Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.56% | — | Pukiwiki | 23/8/2022 | 17/6/2026 | Stored cross-site scripting vulnerability in PukiWiki versions 1.3.1 to 1.5.3 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Alta (7.2) | 1.3% | — | Pukiwiki | 23/8/2022 | 17/6/2026 | Path traversal vulnerability in PukiWiki versions 1.4.5 to 1.5.3 allows a remote authenticated attacker with an administrative privilege to execute a malicious script via unspecified vectors. | |
| Modificada | Media (6.1) | 0.58% | — | Pukiwiki | 23/8/2022 | 17/6/2026 | Reflected cross-site scripting vulnerability in PukiWiki versions 1.5.1 to 1.5.3 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (6.1) | 0.89% | — | LibkiwixFedoraproject Fedora | 25/3/2022 | 17/6/2026 | libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0. | |
| Modificada | Media (4.3) | 0.96% | — | Solarwinds Kiwi Syslog Server | 29/10/2021 | 17/6/2026 | A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transparent iframe in a window to trick a user into clicking on an actionable item, such as a button or link, to another server in which they have… | |
| Modificada | Media (5.4) | 0.50% | — | Tikiwiki Cms/groupware | 28/10/2021 | 17/6/2026 | TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Add Event module. | |
| Modificada | Media (5.4) | 0.50% | — | Tikiwiki Cms/groupware | 28/10/2021 | 17/6/2026 | TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Create category module. | |
| Modificada | Media (5.3) | 0.52% | — | Solarwinds Kiwi Syslog Server | 27/10/2021 | 17/6/2026 | The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send the cookie if the request is being sent over a secure channel such as HTTPS. This will help protect the cookie from being passed over unencrypted requests. If the… | |
| Modificada | Media (5.3) | 1.3% | — | Solarwinds Kiwi Syslog Server | 27/10/2021 | 17/6/2026 | The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web applications, if configured to do so. Debug mode causes ASP.NET to compile applications with extra information. The information enables a debugger to closely monitor and control the… | |
| Modificada | Media (5.3) | 0.96% | — | Solarwinds Kiwi Syslog Server | 27/10/2021 | 17/6/2026 | The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respond to requests that use these methods by returning exact HTTP request that was received in the response to the client. This may lead to the… | |
| Modificada | Media (6.7) | 0.27% | — | Solarwinds Kiwi Syslog Server | 25/10/2021 | 17/6/2026 | As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry. Example vulnerable path:… | |
| Modificada | Media (6.7) | 0.33% | — | Solarwinds Kiwi Cattools | 22/10/2021 | 17/6/2026 | As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry. | |
| Modificada | Alta (8.8) | 1.5% | 💥 PoC | Tikiwiki Cms/groupware | 11/12/2020 | 17/6/2026 | TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management… | |
| Modificada | Media (6.1) | 0.87% | — | Tikiwiki Cms/groupware | 1/4/2020 | 17/6/2026 | There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a legitimate web page. | |
| Modificada | Media (6.1) | 1.4% | — | Tikiwiki Cms/groupware | 12/2/2020 | 16/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code. | |
| Modificada | Media (6.1) | 7.7% | 💥 Exploit | Tikiwiki Cms/groupware | 15/1/2020 | 16/6/2026 | Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php. | |
| Modificada | Media (6.1) | 1.7% | — | IkiwikiFedoraproject Fedora | 21/11/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify action to ikiwiki.cgi. | |
| Modificada | Media (6.1) | 0.83% | — | Ikiwiki | 30/10/2019 | 16/6/2026 | A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment. | |
| Modificada | Alta (8.2) | 1.6% | — | IkiwikiDebian Linux | 29/10/2019 | 16/6/2026 | ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks. | |
| Modificada | Media (6.1) | 0.84% | — | Ikiwiki | 29/10/2019 | 16/6/2026 | Cross Site Scripting (XSS) in ikiwiki before 3.20110122 could allow remote attackers to insert arbitrary JavaScript due to insufficient checking in comments. | |
| Modificada | Alta (8.8) | 0.77% | — | Tikiwiki Cms/groupware | 28/10/2019 | 16/6/2026 | Tiki Wiki CMS Groupware 5.2 has CSRF | |
| Modificada | Media (6.1) | 1.2% | — | Tikiwiki Cms/groupware | 28/10/2019 | 16/6/2026 | Tiki Wiki CMS Groupware 5.2 has XSS | |
| Modificada | Crítica (9.8) | 13% | 💥 Exploit | Tikiwiki Cms/groupware | 28/10/2019 | 16/6/2026 | Tiki Wiki CMS Groupware 5.2 has Local File Inclusion | |
| Modificada | Media (6.5) | 0.87% | — | Kiwi-logo-carousel Project Kiwi-logo-carousel | 26/9/2019 | 17/6/2026 | The kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=kwlogos&page=kwlogos_settings tab or tab_flags_order parameter. | |
| Modificada | Media (5.4) | 0.86% | — | Tikiwiki Cms/groupware | 22/8/2019 | 17/6/2026 | tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI. |