Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.23% | — | HaloAI | 5/8/2025 | 5/7/2026 | The reconcile method in the AttachmentReconciler class of the Halo system v.2.20.18LTS and before is vulnerable to XSS attacks. | |
| Aplazada | Alta (7.1) | 0.36% | — | HaloAI | 8/5/2025 | 17/6/2026 | Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing attackers to redirect users to malicious websites (Open Redirect) and inject JavaScript code to perform cross site scripting attack. The vulnerability affects Halo versions up to 2.174.101 and all… | |
| Modificada | Media (5.5) | 0.81% | — | Halo | 25/4/2025 | 17/6/2026 | Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This bypass enables the upload of malicious files including executables and HTML files, which can lead to stored cross-site scripting attacks and potential remote… | |
| Aplazada | Alta (7.1) | 0.39% | — | Shalomworld SW PlusAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shalomworld SW Plus shalom-world-media-gallery allows Reflected XSS.This issue affects SW Plus: from n/a through <= 2.1. | |
| Aplazada | Alta (7.1) | 0.28% | — | Punit Bhalodiya Killer Theme OptionsAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Punit Bhalodiya Killer Theme Options killer-theme-options allows Reflected XSS.This issue affects Killer Theme Options: from n/a through <= 2.0. | |
| Analizada | Media (6.4) | 0.33% | — | Halo | 11/9/2024 | 17/6/2026 | Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the user's browser through specific HTML and JavaScript code, potentially leading to a Cross-Site Scripting… | |
| Analizada | Media (6.1) | 0.35% | — | Halo | 2/9/2024 | 17/6/2026 | Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the user's browser through specific HTML and JavaScript code, potentially leading to a Cross-Site Scripting… | |
| Analizada | Alta (8.1) | 0.39% | — | Haloservicesolutions Haloitsm | 6/8/2024 | 17/6/2026 | HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent to existing HaloITSM users (given their email address is known). When these poisoned links get accessed (e.g. manually by the victim or automatically by an email client software), the… | |
| Analizada | Crítica (9.8) | 0.48% | — | Haloservicesolutions Haloitsm | 6/8/2024 | 17/6/2026 | HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arbitrary HaloITSM users by just knowing their email address. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the… | |
| Analizada | Media (5.3) | 0.31% | — | Haloservicesolutions Haloitsm | 6/8/2024 | 17/6/2026 | HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate emails. This can lead to the leakage of potentially sensitive information. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability. | |
| Analizada | Media (5.4) | 0.36% | — | Haloservicesolutions Haloitsm | 6/8/2024 | 17/6/2026 | HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScript code can execute arbitrary action on behalf of the user accessing a ticket. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability. | |
| Modificada | Media (6.1) | 0.31% | — | Halo | 28/3/2024 | 17/6/2026 | halo v1.6.0 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Media (4.8) | 0.69% | — | Halo | 10/3/2023 | 9/7/2026 | An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file. | |
| Modificada | Crítica (9.8) | 1.1% | — | Elsight Halo Firmware | 17/11/2022 | 17/6/2026 | Elsight – Elsight Halo Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION parameter and leverage it to remote code execution. | |
| Modificada | Crítica (9.8) | 18% | — | Halo | 27/6/2022 | 17/6/2026 | Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function. | |
| Modificada | Crítica (9.8) | 19% | — | Halo | 27/6/2022 | 17/6/2026 | Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload. | |
| Modificada | Media (4.8) | 0.43% | — | Fit2cloud Halo | 22/4/2022 | 17/6/2026 | Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools. | |
| Modificada | Alta (7.5) | 0.88% | — | Halo | 5/4/2022 | 17/6/2026 | Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function. | |
| Modificada | Media (5.4) | 0.55% | — | Halo | 24/3/2022 | 17/6/2026 | In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS vulnerability. | |
| Modificada | Media (4.8) | 0.83% | — | Halo | 13/1/2022 | 17/6/2026 | In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An authenticated admin attacker can inject arbitrary javascript code that will execute on a victim’s server. | |
| Modificada | Media (5.4) | 0.71% | — | Fit2cloud Halo | 13/1/2022 | 17/6/2026 | In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An authenticated attacker can upload a carefully crafted SVG file that will trigger arbitrary javascript to run on a victim’s browser. | |
| Modificada | Media (5.4) | 0.71% | — | Fit2cloud Halo | 13/1/2022 | 17/6/2026 | In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. An authenticated attacker can inject arbitrary javascript code that will execute on a victim’s server. | |
| Modificada | Media (5.3) | 0.69% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware update with verified firmware. | |
| Modificada | Media (5.3) | 0.49% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker. | |
| Modificada | Media (6.5) | 0.42% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password. |