Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

97 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitIgniterealtime Openfire26/5/202317/6/2026
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an…
ModificadaAlta (7.5)0.79%💥 PoCIcrealtime Icip-p2012t Firmware25/5/20239/7/2026
IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network.
ModificadaAlta (7.5)0.83%💥 PoCIcrealtime Icip-p2012t Firmware24/5/20239/7/2026
IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via unauthenticated port access.
ModificadaAlta (8.8)53%💥 ExploitRealtimelogic Fuguhub17/2/202317/6/2026
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.
ModificadaAlta (7.5)1.0%—Codesys Development SystemCodesys Edge GatewayCodesys GatewayCodesys HMI SL+624/6/202217/6/2026
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
ModificadaCrítica (9.8)21%💥 ExploitPascom Cloud Phone SystemIgniterealtime Openfire18/3/202217/6/2026
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.
ModificadaMedia (4.4)0.37%—Linux KernelFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+14/3/202117/6/2026
A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system.
ModificadaMedia (5.4)0.74%—Igniterealtime Openfire12/12/202017/6/2026
Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.
ModificadaMedia (5.4)0.74%—Igniterealtime Openfire12/12/202017/6/2026
Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS.
ModificadaMedia (6.1)0.91%—Igniterealtime Openfire12/12/202017/6/2026
Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.
ModificadaMedia (5.4)0.62%—Igniterealtime Openfire12/12/202017/6/2026
Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS.
ModificadaMedia (5.4)0.57%—Igniterealtime Openfire11/12/202017/6/2026
Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS.
ModificadaAlta (7.8)0.50%—Realtimelogic Barracudadrive4/9/202017/6/2026
Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\bd\bd.exe file. When the computer next starts, the new bd.exe will be run as LocalSystem.
ModificadaMedia (6.1)1.2%—Igniterealtime Openfire2/9/202017/6/2026
A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic"…
ModificadaMedia (6.1)1.0%—Igniterealtime Openfire2/9/202017/6/2026
Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in the Server…
ModificadaMedia (6.1)0.62%—Igniterealtime Openfire2/9/202017/6/2026
In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page
ModificadaMedia (5.9)3.1%—Linux KernelRedhat 3scaleRedhat OpenstackRedhat Virtualization Host+722/5/202017/6/2026
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO…
ModificadaAlta (8.8)1.7%—Igniterealtime Spark12/5/202017/6/2026
An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an external host's IP address. Upon access to this external host, the (NT)LM hashes of the user are sent with the HTTP request. This allows an…
ModificadaMedia (6.1)0.91%—Igniterealtime Openfire19/3/202017/6/2026
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
ModificadaMedia (6.1)0.91%—Igniterealtime Openfire19/3/202017/6/2026
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
ModificadaMedia (6.1)0.91%—Igniterealtime Openfire19/3/202017/6/2026
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
ModificadaMedia (6.1)0.91%—Igniterealtime Openfire18/3/202017/6/2026
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
ModificadaMedia (6.1)1.3%—Igniterealtime Openfire8/1/202017/6/2026
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
ModificadaMedia (6.1)1.2%—Igniterealtime Openfire8/1/202017/6/2026
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
ModificadaMedia (6.1)1.2%—Igniterealtime Openfire8/1/202017/6/2026
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
Orbitaley — Vulnerabilidades