Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | WUT At-modem-emulator FirmwareWUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx Firmware+13 | 15/11/2022 | 17/6/2026 | Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Request. | |
| Modificada | Media (5.5) | 0.27% | — | Jenkins Violations | 15/11/2022 | 17/6/2026 | Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Alta (8.8) | 0.78% | — | WUT At-modem-emulator FirmwareWUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx Firmware+13 | 10/11/2022 | 17/6/2026 | Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the device. As the user needs to log in for the attack to be successful a user… | |
| Modificada | Media (5.4) | 0.46% | — | WUT At-modem-emulator FirmwareWUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx Firmware+13 | 10/11/2022 | 17/6/2026 | Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into the title of the configuration webpage | |
| Modificada | Crítica (9.8) | 1.3% | — | Isolated-vm Project Isolated-vm | 29/9/2022 | 17/6/2026 | isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached data is passed to the API through CachedDataOptions, attackers can bypass the sandbox and run arbitrary code in the nodejs process. Version 4.3.7 changes the documentation… | |
| Modificada | Alta (8.8) | 0.61% | — | Fortinet Fortiisolator | 4/5/2022 | 17/6/2026 | An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL. | |
| Modificada | Media (5.3) | 0.69% | — | Menlosecurity Email Isolation | 2/5/2022 | 17/6/2026 | Links may not be rewritten according to policy in some specially formatted emails. | |
| Modificada | Alta (8.1) | 1.5% | — | Frentix Openolat | 10/12/2021 | 17/6/2026 | OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a relative path as a parameter in some REST methods, it is possible to create directory structures and write files anywhere on the target… | |
| Modificada | Alta (7.7) | 1.2% | — | Frentix Openolat | 18/10/2021 | 17/6/2026 | OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system. In affected versions by manipulating the HTTP request an attacker can modify the path of a requested file download in the folder component to point to anywhere on the target system.… | |
| Modificada | Alta (8.8) | 1.9% | — | Frentix Openolat | 1/9/2021 | 17/6/2026 | OpenOlat is a web-based learning management system (LMS). Prior to version 15.3.18, 15.5.3, and 16.0.0, using a prepared import XML file (e.g. a course) any class on the Java classpath can be instantiated, including spring AOP bean factories. This can be used to execute code arbitrary code by the attacker. The attack… | |
| Modificada | Alta (8.8) | 2.4% | — | Frentix Openolat | 31/8/2021 | 17/6/2026 | OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Using a specially prepared ZIP file, it is possible to overwrite any file that is writable by the application server user (e.g. the tomcat user). Depending on the… | |
| Modificada | Crítica (9.6) | 0.72% | — | Isolated-vm Project Isolated-vm | 30/3/2021 | 17/6/2026 | isolated-vm is a library for nodejs which gives you access to v8's Isolate interface. Versions of isolated-vm before v4.0.0 have API pitfalls which may make it easy for implementers to expose supposed secure isolates to the permissions of the main nodejs isolate. Reference objects allow access to the underlying… | |
| Modificada | Crítica (9.8) | 1.5% | — | Fortinet Fortiisolator | 8/2/2021 | 17/6/2026 | An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks) | |
| Modificada | Alta (7.8) | 1.6% | — | Chocolatey Boxstarter | 20/10/2020 | 17/6/2026 | The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH environment variable. However, this directory is writable by normal, unprivileged users. To exploit the vulnerability, place a DLL in this directory that a privileged service is looking for. For example,… | |
| Modificada | Crítica (9.8) | 2.7% | — | Chocolate-doom Chocolate DoomChocolate-doom Crispy DoomOpensuse BackportsOpensuse Leap | 22/6/2020 | 17/6/2026 | The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack. | |
| Modificada | Media (5.4) | 0.84% | — | Fortinet Fortiisolator | 12/3/2020 | 17/6/2026 | An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows a remote authenticated attacker to perform a cross site scripting attack (XSS). | |
| Modificada | Media (6.5) | 1.1% | — | Jenkins Violation Comments TO Gitlab | 25/9/2019 | 17/6/2026 | Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (6.5) | 1.1% | — | Jenkins Violation Comments TO Gitlab | 25/9/2019 | 17/6/2026 | Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system. | |
| Modificada | Media (6.1) | 1.00% | — | Symantec WEB Isolation | 22/10/2018 | 17/6/2026 | Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker can target end users protected by WI with social engineering attacks using crafted URLs for legitimate web sites. A successful attack allows injecting malicious JavaScript code… | |
| Modificada | Media (5.4) | 0.27% | — | Loli Chocolate Cake Project Loli Chocolate Cake | 4/10/2014 | 17/6/2026 | The Loli Chocolate Cake (aka com.alison.kang.chocolatecake) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Olat | 14/11/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allows remote attackers to inject arbitrary web script or HTML via the Location field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Olat | 14/11/2013 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allow remote attackers to inject arbitrary web script or HTML via the (1) event name or (2) date field. | |
| Modificada | Media (4.3) | 1.2% | — | Puntolatinoclub Gallery Assist Module | 24/11/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Gallery Assist module 6.x before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via node titles. | |
| Modificada | Alta (7.5) | 1.3% | — | Olatedownload | 27/8/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in download.php in Olate Download (od) 3.4.2 allow remote attackers to execute arbitrary SQL commands via the (1) HTTP_REFERER or (2) HTTP_USER_AGENT HTTP header. | |
| Modificada | Media (4.3) | 0.78% | — | Olatedownload | 27/8/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Olate Download (od) 3.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the PHP_SELF variable in modules/core/uim.php and (2) [url] tags in a comment in modules/core/fldm.php. |