Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

933 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%—Vmware Rabbitmq Java Client25/10/202317/6/2026
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects. Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from DoS…
ModificadaMedia (4.9)1.1%—Vmware Rabbitmq25/10/202317/6/2026
RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target…
ModificadaAlta (8.8)0.49%💥 PoCPhpjabbers Limo Booking Software12/10/202317/6/2026
PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.
ModificadaAlta (8.8)0.59%—Zabbix12/10/202317/6/2026
Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.
ModificadaCrítica (9.1)0.56%—Zabbix12/10/202317/6/2026
Request to LDAP is sent before user permissions are checked.
ModificadaAlta (7.8)0.69%—Zabbix12/10/202317/6/2026
The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open.
ModificadaMedia (5.4)0.60%—Zabbix12/10/202317/6/2026
A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.
ModificadaCrítica (9.8)0.75%—Zabbix-agent212/10/202317/6/2026
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the…
ModificadaAlta (7.5)0.59%—Phpjabbers Appointment Scheduler10/10/202317/6/2026
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaMedia (6.1)0.38%—Phpjabbers Appointment Scheduler10/10/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0
ModificadaAlta (7.5)0.67%—Phpjabbers PHP Shopping Cart21/9/202317/6/2026
Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter.
ModificadaMedia (4.3)0.89%—Cisco Jabber15/9/202317/6/2026
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulnerability is due to the improper handling of nested XMPP…
ModificadaCrítica (9.8)0.53%—Phpjabbers Cleaning Business Software11/9/202317/6/2026
In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.
ModificadaAlta (7.5)0.67%—Phpjabbers Business Directory Script30/8/202317/6/2026
phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter.
ModificadaMedia (6.1)1.1%💥 ExploitPhpjabbers PHP Forum Script30/8/202317/6/2026
phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.
ModificadaMedia (6.1)0.43%—Phpjabbers Business Directory Script30/8/202317/6/2026
phpjabbers Business Directory Script 3.2 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.
ModificadaCrítica (9.8)0.89%—Phpjabbers Make AN Offer Widget28/8/202317/6/2026
User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Ticket Support Script28/8/202317/6/2026
User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Event Booking Calendar28/8/202317/6/2026
User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers CAR Rental Script28/8/202317/6/2026
User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)1.1%—Phpjabbers Taxi Booking Script28/8/202317/6/2026
User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Fundraising Script28/8/202317/6/2026
User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Yacht Listing Script28/8/202317/6/2026
User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Hotel Booking System28/8/202317/6/2026
User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.89%—Phpjabbers Restaurant Booking Script28/8/202317/6/2026
User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Orbitaley — Vulnerabilidades