Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
933 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Vmware Rabbitmq Java Client | 25/10/2023 | 17/6/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects. Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from DoS… | |
| Modificada | Media (4.9) | 1.1% | — | Vmware Rabbitmq | 25/10/2023 | 17/6/2026 | RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target… | |
| Modificada | Alta (8.8) | 0.49% | 💥 PoC | Phpjabbers Limo Booking Software | 12/10/2023 | 17/6/2026 | PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI. | |
| Modificada | Alta (8.8) | 0.59% | — | Zabbix | 12/10/2023 | 17/6/2026 | Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation. | |
| Modificada | Crítica (9.1) | 0.56% | — | Zabbix | 12/10/2023 | 17/6/2026 | Request to LDAP is sent before user permissions are checked. | |
| Modificada | Alta (7.8) | 0.69% | — | Zabbix | 12/10/2023 | 17/6/2026 | The zabbix/src/libs/zbxjson module is vulnerable to a buffer overflow when parsing JSON files via zbx_json_open. | |
| Modificada | Media (5.4) | 0.60% | — | Zabbix | 12/10/2023 | 17/6/2026 | A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL. | |
| Modificada | Crítica (9.8) | 0.75% | — | Zabbix-agent2 | 12/10/2023 | 17/6/2026 | Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the… | |
| Modificada | Alta (7.5) | 0.59% | — | Phpjabbers Appointment Scheduler | 10/10/2023 | 17/6/2026 | User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Media (6.1) | 0.38% | — | Phpjabbers Appointment Scheduler | 10/10/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0 | |
| Modificada | Alta (7.5) | 0.67% | — | Phpjabbers PHP Shopping Cart | 21/9/2023 | 17/6/2026 | Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter. | |
| Modificada | Media (4.3) | 0.89% | — | Cisco Jabber | 15/9/2023 | 17/6/2026 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulnerability is due to the improper handling of nested XMPP… | |
| Modificada | Crítica (9.8) | 0.53% | — | Phpjabbers Cleaning Business Software | 11/9/2023 | 17/6/2026 | In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts. | |
| Modificada | Alta (7.5) | 0.67% | — | Phpjabbers Business Directory Script | 30/8/2023 | 17/6/2026 | phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter. | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Phpjabbers PHP Forum Script | 30/8/2023 | 17/6/2026 | phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter. | |
| Modificada | Media (6.1) | 0.43% | — | Phpjabbers Business Directory Script | 30/8/2023 | 17/6/2026 | phpjabbers Business Directory Script 3.2 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Make AN Offer Widget | 28/8/2023 | 17/6/2026 | User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Ticket Support Script | 28/8/2023 | 17/6/2026 | User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Event Booking Calendar | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers CAR Rental Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 1.1% | — | Phpjabbers Taxi Booking Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Fundraising Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Yacht Listing Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Hotel Booking System | 28/8/2023 | 17/6/2026 | User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Restaurant Booking Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. |