Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Igniterealtime Openfire | 26/5/2023 | 17/6/2026 | Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an… | |
| Modificada | Alta (7.5) | 0.79% | 💥 PoC | Icrealtime Icip-p2012t Firmware | 25/5/2023 | 9/7/2026 | IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network. | |
| Modificada | Alta (7.5) | 0.83% | 💥 PoC | Icrealtime Icip-p2012t Firmware | 24/5/2023 | 9/7/2026 | IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via unauthenticated port access. | |
| Modificada | Alta (8.8) | 53% | 💥 Exploit | Realtimelogic Fuguhub | 17/2/2023 | 17/6/2026 | Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/. | |
| Modificada | Alta (7.5) | 1.0% | — | Codesys Development SystemCodesys Edge GatewayCodesys GatewayCodesys HMI SL+6 | 24/6/2022 | 17/6/2026 | In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected. | |
| Modificada | Crítica (9.8) | 21% | 💥 Exploit | Pascom Cloud Phone SystemIgniterealtime Openfire | 18/3/2022 | 17/6/2026 | An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints. | |
| Modificada | Media (4.4) | 0.37% | — | Linux KernelFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+1 | 4/3/2021 | 17/6/2026 | A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system. | |
| Modificada | Media (5.4) | 0.74% | — | Igniterealtime Openfire | 12/12/2020 | 17/6/2026 | Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS. | |
| Modificada | Media (5.4) | 0.74% | — | Igniterealtime Openfire | 12/12/2020 | 17/6/2026 | Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS. | |
| Modificada | Media (6.1) | 0.91% | — | Igniterealtime Openfire | 12/12/2020 | 17/6/2026 | Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS. | |
| Modificada | Media (5.4) | 0.62% | — | Igniterealtime Openfire | 12/12/2020 | 17/6/2026 | Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS. | |
| Modificada | Media (5.4) | 0.57% | — | Igniterealtime Openfire | 11/12/2020 | 17/6/2026 | Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS. | |
| Modificada | Alta (7.8) | 0.50% | — | Realtimelogic Barracudadrive | 4/9/2020 | 17/6/2026 | Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\bd\bd.exe file. When the computer next starts, the new bd.exe will be run as LocalSystem. | |
| Modificada | Media (6.1) | 1.2% | — | Igniterealtime Openfire | 2/9/2020 | 17/6/2026 | A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic"… | |
| Modificada | Media (6.1) | 1.0% | — | Igniterealtime Openfire | 2/9/2020 | 17/6/2026 | Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in the Server… | |
| Modificada | Media (6.1) | 0.62% | — | Igniterealtime Openfire | 2/9/2020 | 17/6/2026 | In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page | |
| Modificada | Media (5.9) | 3.1% | — | Linux KernelRedhat 3scaleRedhat OpenstackRedhat Virtualization Host+7 | 22/5/2020 | 17/6/2026 | A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO… | |
| Modificada | Alta (8.8) | 1.7% | — | Igniterealtime Spark | 12/5/2020 | 17/6/2026 | An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an external host's IP address. Upon access to this external host, the (NT)LM hashes of the user are sent with the HTTP request. This allows an… | |
| Modificada | Media (6.1) | 0.91% | — | Igniterealtime Openfire | 19/3/2020 | 17/6/2026 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Igniterealtime Openfire | 19/3/2020 | 17/6/2026 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Igniterealtime Openfire | 19/3/2020 | 17/6/2026 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Igniterealtime Openfire | 18/3/2020 | 17/6/2026 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter. | |
| Modificada | Media (6.1) | 1.3% | — | Igniterealtime Openfire | 8/1/2020 | 17/6/2026 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents. | |
| Modificada | Media (6.1) | 1.2% | — | Igniterealtime Openfire | 8/1/2020 | 17/6/2026 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page. | |
| Modificada | Media (6.1) | 1.2% | — | Igniterealtime Openfire | 8/1/2020 | 17/6/2026 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp. |