Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.48% | — | Activecampaign FOR Woocommerce | 9/1/2023 | 17/6/2026 | The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs. | |
| Modificada | Alta (7.6) | 0.12% | — | Alivecor Kardiamobile FirmwareAlivecor Kardiamobile 6L FirmwareAlivecor Kardiamobile Card Firmware | 27/10/2022 | 17/6/2026 | The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-over-sound protocols. Exploiting this vulnerability could allow an attacker to read patient EKG results or create a denial-of-service condition by emitting sounds at similar… | |
| Modificada | Media (6.1) | 0.34% | — | Alivecor Kardia | 26/10/2022 | 17/6/2026 | CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app. | |
| Modificada | Media (6.1) | 0.77% | — | Rocket.chat Livechat | 1/4/2022 | 17/6/2026 | A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance. | |
| Modificada | Media (6.5) | 1.1% | — | Liveconfig | 18/2/2022 | 17/6/2026 | A Path Traversal vulnerability for a log file in LiveConfig 2.12.2 allows authenticated attackers to read files on the underlying server. | |
| Modificada | Media (5.4) | 0.48% | — | Liveconfig | 18/2/2022 | 17/6/2026 | A Stored XSS issue exists in the admin/users user administration form in LiveConfig 2.12.2. | |
| Modificada | Media (4.3) | 0.47% | — | Activecampaign | 18/3/2021 | 17/6/2026 | Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could allow attacker to make a logged-in administrator change API Credentials to attacker's account. | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Livefyre Livecomments | 27/12/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded picture. | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Livecrm Saas Cloud | 24/1/2018 | 17/6/2026 | SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request. | |
| Modificada | Crítica (9.8) | 1.9% | — | Wp-olivecart OlivecartWp-olivecart Olivecartpro | 22/5/2017 | 17/6/2026 | SQL injection vulnerability in the WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows attackers with administrator rights to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.92% | — | Wp-olivecart OlivecartWp-olivecart Olivecartpro | 22/5/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to hijack the authentication of a user to perform unintended operations via unspecified vectors. | |
| Modificada | Media (6.1) | 1.2% | — | Wp-olivecart OlivecartWp-olivecart Olivecartpro | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 2.6% | — | Adobe Experience Manager FormsAdobe Livecycle | 15/12/2016 | 17/6/2026 | Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that could be used in cross-site scripting attacks. | |
| Modificada | Media (6.1) | 2.0% | — | Adobe Experience ManagerAdobe Livecycle | 15/12/2016 | 17/6/2026 | Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the AACComponent that could be used in cross-site scripting attacks. | |
| Modificada | Media (4.3) | 4.5% | — | HP XP P9000 Command View Advanced EditionHP XP7 Command View Advanced EditionAdobe ColdfusionAdobe Livecycle Data Services | 18/11/2015 | 17/6/2026 | Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a… | |
| Modificada | Media (5) | 9.8% | — | HP Business Service ManagementAdobe Livecycle Data Services | 25/8/2015 | 17/6/2026 | Apache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4.6.2 before 4.6.2.354169, and 4.7 before 4.7.0.354169 and other products, allows remote attackers to read arbitrary files via an AMF message containing an XML external… | |
| Modificada | Media (6.8) | 2.8% | — | Adaptivecomputing Torque Resource Manager | 30/10/2014 | 17/6/2026 | The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and earlier does not validate that the owner of the process also owns the adopted session id, which allows remote authenticated users to kill arbitrary processes via a crafted… | |
| Modificada | Media (4) | 1.7% | — | Adaptivecomputing Moab | 8/10/2014 | 17/6/2026 | Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0, when a pre-generated key is used, does not validate that the requesting user matches the actor in the message, which allows remote authenticated users to impersonate arbitrary users via the actor field in a message. | |
| Modificada | Media (4) | 1.7% | — | Adaptivecomputing Moab | 8/10/2014 | 17/6/2026 | The server in Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 does not properly validate the message owner matches the submitting user, which allows remote authenticated users to impersonate arbitrary users via the UserId and Owner tags. | |
| Modificada | Media (5) | 7.4% | 💥 Exploit | Adaptivecomputing Moab | 8/10/2014 | 17/6/2026 | Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execute commands via a message without a signature. | |
| Modificada | Alta (10) | 17% | 💥 Exploit | Adaptivecomputing Torque Resource Manager | 16/5/2014 | 17/6/2026 | Stack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x through 2.5.13 allows remote attackers to execute arbitrary code via a large count value. | |
| Modificada | Alta (10) | 3.3% | — | Adaptivecomputing Torque Resource Manager | 20/11/2013 | 16/6/2026 | The send_the_mail function in server/svr_mail.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 4.2.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the email (-M switch) to qsub. | |
| Modificada | Alta (9) | 2.9% | — | Adaptivecomputing Torque Resource Manager | 11/10/2013 | 16/6/2026 | pbs_mom in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x, 4.x, and earlier does not properly restrict access by unprivileged ports, which allows remote authenticated users to execute arbitrary jobs by submitting a command. | |
| Modificada | Alta (7.2) | 0.34% | — | Redhat Livecd-tools | 29/5/2013 | 16/6/2026 | Red Hat livecd-tools before 13.4.4, 17.x before 17.17, 18.x before 18.16, and 19.x before 19.3, when a rootpw directive is not set in a Kickstart file, sets the root user password to empty, which allows local users to gain privileges. | |
| Modificada | Media (6.5) | 17% | 💥 Exploit | A51dev Activecollab Chat Module | 23/5/2013 | 16/6/2026 | functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the message[message_text] parameter to chat/add_messag, which is not properly handled when executing the preg_replace function with the eval switch. |