Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

57 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—WUT At-modem-emulator FirmwareWUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx Firmware+1315/11/202217/6/2026
Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Request.
ModificadaMedia (5.5)0.27%—Jenkins Violations15/11/202217/6/2026
Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaAlta (8.8)0.78%—WUT At-modem-emulator FirmwareWUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx Firmware+1310/11/202217/6/2026
Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the device. As the user needs to log in for the attack to be successful a user…
ModificadaMedia (5.4)0.46%—WUT At-modem-emulator FirmwareWUT Com-server ++ FirmwareWUT Com-server 20ma FirmwareWUT Com-server Highspeed 100basefx Firmware+1310/11/202217/6/2026
Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into the title of the configuration webpage
ModificadaCrítica (9.8)1.3%—Isolated-vm Project Isolated-vm29/9/202217/6/2026
isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached data is passed to the API through CachedDataOptions, attackers can bypass the sandbox and run arbitrary code in the nodejs process. Version 4.3.7 changes the documentation…
ModificadaAlta (8.8)0.61%—Fortinet Fortiisolator4/5/202217/6/2026
An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL.
ModificadaMedia (5.3)0.69%—Menlosecurity Email Isolation2/5/202217/6/2026
Links may not be rewritten according to policy in some specially formatted emails.
ModificadaAlta (8.1)1.5%—Frentix Openolat10/12/202117/6/2026
OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a relative path as a parameter in some REST methods, it is possible to create directory structures and write files anywhere on the target…
ModificadaAlta (7.7)1.2%—Frentix Openolat18/10/202117/6/2026
OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system. In affected versions by manipulating the HTTP request an attacker can modify the path of a requested file download in the folder component to point to anywhere on the target system.…
ModificadaAlta (8.8)1.9%—Frentix Openolat1/9/202117/6/2026
OpenOlat is a web-based learning management system (LMS). Prior to version 15.3.18, 15.5.3, and 16.0.0, using a prepared import XML file (e.g. a course) any class on the Java classpath can be instantiated, including spring AOP bean factories. This can be used to execute code arbitrary code by the attacker. The attack…
ModificadaAlta (8.8)2.4%—Frentix Openolat31/8/202117/6/2026
OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15.3.18, 15.5.3, and 16.0.0. Using a specially prepared ZIP file, it is possible to overwrite any file that is writable by the application server user (e.g. the tomcat user). Depending on the…
ModificadaCrítica (9.6)0.72%—Isolated-vm Project Isolated-vm30/3/202117/6/2026
isolated-vm is a library for nodejs which gives you access to v8's Isolate interface. Versions of isolated-vm before v4.0.0 have API pitfalls which may make it easy for implementers to expose supposed secure isolates to the permissions of the main nodejs isolate. Reference objects allow access to the underlying…
ModificadaCrítica (9.8)1.5%—Fortinet Fortiisolator8/2/202117/6/2026
An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks)
ModificadaAlta (7.8)1.6%—Chocolatey Boxstarter20/10/202017/6/2026
The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH environment variable. However, this directory is writable by normal, unprivileged users. To exploit the vulnerability, place a DLL in this directory that a privileged service is looking for. For example,…
ModificadaCrítica (9.8)2.7%—Chocolate-doom Chocolate DoomChocolate-doom Crispy DoomOpensuse BackportsOpensuse Leap22/6/202017/6/2026
The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack.
ModificadaMedia (5.4)0.84%—Fortinet Fortiisolator12/3/202017/6/2026
An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows a remote authenticated attacker to perform a cross site scripting attack (XSS).
ModificadaMedia (6.5)1.1%—Jenkins Violation Comments TO Gitlab25/9/201917/6/2026
Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
ModificadaMedia (6.5)1.1%—Jenkins Violation Comments TO Gitlab25/9/201917/6/2026
Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
ModificadaMedia (6.1)1.00%—Symantec WEB Isolation22/10/201817/6/2026
Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker can target end users protected by WI with social engineering attacks using crafted URLs for legitimate web sites. A successful attack allows injecting malicious JavaScript code…
ModificadaMedia (5.4)0.27%—Loli Chocolate Cake Project Loli Chocolate Cake4/10/201417/6/2026
The Loli Chocolate Cake (aka com.alison.kang.chocolatecake) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.3%💥 ExploitOlat14/11/201317/6/2026
Cross-site scripting (XSS) vulnerability in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allows remote attackers to inject arbitrary web script or HTML via the Location field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)3.2%💥 ExploitOlat14/11/201317/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allow remote attackers to inject arbitrary web script or HTML via the (1) event name or (2) date field.
ModificadaMedia (4.3)1.2%—Puntolatinoclub Gallery Assist Module24/11/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Gallery Assist module 6.x before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via node titles.
ModificadaAlta (7.5)1.3%—Olatedownload27/8/200716/6/2026
Multiple SQL injection vulnerabilities in download.php in Olate Download (od) 3.4.2 allow remote attackers to execute arbitrary SQL commands via the (1) HTTP_REFERER or (2) HTTP_USER_AGENT HTTP header.
ModificadaMedia (4.3)0.78%—Olatedownload27/8/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Olate Download (od) 3.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the PHP_SELF variable in modules/core/uim.php and (2) [url] tags in a comment in modules/core/fldm.php.
Orbitaley — Vulnerabilidades