Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.8% | — | Symphonyextensions Rich Text Formatter | 5/9/2019 | 17/6/2026 | The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php. | |
| Modificada | Alta (7.5) | 11% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraApache Drill+14 | 30/7/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath. | |
| Modificada | Alta (7.4) | 1.5% | — | Opentext Brava! | 21/5/2019 | 17/6/2026 | OpenText Brava! Enterprise and Brava! Server 7.5 through 16.4 configure excessive permissions by default on Windows. During installation, a displaylistcache file share is created on the Windows server with full read and write permissions for the Everyone group at both the NTFS and Share levels. The share is used to… | |
| Modificada | Alta (8.1) | 0.65% | — | Eclipse XtendEclipse Xtext | 6/5/2019 | 17/6/2026 | All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised. | |
| Modificada | Media (6.1) | 1.5% | 💥 PoC | Opentext Portal | 22/3/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in OpenText Portal 7.4.4 allows remote attackers to inject arbitrary web script or HTML via the vgnextoid parameter to a menuitem URI. | |
| Modificada | Media (6.1) | 1.5% | — | Opentext Documentum Webtop | 21/3/2019 | 17/6/2026 | XSS and/or a Client Side URL Redirect exists in OpenText Documentum Webtop 5.3 SP2. The parameter startat in "/webtop/help/en/default.htm" is vulnerable. | |
| Modificada | Alta (7.8) | 1.1% | — | Sublimetext Sublime Text 3 | 25/2/2019 | 17/6/2026 | DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibers-l1-1-1.dll or api-ms-win-core-localization-l1-2-1.dll file may be loaded if a victim uses sublime_text.exe to open a .txt file within an attacker's… | |
| Modificada | Crítica (9.8) | 4.3% | — | GNU GettextCanonical Ubuntu LinuxRedhat Enterprise Linux | 29/10/2018 | 17/6/2026 | An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt. | |
| Modificada | Alta (8.2) | 1.8% | — | Oracle Text | 17/10/2018 | 17/6/2026 | Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Text. Successful attacks require human… | |
| Modificada | Media (5.4) | 4.8% | — | Apache KafkaRedhat Jboss Middleware Text-only AdvisoriesOracle DatabaseOracle Primavera P6 Enterprise Project Portfolio Management+1 | 26/7/2018 | 17/6/2026 | In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss. | |
| Modificada | Alta (7.8) | 0.38% | — | KDE Ktexteditor | 25/4/2018 | 17/6/2026 | An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged users on the local system to gain root privileges. The attack occurs when one user (who has an… | |
| Modificada | Media (5.4) | 0.53% | — | Opentext Documentum D2 | 11/4/2018 | 17/6/2026 | In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via the servlet/Download _docbase or _username parameter. | |
| Modificada | Media (5.4) | 0.53% | — | Opentext Documentum D2 | 11/4/2018 | 17/6/2026 | In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Stored Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via a filename of an uploaded image file. | |
| Modificada | Crítica (9.8) | 6.2% | 💥 Exploit | Textpattern | 14/3/2018 | 17/6/2026 | An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Textpattern | 13/3/2018 | 17/6/2026 | textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the web server by exhausting server memory resources. This attack appear to be exploitable via Uploading a specially crafted XML file. | |
| Modificada | Crítica (9.8) | 2.3% | — | Opentext Vertica | 15/2/2018 | 17/6/2026 | A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and later was found. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Opentext Document Sciences Xpression | 4/1/2018 | 17/6/2026 | xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection. | |
| Modificada | Crítica (9.8) | 1.5% | — | Blogotext Project Blogotext | 20/12/2017 | 17/6/2026 | validate_form_preferences in admin/preferences.php in BlogoText through 3.7.6 allows attackers to bypass intended access restrictions via vectors related to an e-mail address field. | |
| Modificada | Alta (7.5) | 2.2% | — | Blogotext Project Blogotext | 20/12/2017 | 17/6/2026 | Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a filename-randomization protection mechanism, and read backup archives on Windows servers, by providing the archiv~1.zip name (aka an 8.3 filename). | |
| Modificada | Media (6.1) | 1.0% | — | Blogotext Project Blogotext | 20/12/2017 | 17/6/2026 | Cross site scripting (XSS) vulnerability in the markup_clean_href function in inc/conv.php in BlogoText through 3.7.6 allows remote attackers to inject arbitrary JavaScript via a comment. | |
| Modificada | Alta (8.8) | 2.1% | — | Docuware Fulltext Server | 21/11/2017 | 17/6/2026 | The default installation of DocuWare Fulltext Search server through 6.11 allows remote users to connect to and download searchable text from the embedded Solr service, bypassing DocuWare's access control features of the DocuWare user interfaces and API. An attacker can also gain privileges by modifying text. The… | |
| Modificada | Alta (8.8) | 9.6% | 💥 PoC | Itextpdf Itext | 8/11/2017 | 17/6/2026 | The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF. | |
| Modificada | Alta (8.8) | 9.5% | 💥 Exploit | Opentext Documentum Content Server | 13/10/2017 | 17/6/2026 | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Server allows uploading content using batches (TAR archives). When unpacking TAR archives, Content Server fails to verify… | |
| Modificada | Media (4.3) | 4.9% | 💥 Exploit | Opentext Documentum Content Server | 13/10/2017 | 17/6/2026 | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows authenticated users to download arbitrary content files regardless of the attacker's repository permissions: When an authenticated user uploads content to the repository, he performs… | |
| Modificada | Alta (8.8) | 6.6% | 💥 Exploit | Opentext Documentum Content Server | 13/10/2017 | 17/6/2026 | OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Server stores information about uploaded files in dmr_content objects, which are queryable and "editable" (before release… |