Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.40% | — | Geminilabs Site Reviews | 22/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions. | |
| Modificada | Media (4.8) | 0.50% | — | Geminilabs Site Reviews | 2/5/2023 | 17/6/2026 | The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (6.1) | 0.79% | — | Resi Gemini-net | 2/6/2022 | 17/6/2026 | resi-calltrace in RESI Gemini-Net 4.2 is affected by Multiple XSS issues. Unauthenticated remote attackers can inject arbitrary web script or HTML into an HTTP GET parameter that reflects user input without sanitization. This exists on numerous application endpoints, | |
| Modificada | Crítica (9.8) | 1.7% | — | Resi Gemini-net | 12/5/2022 | 17/6/2026 | resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are processed on the server. Due to the lack of validation of user input, an unauthenticated attacker can bypass the syntax intended by the software (e.g., concatenate `&|;\r\… | |
| Modificada | Media (5.3) | 0.88% | — | Resi Gemini-net | 12/5/2022 | 17/6/2026 | RESI Gemini-Net Web 4.2 is affected by Improper Access Control in authorization logic. An unauthenticated user is able to access some critical resources. | |
| Modificada | Baja (2.4) | 0.24% | — | Phillips Gemini 882300 FirmwarePhillips Gemini 882160 FirmwarePhillips Gemini 882400 FirmwarePhillips Gemini 882390 Firmware+7 | 23/3/2022 | 17/6/2026 | Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control. | |
| Modificada | Media (6.1) | 1.3% | — | Geminilabs Site Reviews | 3/1/2022 | 17/6/2026 | The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin | |
| Modificada | Media (5.4) | 0.62% | — | Geminilabs Site Reviews | 6/9/2021 | 17/6/2026 | The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed | |
| Modificada | Media (6.1) | 1.3% | — | Geminilabs Site Reviews | 26/6/2018 | 17/6/2026 | Cross-site scripting vulnerability in Site Reviews versions prior to 2.15.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 2.5% | 💥 Exploit | Arzdev Gemini LiteArzdev Gemini Portal | 21/8/2009 | 16/6/2026 | admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to "admin" and setting the name parameter to "users." | |
| Modificada | Alta (9.3) | 3.0% | 💥 Exploit | Arzdev Gemini Portal | 23/10/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) page/forums/bottom.php and (2) page/forums/category.php. | |
| Modificada | Media (4.3) | 1.2% | — | Countersoft Gemini | 15/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in issue/createissue.aspx in Gemini 2.0 allows remote attackers to inject arbitrary web script or HTML via the rtcDescription$RadEditor1 field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |