Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 7.9% | 💥 Exploit | Alfresco Community EditionAI | 17/6/2025 | 17/6/2026 | Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch. | |
| Aplazada | Media (6.8) | 0.40% | — | Portainer Community EditionAI | 17/6/2025 | 17/6/2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Prior to STS version 2.31.0 and LTS version 2.27.7, if a Portainer administrator can be convinced to register a malicious container registry,… | |
| Aplazada | Media (6.3) | 0.14% | — | OtrsAIOtrs Community EditionAI | 27/1/2025 | 17/6/2026 | Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator. This issue affects: Products based on the ((OTRS)) Community Edition also very likely to be affected | |
| Aplazada | Baja (3.5) | 0.22% | — | OtrsAIOtrs Community EditionAI | 27/1/2025 | 17/6/2026 | An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: Products based on the ((OTRS)) Community Edition also very likely to be affected | |
| Aplazada | Media (6.9) | 0.58% | — | Hyland Alfresco Community EditionAIHyland Alfresco Enterprise EditionAI | 18/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part of the file /share/s/ of the component URL Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Aplazada | Alta (8.2) | 0.38% | — | OtrsAIOtrs Community EditionAI | 26/8/2024 | 17/6/2026 | Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled. This issue affects: Products based on the ((OTRS)) Community Edition also very likely to be… | |
| Aplazada | Media (4.9) | 0.36% | — | OtrsAIOtrs Community EditionAI | 26/8/2024 | 17/6/2026 | Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins. This issue affects: Products based on the ((OTRS)) Community… | |
| Aplazada | Media (6.3) | 0.78% | — | OtrsAIOtrs Community EditionAI | 6/6/2024 | 17/6/2026 | The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits authenticated agents or customer users to upload potentially harmful files to directories accessible by the web server, potentially leading to the execution of local code like Perl scripts. This issue… | |
| Aplazada | Media (5.4) | 0.48% | — | ANT Media Server Community EditionAI | 14/5/2024 | 17/6/2026 | Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users. All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor… | |
| Aplazada | Alta (7.5) | 0.84% | 💥 PoC | Sheetjs Community EditionAI | 5/4/2024 | 17/6/2026 | SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS). | |
| Modificada | Media (6.5) | 1.3% | — | Tibco Jasperreports Library Community EditionTibco Jasperreports Library FOR Activematrix BPMTibco Jasperreports ProfessionalTibco Jasperreports Server+5 | 29/6/2017 | 17/6/2026 | JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReports Library Community Edition (versions 6.4.0 and below), TIBCO JasperReports Library for… | |
| Modificada | Media (5) | 2.0% | 💥 Exploit | Alfresco Community Edition | 7/12/2014 | 17/6/2026 | Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition 5.0.a and earlier allows remote attackers to trigger outbound requests via a crafted URI in the url parameter. |