Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

42 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.72%—Jenkins Anchore Container Image Scanner21/9/202217/6/2026
Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control API responses by Anchore engine.
ModificadaAlta (7.5)0.70%—AnchoreAnchorectl20/7/202217/6/2026
Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Materials (SBOM) generated by anchorectl. Users of anchorectl version 0.1.4 should upgrade to…
ModificadaMedia (4.5)0.40%—Anchorcms Anchor CMS24/3/202217/6/2026
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This vulnerability allows attackers to arbitrarily delete posts.
ModificadaMedia (5.4)0.62%—Anchorcms Anchor CMS1/2/202217/6/2026
A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML.
ModificadaMedia (6.1)0.75%—Anchorcms Anchor CMS15/12/202117/6/2026
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achieving other malicious operations.
ModificadaMedia (6.1)1.2%—Anchorme Project Anchorme21/7/202117/6/2026
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts input that can result in the output (an anchor a tag) containing undesirable Javascript code that can be executed upon user interaction.
ModificadaAlta (8.8)12%💥 ExploitAnchorcms Anchor CMS19/1/202117/6/2026
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
ModificadaCrítica (9.9)1.8%—Anchore Engine27/5/202017/6/2026
In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to trigger a shell escape flaw in the anchore engine analyzer service during an image analysis process. The image analysis operation can only be executed by an authenticated user via a valid API request…
ModificadaMedia (4.8)0.56%—Anchorcms Anchor23/4/202017/6/2026
Anchor 0.12.7 allows admins to cause XSS via crafted post content.
ModificadaMedia (6.5)0.85%—Jenkins Anchore Container Image Scanner21/11/201917/6/2026
Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
ModificadaMedia (6.5)0.87%—Anchore Container Image Scanner1/8/201817/6/2026
An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java that allows attackers with Item/ExtendedRead permission or file system access to the Jenkins master to obtain the password stored in this plugin's configuration.
ModificadaCrítica (9.8)72%💥 ExploitAnchorcms Anchor19/2/201817/6/2026
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.
ModificadaAlta (7.5)11%💥 ExploitAnchorfree Hotspot Shield31/1/201817/6/2026
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including configuration. User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter…
ModificadaMedia (6.1)0.65%—Anchorcms Anchor CMS7/9/201717/6/2026
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
ModificadaAlta (7.5)2.5%—Anchorcms Anchor CMS5/10/201517/6/2026
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.
ModificadaMedia (4.3)1.0%—Anchorcms Anchor CMS2/12/201417/6/2026
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.
ModificadaBaja (2.6)1.7%💥 ExploitAnchor CMS9/8/201316/6/2026
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Name field. NOTE: some sources have reported that comments.php is vulnerable, but certain functions from comments.php are used by article.php.
Orbitaley — Vulnerabilidades