Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.85% | — | Ari-soft ARI Adminer | 15/9/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' function is called. | |
| Modificada | Media (6.1) | 9.6% | 💥 Exploit | Adminer | 19/5/2021 | 17/6/2026 | Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer is using a `pdo_` extension to… | |
| Analizada | Alta (7.2) | 98% | ⚠ Explotación activa💥 Exploit | AdminerDebian Linux | 11/2/2021 | 17/6/2026 | Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9. | |
| Modificada | Media (6.1) | 2.0% | — | Adminer | 9/2/2021 | 17/6/2026 | Adminer through 4.7.8 allows XSS via the history parameter to the default URI. | |
| Modificada | Crítica (9.8) | 2.9% | — | Docker Adminer | 17/12/2020 | 17/6/2026 | The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 4.4% | — | Adminer | 5/3/2018 | 17/6/2026 | Adminer through 4.3.1 has SSRF via the server parameter. |