Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)1.5%—Pydio Cells4/6/202017/6/2026
Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web application. The extracted files will be placed in the targeted user…
ModificadaAlta (7.2)1.7%—Pydio Cells4/6/202017/6/2026
Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator role. This console provides an administrator user with the possibility of changing several settings, including the application’s mailer configuration. It is possible to configure a…
ModificadaAlta (8.8)3.1%—Aspose.cells21/8/201917/6/2026
An exploitable out-of-bounds read vulnerability exists in the Number record parser of Aspose Aspose.Cells 19.1.0 library. A specially crafted XLS file can cause an out-of-bounds read, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.
ModificadaAlta (8.8)3.1%—Aspose.cells21/8/201917/6/2026
An exploitable out-of-bounds read vulnerability exists in the LabelSst record parser of Aspose Aspose.Cells 19.1.0 library. A specially crafted XLS file can cause an out-of-bounds read, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.
ModificadaMedia (4.3)0.93%—Pydio Cells20/6/201917/6/2026
Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and includes the database column/table name as pert of the error message, exposing sensitive information.
ModificadaMedia (6.5)1.1%—Pydio Cells20/6/201917/6/2026
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data.
ModificadaAlta (8.8)1.7%—Pydio Cells20/6/201917/6/2026
Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.
ModificadaMedia (6.5)1.0%—Pivotal Software Windows Stemcells17/5/201817/6/2026
Windows 2012R2 stemcells, versions prior to 1200.17, contain an information exposure vulnerability on vSphere. A remote user with the ability to push apps can execute crafted commands to read the IaaS metadata from the VM, which may contain BOSH credentials.
ModificadaAlta (8.5)0.64%—Pivotal Software Windows Stemcells19/3/201817/6/2026
In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are able to access the metadata endpoint. A malicious developer could use this access to gain privileged credentials.
ModificadaAlta (8.8)0.97%—Cells Blog28/12/201717/6/2026
Cells Blog 3.5 has SQL Injection via the pub_readpost.php ptid parameter.
ModificadaMedia (6.1)0.66%—Cells Blog28/12/201717/6/2026
Cells Blog 3.5 has XSS via the pub_readpost.php fmid parameter.
ModificadaMedia (6.1)0.66%—Cells Blog28/12/201717/6/2026
Cells Blog 3.5 has XSS via the jfdname parameter in an act=showpic request.