Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

622 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.4%—Opentext Brava! Desktop15/6/202117/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF…
ModificadaAlta (7.8)1.4%—Opentext Brava! Desktop15/6/202117/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF…
ModificadaCrítica (9.8)1.6%—Lextudio Restructuredtext20/4/202117/6/2026
vscode-restructuredtext before 146.0.0 contains an incorrect access control vulnerability, where a crafted project folder could execute arbitrary binaries via crafted workspace configuration.
ModificadaMedia (6.5)0.76%—Textpattern15/4/202117/6/2026
Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security verification, which may lead to obtaining system permissions.
ModificadaCrítica (9.6)2.8%—Marktext5/4/202117/6/2026
Mark Text through 0.16.3 allows attackers arbitrary command execution. This could lead to Remote Code Execution (RCE) by opening .md files containing a mutation Cross Site Scripting (XSS) payload.
ModificadaMedia (5.4)0.86%—Opentext Content Server26/2/202117/6/2026
There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server Version 20.3. The application allows a remote attacker to introduce arbitrary JavaScript by crafting malicious form values that are later not sanitized.
ModificadaAlta (7.8)1.4%—Softmaker Office Textmaker 202110/2/202117/6/2026
In SoftMaker Software GmbH SoftMaker Office TextMaker 2021 (revision 1014), a specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon usage of this buffer the application will write outside its bounds resulting in a heap-based buffer overflow. An attacker…
ModificadaMedia (4.8)0.57%—Textpattern26/1/20219/7/2026
Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.
ModificadaBaja (3.1)0.94%—Oracle Text20/1/202117/6/2026
Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Text. Successful…
ModificadaMedia (5.3)1.7%💥 ExploitSonicwall Netextender9/1/202117/6/2026
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier.
ModificadaAlta (7.5)1.7%—Golang Text2/1/202117/6/2026
In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)
ModificadaAlta (8.8)0.66%—Textpattern2/12/202017/6/2026
Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.
ModificadaAlta (8.1)1.7%—Oracle Text21/10/202017/6/2026
Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Text. Successful attacks of this…
ModificadaCrítica (9.6)1.9%—Marktext16/10/202017/6/2026
Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; however, it can also be considered an issue in the design of the "source code mode" feature, which parses HTML even though HTML support is not one of the primary advertised…
ModificadaMedia (5.3)0.81%—Textpattern14/8/202017/6/2026
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
ModificadaMedia (5.3)0.81%—Textpattern14/8/202017/6/2026
In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
ModificadaAlta (7.8)0.55%—Sonicwall Netextender17/7/202017/6/2026
SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite a DLL and execute code with the same privilege in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 9.0.815 and earlier.
ModificadaMedia (6.5)2.1%💥 PoCHibernate ORMRedhat Build OF QuarkusRedhat Decision ManagerRedhat Fuse+66/7/202017/6/2026
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or…
ModificadaAlta (7.5)1.8%—Golang TextFedoraproject Fedora17/6/202017/6/2026
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop…
ModificadaMedia (5.9)1.8%—Apache CXFApache Wss4jRedhat Jboss Business Rules Management SystemRedhat Jboss Enterprise Application Platform+611/3/202016/6/2026
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
ModificadaAlta (7.5)3.6%—NettyFedoraproject FedoraDebian LinuxRedhat Jboss Enterprise Application Platform+227/1/202017/6/2026
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
ModificadaAlta (7.5)1.2%—Openbsd Textproc/isearch30/12/201916/6/2026
The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp).
ModificadaMedia (6.5)1.3%—Apple Texture18/12/201917/6/2026
Some analytics data was sent using HTTP rather than HTTPS. This was addressed by no longer sending this analytics data. This issue is fixed in Texture 5.11.10 for iOS, Texture 4.22.0.4 for Android. An attacker in a privileged network position may be able to intercept analytics data.
ModificadaCrítica (9.8)6.7%—Php-gettext Project Php-gettextOpensuse LeapRedhat Enterprise LinuxFedoraproject Fedora4/11/201917/6/2026
The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.
ModificadaAlta (7.8)1.2%💥 PoCSamsung Text-to-speech25/9/201917/6/2026
The Text-to-speech Engine (aka SamsungTTS) application before 3.0.02.7 and 3.0.00.101 for Android allows a local attacker to escalate privileges, e.g., to system privileges. The Samsung case ID is 101755.
Orbitaley — Vulnerabilidades