Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.1%—Jenkins Chef Sinatra15/2/202217/6/2026
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
ModificadaAlta (8.8)0.72%—Jenkins Chef Sinatra15/2/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
ModificadaAlta (7.8)0.27%—SAP Business-one-hana-chef-cookbookSAP Business ONE11/5/202117/6/2026
Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted, resulting in Information Disclosure…
ModificadaAlta (7.1)0.26%—SAP Business-one-hana-chef-cookbookSAP Business ONE11/5/202117/6/2026
SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application thereby highly impacting the integrity and…
ModificadaAlta (7.8)0.26%—SAP Chef Business-one-cookbook11/5/202117/6/2026
Under certain conditions, SAP Business One Chef cookbook, version - 9.2, 9.3, 10.0, used to install SAP Business One, allows an attacker to exploit an insecure temporary folder for incoming & outgoing payroll data and to access information which would otherwise be restricted, which could lead to Information Disclosure…
ModificadaAlta (8.8)22%—Apachefriends Xampp2/4/202017/6/2026
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.
ModificadaMedia (6.1)1.3%—Gchq Cyberchef26/8/201917/6/2026
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
ModificadaMedia (6.1)0.84%—Apachefriends Xampp9/7/201917/6/2026
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
ModificadaAlta (8.8)1.1%—Wpchef Widget Logic1/7/201917/6/2026
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility) by crafting a malicious POST request…
ModificadaMedia (6.1)5.7%—Apachefriends Xampp17/5/201917/6/2026
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
ModificadaCrítica (9.8)3.9%—Apachefriends Xampp14/5/201917/6/2026
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.
ModificadaMedia (6.5)1.5%—Jenkins Chef Sinatra4/4/201917/6/2026
A missing permission check in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
ModificadaMedia (6.5)1.3%—Jenkins Chef Sinatra4/4/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
ModificadaAlta (7.5)1.9%—Chef21/9/201717/6/2026
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
ModificadaAlta (7.5)1.3%—Bluecoat Advanced Secure GatewayBluecoat CacheflowBluecoat Proxysg8/6/201717/6/2026
Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning.
ModificadaCrítica (9.8)2.4%—Chef Manage Project Chef Manage17/3/201717/6/2026
The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code. This is fixed in 2.4.5.
ModificadaCrítica (9.8)4.2%—Chef Manage10/6/201617/6/2026
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.
ModificadaMedia (4.3)5.2%—Apachefriends Xampp29/9/201416/6/2026
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method.
ModificadaMedia (5.4)0.27%—Penguinchefshop Project Penguinchefshop9/9/201417/6/2026
The penguinchefshop (aka com.freegames.penguinchefshop) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.5)1.7%—Opscode Chef8/8/201216/6/2026
chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and…
ModificadaMedia (5.5)1.4%—Opscode Chef8/8/201216/6/2026
chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileges for the update and destroy methods, which allows remote authenticated users to (1) upload cookbooks via a knife cookbook upload command or (2) delete cookbooks via a…
ModificadaMedia (6.5)1.6%—Opscode Chef8/8/201216/6/2026
chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.
ModificadaMedia (5.5)1.6%—Apachefriends Xampp20/3/200916/6/2026
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated by setting the REMOTE_ADDR variable to 127.0.0.1.
ModificadaMedia (6.8)1.0%—Apachefriends Xampp20/3/200916/6/2026
Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for requests that change a certain .htaccess password via the xampppasswd parameter.
ModificadaAlta (7.5)9.0%—Apachefriends Xampp16/3/200916/6/2026
XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL…