Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

48 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.97%—Lemon8 Project Lemon824/10/202217/6/2026
Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing…
ModificadaCrítica (9.8)1.2%—Lemonldap-ng Lemonldap\Debian Linux18/7/202217/6/2026
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in,…
ModificadaAlta (7.5)0.77%—Lemonldap-ng Lemonldap\Debian Linux18/7/202217/6/2026
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.
ModificadaMedia (6.1)0.72%—Mossle Lemon22/12/202117/6/2026
A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.
ModificadaMedia (6.1)0.72%—Mossle Lemon22/12/202117/6/2026
A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.
ModificadaAlta (8.8)1.8%—Lemonldap-ng Lemonldap\Debian Linux30/7/202117/6/2026
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.
ModificadaCrítica (9.8)2.4%—Lemonldap-ng Lemonldap\Debian Linux14/9/202017/6/2026
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
ModificadaCrítica (9.8)2.5%—Lemonldap-ng Lemonldap\Debian Linux25/9/201917/6/2026
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no…
ModificadaAlta (8.1)2.4%—Lemonldap-ng Lemonldap\Debian Linux28/6/201917/6/2026
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.
ModificadaCrítica (9.8)3.1%—Lemonldap-ng Lemonldap\Debian Linux22/5/201917/6/2026
LemonLDAP::NG -2.0.3 has Incorrect Access Control.
ModificadaAlta (7.5)1.2%—Mossle Lemon15/10/201817/6/2026
com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFileToFile method in CdnUtils only checks for a ../ substring, and does not validate the file type and spaceName parameter.
ModificadaMedia (4.3)0.95%—Lemon-s PHP Twit BBS7/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in index.php in LEMON-S PHP Twit BBS allows remote attackers to inject arbitrary web script or HTML via the imagetitle parameter.
ModificadaMedia (5)1.3%—Lemon-s PHP Gazou BBS Plus29/7/201517/6/2026
LEMON-S PHP Gazou BBS plus before 2.36 allows remote attackers to upload arbitrary HTML documents via vectors involving a crafted image file.
ModificadaMedia (6.4)1.6%—Lemon-s PHP Simple Oekaki10/7/201517/6/2026
index.php in LEMON-S PHP Simple Oekaki BBS before 1.21 allows remote attackers to delete arbitrary files via the oekakis parameter.
ModificadaMedia (4.3)1.2%—Lemon-s PHP Simple Oekaki BBS10/7/201517/6/2026
Cross-site scripting (XSS) vulnerability in index.php in LEMON-S PHP Simple Oekaki BBS before 1.21 allows remote attackers to inject arbitrary web script or HTML via the oekakis parameter.
ModificadaAlta (7.5)1.6%—Lemonldap-ng Lemonldap\1/1/201316/6/2026
LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.
ModificadaMedia (4.3)1.5%—Phplemon Adquick10/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in account.php in phplemon AdQuick 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the red_url parameter.
ModificadaMedia (4.3)1.8%—Phplemon Myweight1/10/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date parameter to user_addfood.php, info parameter to (2) user_forgot_pwd_form.php and (3) user_login.php, and (4) return parameter to user_login.php.
ModificadaMedia (6.8)1.9%—Lemoncms Lemon CMS25/7/200816/6/2026
Directory traversal vulnerability in lemon_includes/FCKeditor/editor/filemanager/browser/browser.php in Lemon CMS 1.10 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dir parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from…
ModificadaMedia (5.1)1.3%—Tachyon Vsns Lemon31/3/200616/6/2026
SQL injection vulnerability in functions/final_functions.php in VSNS Lemon 3.2.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaBaja (2.6)1.4%—Tachyon Vsns Lemon31/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in VSNS Lemon 3.2.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter while adding a comment.
ModificadaAlta (7.5)1.9%—Tachyon Vsns Lemon31/3/200616/6/2026
VSNS Lemon 3.2.0 allows remote attackers to bypass authentication and access password-protected articles by setting the vsns[topic_id] cookie to the targeted topic.
ModificadaAlta (7.2)0.39%—Timecop BubblemonFreebsd2/7/200116/6/2026
BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.