Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

154 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.3)0.35%—Octopus Server11/2/202517/6/2026
In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.
AnalizadaBaja (1.8)0.24%—Octopus Server11/2/202517/6/2026
In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message.
AnalizadaBaja (2.3)0.38%—Octopus Server11/2/202517/6/2026
In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could provide an adversary with information that may aid in further attacks against the server.
AnalizadaMedia (6.9)0.37%—Octopus Server11/2/202517/6/2026
In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API request against two endpoints which would retrieve some data from the associated Active Directory. The requests when crafted correctly would return specific…
AplazadaMedia (6.5)0.35%—Octopus Kubernetes WorkerAIOctopus Kubernetes AgentAI16/1/202517/6/2026
In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this could also be achieved in Version 1 and the fix was applied to both versions accordingly.
AnalizadaAlta (8.7)0.43%—Octopus Server30/9/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL Injection.This issue affects Octopus Server: from 2024.1.0 before 2024.1.13038, from 2024.2.0 before 2024.2.9482, from 2024.3.0 before…
AnalizadaBaja (2.6)0.25%—Octopus Server11/9/202417/6/2026
Affected versions of Octopus Server had a weak content security policy.
AnalizadaBaja (2.6)0.25%—Octopus Server21/8/202417/6/2026
In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespan.
AnalizadaMedia (6.5)0.23%—Octopus Server25/7/202417/6/2026
In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.
AnalizadaBaja (2.2)0.24%—Octopus Server25/7/202417/6/2026
In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.
AplazadaAlta (7.5)0.60%—Discordjs OpusAI10/7/202417/6/2026
All versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object with a property toString to several different functions. Exploiting this vulnerability could lead to a system crash.
ModificadaMedia (6.1)0.29%—Loopus WP Visitors Tracker8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Loopus WP Visitors Tracker allows Reflected XSS.This issue affects WP Visitors Tracker: from n/a through 2.3.
AnalizadaMedia (5.4)0.26%—Octopus Server8/5/202417/6/2026
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page.
AnalizadaBaja (3.5)0.30%—Octopus Server30/4/202417/6/2026
It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.
AnalizadaMedia (4.3)0.23%—Octopus Server18/4/202417/6/2026
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.
AplazadaAlta (7.1)0.35%—Loopus WP Cost Estimation AND Payment Forms BuilderAI17/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Loopus WP Cost Estimation & Payment Forms Builder allows Reflected XSS.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through 10.1.75.
AplazadaMedia (6.5)0.44%—Loopus WP Cost Estimation & Payment Forms BuilderAI17/4/202417/6/2026
Missing Authorization vulnerability in Loopus WP Cost Estimation & Payment Forms Builder.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through 10.1.76.
AnalizadaAlta (7.5)0.39%—Octopus Server9/4/202417/6/2026
A race condition was identified through which privilege escalation was possible in certain configurations.
AplazadaAlta (8.5)0.49%—Loopus WP Cost Estimation AND Payment Forms BuilderAI31/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Cost Estimation & Payment Forms Builder.This issue affects WP Cost Estimation & Payment Forms Builder: from n/a through 10.1.75.
ModificadaMedia (5.4)0.56%—Hongmaple Octopus25/1/202417/6/2026
A vulnerability was found in hongmaple octopus 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument description with the input <script>alert(document.cookie)</script> leads to cross site scripting. The attack can be launched remotely.…
ModificadaCrítica (9.8)0.66%—Hongmaple Octopus25/1/202417/6/2026
A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation of the argument ancestors leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be…
ModificadaCrítica (9.8)0.68%—Hongmaple Octopus22/1/202417/6/2026
A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/role/list. The manipulation of the argument dataScope leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be…
ModificadaAlta (7.5)0.39%—Octopus Server14/12/202317/6/2026
In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.
ModificadaMedia (4.3)0.30%—Octopus Server2/8/202317/6/2026
In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enumeration/recon of an environment.
ModificadaMedia (4.3)0.34%—Octopus Server2/8/202317/6/2026
In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.