Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.4% | — | Tikiwiki Cms/groupware | 12/2/2020 | 16/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code. | |
| Modificada | Media (6.1) | 7.7% | — | Tikiwiki Cms/groupware | 15/1/2020 | 16/6/2026 | Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php. | |
| Modificada | Crítica (9.8) | 2.2% | — | Kopano Groupware Core | 19/12/2019 | 17/6/2026 | HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data. | |
| Modificada | Media (6.5) | 2.1% | — | Horde GroupwareDebian Linux | 5/11/2019 | 17/6/2026 | Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php. | |
| Modificada | Media (5.3) | 1.1% | — | Horde GroupwareOpensuseDebian Linux | 5/11/2019 | 17/6/2026 | Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions | |
| Modificada | Alta (8.8) | 2.1% | — | Horde GroupwareDebian Linux | 5/11/2019 | 17/6/2026 | Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book | |
| Modificada | Alta (8.8) | 0.77% | — | Tikiwiki Cms/groupware | 28/10/2019 | 16/6/2026 | Tiki Wiki CMS Groupware 5.2 has CSRF | |
| Modificada | Media (6.1) | 1.2% | — | Tikiwiki Cms/groupware | 28/10/2019 | 16/6/2026 | Tiki Wiki CMS Groupware 5.2 has XSS | |
| Modificada | Crítica (9.8) | 13% | — | Tikiwiki Cms/groupware | 28/10/2019 | 16/6/2026 | Tiki Wiki CMS Groupware 5.2 has Local File Inclusion | |
| Modificada | Alta (8.8) | 1.1% | — | Horde Groupware | 24/10/2019 | 17/6/2026 | Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload. | |
| Modificada | Media (6.1) | 1.5% | — | Horde Groupware | 24/10/2019 | 17/6/2026 | Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI. | |
| Modificada | Media (5.4) | 0.86% | — | Tikiwiki Cms/groupware | 22/8/2019 | 17/6/2026 | tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI. | |
| Modificada | Alta (8.8) | 19% | — | Horde GroupwareDebian Linux | 29/5/2019 | 17/6/2026 | Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Horde_Form_Type_image method onSubmit() is called on uploads, it invokes the functions getImage() and _getUpload(), which uses unsanitized user… | |
| Modificada | Alta (8.8) | 1.00% | — | Tikiwiki Cms/groupware | 15/1/2019 | 17/6/2026 | In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter. | |
| Modificada | Media (5.4) | 0.68% | — | Tikiwiki Cms/groupware | 13/8/2018 | 17/6/2026 | Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image. | |
| Modificada | Media (5.4) | 0.68% | — | Tikiwiki Cms/groupware | 13/8/2018 | 17/6/2026 | Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php. | |
| Modificada | Media (5.4) | 0.50% | — | Tikiwiki Cms/groupware | 9/3/2018 | 17/6/2026 | Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1. | |
| Modificada | Media (5.4) | 0.54% | — | Tikiwiki Cms/groupware | 21/2/2018 | 17/6/2026 | The Calendar component in Tiki 17.1 allows HTML injection. | |
| Modificada | Media (5.4) | 0.52% | — | Tikiwiki Cms/groupware | 16/2/2018 | 17/6/2026 | An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with a malicious SVG image, related to lib/filegals/filegallib.php. | |
| Modificada | Media (6.1) | 0.64% | — | Tikiwiki Cms/groupware | 6/2/2018 | 17/6/2026 | tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie. | |
| Modificada | Media (5.4) | 1.8% | — | Horde Groupware | 20/11/2017 | 17/6/2026 | In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the CVE-2015-7984 CSRF protection mechanism can then be bypassed. | |
| Modificada | Media (5.4) | 1.1% | — | Horde Groupware | 20/11/2017 | 17/6/2026 | In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action. | |
| Modificada | Media (5.4) | 1.1% | — | Horde Groupware | 20/11/2017 | 17/6/2026 | In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a "Calendar -> New Event" action. | |
| Modificada | Alta (7.5) | 5.5% | — | Horde Groupware | 11/10/2017 | 17/6/2026 | The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponds to the exact filename. | |
| Modificada | Alta (8) | 0.51% | — | Tikiwiki Cms/groupware | 30/9/2017 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For… |