Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | Notifyvisitors | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Notifyvisitors NotifyVisitors plugin <= 1.0 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Cyclodev WP Notify | 13/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting') vulnerability in Zephilou Cyklodev WP Notify plugin <= 1.2.1 versions. | |
| Modificada | Media (4.3) | 0.68% | — | Jenkins Pipeline Github Notify Step | 12/2/2020 | 17/6/2026 | A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. | |
| Modificada | Media (4.3) | 0.68% | — | Jenkins Pipeline Github Notify Step | 12/2/2020 | 17/6/2026 | A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 0.68% | — | Jenkins Pipeline Github Notify Step | 12/2/2020 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Crítica (9.8) | 2.7% | — | Libnotify Project Libnotify | 12/2/2020 | 17/6/2026 | libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify. | |
| Modificada | Media (4) | 0.94% | — | Notify Project Notify | 1/12/2014 | 17/6/2026 | The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email. | |
| Modificada | Media (5.1) | 1.5% | — | Jianping YU Pidgin-knotify | 8/10/2010 | 16/6/2026 | The notify function in pidgin-knotify.c in the pidgin-knotify plugin 0.2.1 and earlier for Pidgin allows remote attackers to execute arbitrary commands via shell metacharacters in a message. | |
| Modificada | Media (4.6) | 0.30% | — | Inotify Incron | 8/10/2009 | 16/6/2026 | incron 0.5.5 does not initialize supplementary groups when running a process from a user's incrontabs, which causes the process to be run with the incrond supplementary groups and allows local users to gain privileges via an incrontab table. | |
| Modificada | Media (6.8) | 3.0% | — | Inotify-tools | 24/9/2007 | 16/6/2026 | Buffer overflow in the inotifytools_snprintf function in src/inotifytools.c in the inotify-tools library before 3.11 allows context-dependent attackers to execute arbitrary code via a long filename. | |
| Modificada | Baja (2.1) | 0.33% | — | Inotify Incron | 31/1/2007 | 16/6/2026 | Unspecified vulnerability in inotify before 0.3.5 has unknown impact and attack vectors, related to "access rights to watched files." | |
| Modificada | Alta (7.5) | 2.3% | — | AVI Alkalay Notify | 28/9/2005 | 16/6/2026 | Avi Alkalay notify program, dated 19 Aug 2001, allows remote attackers to execute arbitrary commands via shell metacharacters in the from parameter. | |
| Modificada | Media (5) | 1.6% | — | Notify Technology Notifylink | 2/5/2005 | 16/6/2026 | The web interface in NotifyLink 3.0 displays passwords in cleartext on the administrative page, which could allow remote attackers or local users to obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.5% | — | Notify Technology Notifylink | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in NotifyLink before 3.0 allows remote attackers to execute arbitrary SQL commands via the URL. | |
| Modificada | Media (4.6) | 0.66% | — | Notify Technology Notifylink | 2/5/2005 | 16/6/2026 | The web interface in NotifyLink 3.0 does not properly restrict access to functions that have been disabled in the GUI, which allows remote authenticated users to bypass intended restrictions via a direct request to certain URLs. | |
| Modificada | Alta (7.5) | 1.2% | — | Notify Technology Notifylink | 2/5/2005 | 16/6/2026 | NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack. |