Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.82% | — | It-novum Openitcockpit | 23/8/2019 | 17/6/2026 | openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21. | |
| Modificada | Alta (8.8) | 0.60% | — | It-novum Openitcockpit | 23/8/2019 | 17/6/2026 | openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21. | |
| Modificada | Crítica (9.8) | 1.7% | — | It-novum Openitcockpit | 23/8/2019 | 17/6/2026 | openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21. | |
| Modificada | Media (5) | 0.87% | — | Adnovum Nevisauth | 28/9/2015 | 17/6/2026 | The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 certificate embedded in the assertion against the certificate from the identity provider (IdP), which allows remote attackers to inject arbitrary SAML assertions via a… | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Solidweb Novus | 28/9/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in buscar.asp in Solidweb Novus 1.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Solidweb Novus | 27/9/2007 | 16/6/2026 | SQL injection vulnerability in notas.asp in Novus 1.0 allows remote attackers to execute arbitrary SQL commands via the nota_id parameter. |