WWW12/2/201016/6/2026
Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vulnerability than CVE-2000-0664.
ModificadaAlta (7.5)0.97%💥 ExploitIndianpulses COM Gameserver28/1/201016/6/2026
SQL injection vulnerability in the indianpulse Game Server (com_gameserver) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the grp parameter in a gameserver action to index.php.
ModificadaAlta (7.5)1.0%💥 ExploitJforjoomla COM Jreservation23/9/200916/6/2026
SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php.
ModificadaAlta (10)9.9%💥 ExploitGameservers GSC8/9/200916/6/2026
GSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to execute arbitrary administrator commands via a crafted packet.
ModificadaMedia (4.3)0.93%—Webformatique Reservation Manager3/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Reservation Manager allows remote attackers to inject arbitrary web script or HTML via the resman_startdate parameter.
ModificadaAlta (7.5)0.96%💥 ExploitIndianpulses COM Gameserver3/9/200916/6/2026
SQL injection vulnerability in the Game Server (com_gameserver) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.
ModificadaMedia (6.8)3.4%💥 ExploitMarcelo Costa Fileserver20/7/200916/6/2026
Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files via a .. (dot dot) in a pathname.
ModificadaMedia (5)2.2%💥 ExploitFunscripts RED Reservations2/4/200916/6/2026
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct request to (1) makered.mdb and (2) makered97.mdb.
ModificadaAlta (7.5)1.0%💥 ExploitEnthrallweb Ereservations22/1/200916/6/2026
Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field). NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.97%💥 ExploitJoomlahbs COM LowcosthotelsJoomlahbs Hotel Booking Reservation System8/1/200916/6/2026
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.
ModificadaAlta (7.5)0.97%💥 ExploitJoomlahbs COM 5starhotelsJoomlahbs COM AllhotelsJoomlahbs Hotel Booking Reservation System8/1/200916/6/2026
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2) com_5starhotels module. NOTE: some of these details are obtained…
ModificadaAlta (7.5)1.0%💥 ExploitJoomlahbs Hotel Booking Reservation System6/1/200916/6/2026
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the r_type parameter in a showhoteldetails action to index.php.
Orbitaley — Vulnerabilidades