Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.72% | — | Jenkins Anchore Container Image Scanner | 21/9/2022 | 17/6/2026 | Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control API responses by Anchore engine. | |
| Modificada | Alta (7.5) | 0.70% | — | AnchoreAnchorectl | 20/7/2022 | 17/6/2026 | Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Materials (SBOM) generated by anchorectl. Users of anchorectl version 0.1.4 should upgrade to… | |
| Modificada | Media (4.5) | 0.40% | — | Anchorcms Anchor CMS | 24/3/2022 | 17/6/2026 | Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This vulnerability allows attackers to arbitrarily delete posts. | |
| Modificada | Media (5.4) | 0.62% | — | Anchorcms Anchor CMS | 1/2/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Media (6.1) | 0.75% | — | Anchorcms Anchor CMS | 15/12/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achieving other malicious operations. | |
| Modificada | Media (6.1) | 1.2% | — | Anchorme Project Anchorme | 21/7/2021 | 17/6/2026 | Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts input that can result in the output (an anchor a tag) containing undesirable Javascript code that can be executed upon user interaction. | |
| Modificada | Alta (8.8) | 12% | 💥 Exploit | Anchorcms Anchor CMS | 19/1/2021 | 17/6/2026 | A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users. | |
| Modificada | Crítica (9.9) | 1.8% | — | Anchore Engine | 27/5/2020 | 17/6/2026 | In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to trigger a shell escape flaw in the anchore engine analyzer service during an image analysis process. The image analysis operation can only be executed by an authenticated user via a valid API request… | |
| Modificada | Media (4.8) | 0.56% | — | Anchorcms Anchor | 23/4/2020 | 17/6/2026 | Anchor 0.12.7 allows admins to cause XSS via crafted post content. | |
| Modificada | Media (6.5) | 0.85% | — | Jenkins Anchore Container Image Scanner | 21/11/2019 | 17/6/2026 | Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (6.5) | 0.87% | — | Anchore Container Image Scanner | 1/8/2018 | 17/6/2026 | An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java that allows attackers with Item/ExtendedRead permission or file system access to the Jenkins master to obtain the password stored in this plugin's configuration. | |
| Modificada | Crítica (9.8) | 72% | 💥 Exploit | Anchorcms Anchor | 19/2/2018 | 17/6/2026 | An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Anchorfree Hotspot Shield | 31/1/2018 | 17/6/2026 | Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including configuration. User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter… | |
| Modificada | Media (6.1) | 0.65% | — | Anchorcms Anchor CMS | 7/9/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev. | |
| Modificada | Alta (7.5) | 2.5% | — | Anchorcms Anchor CMS | 5/10/2015 | 17/6/2026 | system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie. | |
| Modificada | Media (4.3) | 1.0% | — | Anchorcms Anchor CMS | 2/12/2014 | 17/6/2026 | models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header. | |
| Modificada | Baja (2.6) | 1.7% | 💥 Exploit | Anchor CMS | 9/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Name field. NOTE: some sources have reported that comments.php is vulnerable, but certain functions from comments.php are used by article.php. |