Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.56%—Pukiwiki23/8/202217/6/2026
Stored cross-site scripting vulnerability in PukiWiki versions 1.3.1 to 1.5.3 allows a remote attacker to inject an arbitrary script via unspecified vectors.
ModificadaAlta (7.2)1.3%—Pukiwiki23/8/202217/6/2026
Path traversal vulnerability in PukiWiki versions 1.4.5 to 1.5.3 allows a remote authenticated attacker with an administrative privilege to execute a malicious script via unspecified vectors.
ModificadaMedia (6.1)0.58%—Pukiwiki23/8/202217/6/2026
Reflected cross-site scripting vulnerability in PukiWiki versions 1.5.1 to 1.5.3 allows a remote attacker to inject an arbitrary script via unspecified vectors.
ModificadaMedia (6.1)0.89%—LibkiwixFedoraproject Fedora25/3/202217/6/2026
libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.
ModificadaMedia (4.3)0.96%—Solarwinds Kiwi Syslog Server29/10/202117/6/2026
A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an actionable item, such as a button or link, to another server in which they have…
ModificadaMedia (5.4)0.50%—Tikiwiki Cms/groupware28/10/202117/6/2026
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Add Event module.
ModificadaMedia (5.4)0.50%—Tikiwiki Cms/groupware28/10/202117/6/2026
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Create category module.
ModificadaMedia (5.3)0.52%—Solarwinds Kiwi Syslog Server27/10/202117/6/2026
The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send the cookie if the request is being sent over a secure channel such as HTTPS. This will help protect the cookie from being passed over unencrypted requests. If the…
ModificadaMedia (5.3)1.3%—Solarwinds Kiwi Syslog Server27/10/202117/6/2026
The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web applications, if configured to do so. Debug mode causes ASP.NET to compile applications with extra information. The information enables a debugger to closely monitor and control the…
ModificadaMedia (5.3)0.96%—Solarwinds Kiwi Syslog Server27/10/202117/6/2026
The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respond to requests that use these methods by returning exact HTTP request that was received in the response to the client. This may lead to the…
ModificadaMedia (6.7)0.27%—Solarwinds Kiwi Syslog Server25/10/202117/6/2026
As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry. Example vulnerable path:…
ModificadaMedia (6.7)0.33%—Solarwinds Kiwi Cattools22/10/202117/6/2026
As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry.
ModificadaAlta (8.8)1.5%💥 PoCTikiwiki Cms/groupware11/12/202017/6/2026
TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management…
ModificadaMedia (6.1)0.87%—Tikiwiki Cms/groupware1/4/202017/6/2026
There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a legitimate web page.
ModificadaMedia (6.1)1.4%—Tikiwiki Cms/groupware12/2/202016/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code.
ModificadaMedia (6.1)7.7%💥 ExploitTikiwiki Cms/groupware15/1/202016/6/2026
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
ModificadaMedia (6.1)1.7%—IkiwikiFedoraproject Fedora21/11/201917/6/2026
Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify action to ikiwiki.cgi.
ModificadaMedia (6.1)0.83%—Ikiwiki30/10/201916/6/2026
A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment.
ModificadaAlta (8.2)1.6%—IkiwikiDebian Linux29/10/201916/6/2026
ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.
ModificadaMedia (6.1)0.84%—Ikiwiki29/10/201916/6/2026
Cross Site Scripting (XSS) in ikiwiki before 3.20110122 could allow remote attackers to insert arbitrary JavaScript due to insufficient checking in comments.
ModificadaAlta (8.8)0.77%—Tikiwiki Cms/groupware28/10/201916/6/2026
Tiki Wiki CMS Groupware 5.2 has CSRF
ModificadaMedia (6.1)1.2%—Tikiwiki Cms/groupware28/10/201916/6/2026
Tiki Wiki CMS Groupware 5.2 has XSS
ModificadaCrítica (9.8)13%💥 ExploitTikiwiki Cms/groupware28/10/201916/6/2026
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
ModificadaMedia (6.5)0.87%—Kiwi-logo-carousel Project Kiwi-logo-carousel26/9/201917/6/2026
The kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=kwlogos&page=kwlogos_settings tab or tab_flags_order parameter.
ModificadaMedia (5.4)0.86%—Tikiwiki Cms/groupware22/8/201917/6/2026
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.
Orbitaley — Vulnerabilidades