Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.32% | — | Jupo Mezzanine | 17/6/2025 | 17/6/2026 | Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnerability exists in the "displayable_links_js" function, which fails to properly sanitize blog post titles before including them in JSON responses served via… | |
| Aplazada | Media (4.3) | 0.17% | — | Roxnor FundenineAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Roxnor FundEngine wp-fundraising-donation allows Cross Site Request Forgery.This issue affects FundEngine: from n/a through <= 1.7.3. | |
| Analizada | Media (6.1) | 0.29% | — | Jupo Mezzanine | 5/5/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module. | |
| Aplazada | Media (6.5) | 0.27% | — | Covertnine C9 BlocksAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in covertnine C9 Blocks c9-blocks allows DOM-Based XSS.This issue affects C9 Blocks: from n/a through <= 1.7.7. | |
| Analizada | Media (5.3) | 0.35% | — | Covertnine C9 Blocks | 21/2/2025 | 17/6/2026 | The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. This is due the plugin containing a publicly accessible composer-setup.php file with error display enabled. This makes it possible for unauthenticated attackers to retrieve the full path of the web… | |
| Analizada | Media (5.4) | 0.31% | — | Covertnine C9 Admin Dashboard | 21/2/2025 | 17/6/2026 | The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Aplazada | Alta (7.1) | 0.31% | — | Khaninejad Envato AffiliaterAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in khaninejad Envato Affiliater envato-affiliater allows Reflected XSS.This issue affects Envato Affiliater: from n/a through <= 1.2.4. | |
| Aplazada | Alta (8.6) | 0.50% | — | Ininet Solutions Spidercontrol Scada PC HMI EditorAI | 24/10/2024 | 17/6/2026 | iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting system files, causing system paralysis, or writing to startup… | |
| Aplazada | Alta (7.5) | 6.5% | 💥 Exploit | Severalnines Cluster ControlAI | 26/7/2024 | 9/7/2026 | Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API. | |
| Analizada | Crítica (9.1) | 0.88% | 💥 PoC | Jupo Mezzanine | 28/2/2024 | 17/6/2026 | An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header. | |
| Modificada | Crítica (9.8) | 1.1% | 💥 PoC | Jupo Mezzanine | 28/2/2024 | 17/6/2026 | An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request. | |
| Modificada | Media (4.8) | 0.52% | — | Newnine Font Awesome 4 Menus | 16/1/2024 | 17/6/2026 | The Font Awesome 4 Menus WordPress plugin through 4.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.4) | 0.51% | — | Newnine Font Awesome 4 Menus | 2/9/2023 | 17/6/2026 | The Font Awesome 4 Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fa' and 'fa-stack' shortcodes in versions up to, and including, 4.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (6.1) | 0.97% | — | Uninett MOD Auth Mellon | 22/8/2022 | 17/6/2026 | A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this… | |
| Modificada | Media (6.1) | 1.1% | — | Jupo Mezzanine | 27/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the 'Description' field of the component 'admin/blog/blogpost/add/'. This issue is different than CVE-2018-16632. | |
| Modificada | Crítica (9.4) | 1.3% | — | Uninett RadsecproxyFedoraproject Fedora | 28/5/2021 | 17/6/2026 | radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-eduroam.sh` and `radsec-dynsrv.sh` scripts can lead to configuration injection via crafted radsec peer discovery DNS records. Users are subject to Information disclosure,… | |
| Modificada | Media (6.1) | 0.99% | — | 9folders Nine | 18/3/2020 | 17/6/2026 | The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission. | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Media (4.8) | 0.62% | — | Jupo Mezzanine | 28/12/2018 | 17/6/2026 | Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&_popup=1 title parameter at admin/blog/blogpost/add/. | |
| Modificada | Media (5.9) | 4.1% | — | 9folders NineApple MailBloop AirmailEmclient+13 | 16/5/2018 | 17/6/2026 | The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. | |
| Modificada | Media (6.1) | 0.65% | — | Severalnines Clustercontrol | 9/5/2018 | 17/6/2026 | Severalnines ClusterControl before 1.6.0-4699 allows XSS. | |
| Modificada | Crítica (10) | 2.5% | — | Spidercontrol Ininet Webserver | 5/10/2017 | 17/6/2026 | An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does not properly authenticate users, which may allow a malicious attacker to access sensitive information such as HMI pages or modify PLC variables. | |
| Modificada | Media (6.1) | 1.1% | — | Uninett MOD Auth Mellon | 13/3/2017 | 17/6/2026 | mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site. | |
| Modificada | Alta (7.5) | 3.4% | — | Fedoraproject FedoraUninett MOD Auth Mellon | 15/4/2016 | 17/6/2026 | The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data. | |
| Modificada | Alta (7.5) | 3.1% | — | Fedoraproject FedoraUninett MOD Auth Mellon | 15/4/2016 | 17/6/2026 | The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST data. |