Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | Jenkins Chef Sinatra | 15/2/2022 | 17/6/2026 | A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response. | |
| Modificada | Alta (8.8) | 0.72% | — | Jenkins Chef Sinatra | 15/2/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response. | |
| Modificada | Alta (7.8) | 0.27% | — | SAP Business-one-hana-chef-cookbookSAP Business ONE | 11/5/2021 | 17/6/2026 | Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted, resulting in Information Disclosure… | |
| Modificada | Alta (7.1) | 0.26% | — | SAP Business-one-hana-chef-cookbookSAP Business ONE | 11/5/2021 | 17/6/2026 | SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application thereby highly impacting the integrity and… | |
| Modificada | Alta (7.8) | 0.26% | — | SAP Chef Business-one-cookbook | 11/5/2021 | 17/6/2026 | Under certain conditions, SAP Business One Chef cookbook, version - 9.2, 9.3, 10.0, used to install SAP Business One, allows an attacker to exploit an insecure temporary folder for incoming & outgoing payroll data and to access information which would otherwise be restricted, which could lead to Information Disclosure… | |
| Modificada | Alta (8.8) | 22% | — | Apachefriends Xampp | 2/4/2020 | 17/6/2026 | An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution. | |
| Modificada | Media (6.1) | 1.3% | — | Gchq Cyberchef | 26/8/2019 | 17/6/2026 | CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs. | |
| Modificada | Media (6.1) | 0.84% | — | Apachefriends Xampp | 9/7/2019 | 17/6/2026 | iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569. | |
| Modificada | Alta (8.8) | 1.1% | — | Wpchef Widget Logic | 1/7/2019 | 17/6/2026 | A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility) by crafting a malicious POST request… | |
| Modificada | Media (6.1) | 5.7% | — | Apachefriends Xampp | 17/5/2019 | 17/6/2026 | XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued. | |
| Modificada | Crítica (9.8) | 3.9% | — | Apachefriends Xampp | 14/5/2019 | 17/6/2026 | XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued. | |
| Modificada | Media (6.5) | 1.5% | — | Jenkins Chef Sinatra | 4/4/2019 | 17/6/2026 | A missing permission check in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | |
| Modificada | Media (6.5) | 1.3% | — | Jenkins Chef Sinatra | 4/4/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server. | |
| Modificada | Alta (7.5) | 1.9% | — | Chef | 21/9/2017 | 17/6/2026 | The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages. | |
| Modificada | Alta (7.5) | 1.3% | — | Bluecoat Advanced Secure GatewayBluecoat CacheflowBluecoat Proxysg | 8/6/2017 | 17/6/2026 | Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning. | |
| Modificada | Crítica (9.8) | 2.4% | — | Chef Manage Project Chef Manage | 17/3/2017 | 17/6/2026 | The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code. This is fixed in 2.4.5. | |
| Modificada | Crítica (9.8) | 4.2% | — | Chef Manage | 10/6/2016 | 17/6/2026 | The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie. | |
| Modificada | Media (4.3) | 5.2% | — | Apachefriends Xampp | 29/9/2014 | 16/6/2026 | XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method. | |
| Modificada | Media (5.4) | 0.27% | — | Penguinchefshop Project Penguinchefshop | 9/9/2014 | 17/6/2026 | The penguinchefshop (aka com.freegames.penguinchefshop) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.5) | 1.7% | — | Opscode Chef | 8/8/2012 | 16/6/2026 | chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and… | |
| Modificada | Media (5.5) | 1.4% | — | Opscode Chef | 8/8/2012 | 16/6/2026 | chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileges for the update and destroy methods, which allows remote authenticated users to (1) upload cookbooks via a knife cookbook upload command or (2) delete cookbooks via a… | |
| Modificada | Media (6.5) | 1.6% | — | Opscode Chef | 8/8/2012 | 16/6/2026 | chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI. | |
| Modificada | Media (5.5) | 1.6% | — | Apachefriends Xampp | 20/3/2009 | 16/6/2026 | security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated by setting the REMOTE_ADDR variable to 127.0.0.1. | |
| Modificada | Media (6.8) | 1.0% | — | Apachefriends Xampp | 20/3/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for requests that change a certain .htaccess password via the xampppasswd parameter. | |
| Modificada | Alta (7.5) | 9.0% | — | Apachefriends Xampp | 16/3/2009 | 16/6/2026 | XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL… |